← Back
CWE-918

3,430 CVEs • Abstraction: Base

Server-Side Request Forgery (SSRF)

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

JSON object

Loading...

CVEs (3,430)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Wavemaker
1Wavemarker Studio
Jun 17, 2026
Feb 21, 2019
N/A· v4
9.6 CRITICAL· v3
6.8 MEDIUM· v2
com/wavemaker/studio/StudioService.java in WaveMaker Studio 6.6 mishandles the studioService.download?method=getContent&inUrl= value, leading to disclosure of local files and SSRF.
1Jenkins
1Jms Messaging
Jun 17, 2026
Feb 20, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
A server-side request forgery vulnerability exists in Jenkins JMS Messaging Plugin 1.1.1 and earlier in SSLCertificateAuthenticationMethod.java, UsernameAuthenticationMethod.java that allows attackers with Overall/Read p...Show more
A server-side request forgery vulnerability exists in Jenkins JMS Messaging Plugin 1.1.1 and earlier in SSLCertificateAuthenticationMethod.java, UsernameAuthenticationMethod.java that allows attackers with Overall/Read permission to have Jenkins connect to a JMS endpoint.Show less
1Jenkins
1Octopusdeploy
Jun 17, 2026
Feb 20, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
A server-side request forgery vulnerability exists in Jenkins OctopusDeploy Plugin 1.8.1 and earlier in OctopusDeployPlugin.java that allows attackers with Overall/Read permission to have Jenkins connect to an attacker-s...Show more
A server-side request forgery vulnerability exists in Jenkins OctopusDeploy Plugin 1.8.1 and earlier in OctopusDeployPlugin.java that allows attackers with Overall/Read permission to have Jenkins connect to an attacker-specified URL and obtain the HTTP response code if successful, and exception error message otherwise.Show less
1Jenkins
1Mattermost
Jun 17, 2026
Feb 20, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
A server-side request forgery vulnerability exists in Jenkins Mattermost Notification Plugin 2.6.2 and earlier in MattermostNotifier.java that allows attackers with Overall/Read permission to have Jenkins connect to an a...Show more
A server-side request forgery vulnerability exists in Jenkins Mattermost Notification Plugin 2.6.2 and earlier in MattermostNotifier.java that allows attackers with Overall/Read permission to have Jenkins connect to an attacker-specified Mattermost server and room and send a message.Show less
1Atlassian
2Jira
Jira Server
Nov 21, 2024
Feb 13, 2019
N/A· v4
4.1 MEDIUM· v3
4.0 MEDIUM· v2
The VerifyPopServerConnection resource in Atlassian Jira before version 7.6.10, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10...Show more
The VerifyPopServerConnection resource in Atlassian Jira before version 7.6.10, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3, from version 7.11.0 before version 7.11.3, from version 7.12.0 before version 7.12.3, and from version 7.13.0 before version 7.13.1 allows remote attackers who have administrator rights to determine the existence of internal hosts & open ports and in some cases obtain service information from internal network resources via a Server Side Request Forgery (SSRF) vulnerability.Show less
1Dundas
1Dundas Bi
Nov 21, 2024
Feb 11, 2019
N/A· v4
8.6 HIGH· v3
5.0 MEDIUM· v2
The Dundas BI server before 5.0.1.1010 is vulnerable to a Server-Side Request Forgery attack, allowing an attacker to forge arbitrary requests (with certain restrictions) that will be executed on behalf of the attacker,...Show more
The Dundas BI server before 5.0.1.1010 is vulnerable to a Server-Side Request Forgery attack, allowing an attacker to forge arbitrary requests (with certain restrictions) that will be executed on behalf of the attacker, via the viewUrl parameter of the "export the dashboard as an image" feature. This could be leveraged to provide a proxy to attack other servers (internal or external) or to perform network scans of external or internal networks.Show less
1Cisco
2Telepresence Conductor
Telepresence Video Communication Server
Jun 17, 2026
Feb 7, 2019
N/A· v4
5.0 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability in the web interface of Cisco TelePresence Conductor, Cisco Expressway Series, and Cisco TelePresence Video Communication Server (VCS) Software could allow an authenticated, remote attacker to trigger an...Show more
A vulnerability in the web interface of Cisco TelePresence Conductor, Cisco Expressway Series, and Cisco TelePresence Video Communication Server (VCS) Software could allow an authenticated, remote attacker to trigger an HTTP request from an affected server to an arbitrary host. This type of attack is commonly referred to as server-side request forgery (SSRF). The vulnerability is due to insufficient access controls for the REST API of Cisco Expressway Series and Cisco TelePresence VCS. An attacker could exploit this vulnerability by submitting a crafted HTTP request to the affected server. Versions prior to XC4.3.4 are affected.Show less
