CWE-918
3,430 CVEs • Abstraction: Base
Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
CVEs (3,430)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microstrategy 1Microstrategy Web Jun 17, 2026 Apr 2, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Microstrategy Web 10.4 is vulnerable to Server-Side Request Forgery in the Test Web Service functionality exposed through the path /MicroStrategyWS/. The functionality requires no authentication and, while it is not poss...Show more |
1Microstrategy 1Microstrategy Web Jun 17, 2026 Apr 2, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Microstrategy Web 10.4 includes functionality to allow users to import files or data from external resources such as URLs or databases. By providing an external URL under attacker control, it's possible to send requests...Show more |
GitLab 8.10 and later through 12.9 is vulnerable to an SSRF in a project import note feature. |
Adobe Experience Manager versions 6.5 and earlier have a server-side request forgery (ssrf) vulnerability. Successful exploitation could lead to sensitive information disclosure. |
app/Plugin/GrafanaModule/Controller/GrafanaConfigurationController.php in openITCOCKPIT before 3.7.3 allows remote authenticated users to trigger outbound TCP requests (aka SSRF) via the Test Connection feature (aka test...Show more |
1Simplemachines 1Simple Machine Forum Jun 17, 2026 Mar 20, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in Simple Machines Forum (SMF) before release 2.0.17. There is SSRF related to Subs-Package.php and Subs.php because user-supplied data is used directly in curl calls. |
A missing check for IPv4 nested inside IPv6 in Nextcloud server < 17.0.1, < 16.0.7, and < 15.0.14 allowed a Server-Side Request Forgery (SSRF) vulnerability when subscribing to a malicious calendar URL. |
The uppy npm package < 1.9.3 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability, which allows an attacker to scan local or external network or otherwise interact with internal systems. |
Server-side request forgery (SSRF) vulnerability in Ghost CMS < 3.10.0 allows an attacker to scan local or external network or otherwise interact with internal systems. |
GitLab EE 3.0 through 12.8.1 allows SSRF. An internal investigation revealed that a particular deprecated service was creating a server side request forgery risk. |
1Zohocorp 1Manageengine Desktop Central Jun 17, 2026 Mar 11, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An XML external entity (XXE) vulnerability in Zoho ManageEngine Desktop Central before the 07-Mar-2020 update allows remote unauthenticated users to read arbitrary files or conduct server-side request forgery (SSRF) atta...Show more |
An issue was discovered in GitLab Enterprise Edition 10.6 through 12.0.2. The GitHub project integration was vulnerable to an SSRF vulnerability which allowed an attacker to make requests to local network resources. It h...Show more |
An issue was discovered in GitLab Community and Enterprise Edition 10.2 through 11.11. Multiple features contained Server-Side Request Forgery (SSRF) vulnerabilities caused by an insufficient validation to prevent DNS re...Show more |
1Tecrail 1Responsive Filemanager Jun 17, 2026 Mar 7, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 upload.php in Responsive FileManager 9.13.4 and 9.14.0 allows SSRF via the url parameter because file-extension blocking is mishandled and because it is possible for a DNS hostname to resolve to an internal IP address. F...Show more |
1Open Xchange 1Open Xchange Appsuite Jun 17, 2026 Feb 21, 2020 N/A· v4 5.0 MEDIUM· v3 4.0 MEDIUM· v2 OX App Suite through 7.10.2 allows SSRF. |
1Synacor 1Zimbra Collaboration Suite Jun 17, 2026 Feb 18, 2020 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 Zimbra Collaboration Suite (ZCS) before 8.8.15 Patch 7 allows SSRF when WebEx zimlet is installed and zimlet JSP is enabled. |
1Zohocorp 1Manageengine Remote Access Plus Jun 17, 2026 Feb 17, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered in Zoho ManageEngine Remote Access Plus 10.0.447. The service to test the mail-server configuration suffers from an authorization issue allowing a user with the Guest role (read-only access) to us...Show more |
An unintended require and server-side request forgery vulnerabilities in jsreport version 2.5.0 and earlier allow attackers to execute arbitrary code. |
IBM Content Navigator 3.0CD is vulnerable to Server Side Request Forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or fac...Show more |
3Nextcloud NovellOpensuse3Backports Sle Nextcloud ServerSuse Linux Enterprise ServerJun 17, 2026 Feb 4, 2020 N/A· v4 5.0 MEDIUM· v3 4.0 MEDIUM· v2 An authenticated server-side request forgery in Nextcloud server 16.0.1 allowed to detect local and remote services when adding a new subscription in the calendar application. |