1Jenkins
1Kanboard
Jun 17, 2026
Feb 6, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
A server-side request forgery vulnerability exists in Jenkins Kanboard Plugin 1.5.10 and earlier in KanboardGlobalConfiguration.java that allows attackers with Overall/Read permission to submit a GET request to an attack...Show more
A server-side request forgery vulnerability exists in Jenkins Kanboard Plugin 1.5.10 and earlier in KanboardGlobalConfiguration.java that allows attackers with Overall/Read permission to submit a GET request to an attacker-specified URL.Show less
142gears
1Suremdm
Nov 21, 2024
Feb 5, 2019
N/A· v4
7.3 HIGH· v3
1.9 LOW· v2
An SSRF issue was discovered in 42Gears SureMDM before 2018-11-27 via the /api/DownloadUrlResponse.ashx "url" parameter.
1Dlink
1Central Wifimanager
Nov 21, 2024
Jan 31, 2019
N/A· v4
8.6 HIGH· v3
5.0 MEDIUM· v2
The MailConnect feature on D-Link Central WiFiManager CWM-100 1.03 r0098 devices is intended to check a connection to an SMTP server but actually allows outbound TCP to any port on any IP address, leading to SSRF, as dem...Show more
The MailConnect feature on D-Link Central WiFiManager CWM-100 1.03 r0098 devices is intended to check a connection to an SMTP server but actually allows outbound TCP to any port on any IP address, leading to SSRF, as demonstrated by an index.php/System/MailConnect/host/127.0.0.1/port/22/secure/ URI.Show less
1Dlink
1Central Wifimanager
Nov 21, 2024
Jan 31, 2019
N/A· v4
5.8 MEDIUM· v3
3.5 LOW· v2
The FTP service on D-Link Central WiFiManager CWM-100 1.03 r0098 devices allows remote attackers to conduct a PORT command bounce scan via port 8000, resulting in SSRF.
1Open Xchange
1Open Xchange Appsuite
Nov 21, 2024
Jan 30, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
OX App Suite 7.8.4 and earlier allows Server-Side Request Forgery.
1Std42
1Elfinder
Jun 17, 2026
Jan 14, 2019
N/A· v4
7.7 HIGH· v3
4.0 MEDIUM· v2
A Server Side Request Forgery (SSRF) vulnerability in elFinder before 2.1.46 could allow a malicious user to access the content of internal network resources. This occurs in get_remote_contents() in php/elFinder.class.ph...Show more
A Server Side Request Forgery (SSRF) vulnerability in elFinder before 2.1.46 could allow a malicious user to access the content of internal network resources. This occurs in get_remote_contents() in php/elFinder.class.php.Show less
1Atlassian
1Crowd2
Nov 21, 2024
Jan 9, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An improper authorization vulnerability exists in Jenkins Crowd 2 Integration Plugin 2.0.0 and earlier in CrowdSecurityRealm.java that allows attackers to have Jenkins perform a connection test, connecting to an attacker...Show more
An improper authorization vulnerability exists in Jenkins Crowd 2 Integration Plugin 2.0.0 and earlier in CrowdSecurityRealm.java that allows attackers to have Jenkins perform a connection test, connecting to an attacker-specified server with attacker-specified credentials and connection settings.Show less
1Apache
1Mesos
Nov 21, 2024
Jan 9, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An improper authorization vulnerability exists in Jenkins Mesos Plugin 0.17.1 and earlier in MesosCloud.java that allows attackers with Overall/Read access to initiate a test connection to an attacker-specified Mesos ser...Show more
An improper authorization vulnerability exists in Jenkins Mesos Plugin 0.17.1 and earlier in MesosCloud.java that allows attackers with Overall/Read access to initiate a test connection to an attacker-specified Mesos server with attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.Show less
1Qibosoft
1Qibosoft
Jun 17, 2026
Jan 8, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
qibosoft through V7 allows remote attackers to read arbitrary files via the member/index.php main parameter, as demonstrated by SSRF to a URL on the same web site to read a .sql file.
1Rhymix
1Rhymix
Nov 21, 2024
Jan 3, 2019
N/A· v4
9.1 CRITICAL· v3
6.5 MEDIUM· v2
Rhymix CMS 1.9.8.1 allows SSRF via an index.php?module=admin&act=dispModuleAdminFileBox SVG upload.
1Zohocorp
1Manageengine Adselfservice Plus
Jun 17, 2026
Jan 3, 2019
N/A· v4
10.0 CRITICAL· v3
7.5 HIGH· v2
Zoho ManageEngine ADSelfService Plus 5.x before build 5703 has SSRF.
4Debian
FasterxmlOracle+1 more
12Banking Platform
Communications Billing And Revenue ManagementDebian Linux+9 more
Nov 21, 2024
Jan 2, 2019
N/A· v4
10.0 CRITICAL· v3
7.5 HIGH· v2
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to conduct server-side request forgery (SSRF) attacks by leveraging failure to block the axis2-jaxws class from polymorphic deserialization.
1Jspxcms
1Jspxcms
Nov 21, 2024
Dec 30, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Jspxcms v9.0.0 allows SSRF.