← Back
CWE-918

3,430 CVEs • Abstraction: Base

Server-Side Request Forgery (SSRF)

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

JSON object

Loading...

CVEs (3,430)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Allen Disk Project
1Allen Disk
May 13, 2026
May 31, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
SSRF vulnerability in remotedownload.php in Allen Disk 1.6 allows remote authenticated users to conduct port scans and access intranet servers via a crafted file parameter.
2Debian
Wordpress
2Debian Linux
Wordpress
May 13, 2026
May 18, 2017
N/A· v4
8.6 HIGH· v3
5.0 MEDIUM· v2
In WordPress before 4.7.5, there is insufficient redirect validation in the HTTP class, leading to SSRF.
1Accellion
1File Transfer Appliance
May 13, 2026
May 5, 2017
N/A· v4
10.0 CRITICAL· v3
6.4 MEDIUM· v2
An issue was discovered on Accellion FTA devices before FTA_9_12_180. Because a regular expression (intended to match local https URLs) lacks an initial ^ character, courier/web/1000@/wmProgressval.html allows SSRF attac...Show more
An issue was discovered on Accellion FTA devices before FTA_9_12_180. Because a regular expression (intended to match local https URLs) lacks an initial ^ character, courier/web/1000@/wmProgressval.html allows SSRF attacks with a file:///etc/passwd#https:// URL pattern.Show less
1Oracle
1Peoplesoft Enterprise Peopletools
May 13, 2026
Apr 24, 2017
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: MultiChannel Framework). Supported versions that are affected are 8.54 and 8.55. Easily "exploitable" vulnerab...Show more
Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: MultiChannel Framework). Supported versions that are affected are 8.54 and 8.55. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.0 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).Show less
1Yeager
1Yeager Cms
May 13, 2026
Apr 24, 2017
N/A· v4
7.2 HIGH· v3
6.4 MEDIUM· v2
Multiple server-side request forgery (SSRF) vulnerabilities in Yeager CMS 1.2.1 allow remote attackers to trigger outbound requests and enumerate open ports via the dbhost parameter to libs/org/adodb_lite/tests/test_adod...Show more
Multiple server-side request forgery (SSRF) vulnerabilities in Yeager CMS 1.2.1 allow remote attackers to trigger outbound requests and enumerate open ports via the dbhost parameter to libs/org/adodb_lite/tests/test_adodb_lite.php, libs/org/adodb_lite/tests/test_datadictionary.php, or libs/org/adodb_lite/tests/test_adodb_lite_sessions.php.Show less
1Fasterxml
1Jackson Dataformat Xml
May 13, 2026
Apr 14, 2017
N/A· v4
8.6 HIGH· v3
5.0 MEDIUM· v2
XmlMapper in the Jackson XML dataformat component (aka jackson-dataformat-xml) before 2.7.8 and 2.8.x before 2.8.4 allows remote attackers to conduct server-side request forgery (SSRF) attacks via vectors related to a DT...Show more
XmlMapper in the Jackson XML dataformat component (aka jackson-dataformat-xml) before 2.7.8 and 2.8.x before 2.8.4 allows remote attackers to conduct server-side request forgery (SSRF) attacks via vectors related to a DTD.Show less
1Vbulletin
1Vbulletin
May 13, 2026
Apr 6, 2017
N/A· v4
8.6 HIGH· v3
5.0 MEDIUM· v2
In vBulletin before 5.3.0, remote attackers can bypass the CVE-2016-6483 patch and conduct SSRF attacks by leveraging the behavior of the PHP parse_url function, aka VBV-17037.
1Mybb
1Mybb
May 13, 2026
Apr 6, 2017
N/A· v4
7.7 HIGH· v3
4.0 MEDIUM· v2
MyBB before 1.8.11 allows remote attackers to bypass an SSRF protection mechanism.
1F5
2Ssl Intercept Iapp
Ssl Orchestrator
May 13, 2026
Apr 6, 2017
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
F5 SSL Intercept iApp 1.5.0 - 1.5.7 and SSL Orchestrator 2.0 is vulnerable to a Server-Side Request Forgery (SSRF) attack when deployed using the Dynamic Domain Bypass (DDB) feature feature plus SNAT Auto Map option for...Show more
F5 SSL Intercept iApp 1.5.0 - 1.5.7 and SSL Orchestrator 2.0 is vulnerable to a Server-Side Request Forgery (SSRF) attack when deployed using the Dynamic Domain Bypass (DDB) feature feature plus SNAT Auto Map option for egress traffic.Show less
1Php
1Php
May 13, 2026
Mar 27, 2017
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
PHP through 7.1.11 enables potential SSRF in applications that accept an fsockopen or pfsockopen hostname argument with an expectation that the port number is constrained. Because a :port syntax is recognized, fsockopen...Show more
PHP through 7.1.11 enables potential SSRF in applications that accept an fsockopen or pfsockopen hostname argument with an expectation that the port number is constrained. Because a :port syntax is recognized, fsockopen will use the port number that is specified in the hostname argument, instead of the port number in the second argument of the function.Show less
1Openstack
1Glance
May 13, 2026
Mar 21, 2017
N/A· v4
5.8 MEDIUM· v3
5.0 MEDIUM· v2
An SSRF issue was discovered in OpenStack Glance before Newton. The 'copy_from' feature in the Image Service API v1 allowed an attacker to perform masked network port scans. With v1, it is possible to create images with...Show more
An SSRF issue was discovered in OpenStack Glance before Newton. The 'copy_from' feature in the Image Service API v1 allowed an attacker to perform masked network port scans. With v1, it is possible to create images with a URL such as 'http://localhost:22'. This could then allow an attacker to enumerate internal network details while appearing masked, since the scan would appear to originate from the Glance Image service.Show less
1Apache
1Camel
May 13, 2026
Mar 16, 2017
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
Apache Camel's Validation Component is vulnerable against SSRF via remote DTDs and XXE.
2Debian
Kitfox
2Debian Linux
Svg Salamander
May 13, 2026
Mar 16, 2017
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
The SVG Salamander (aka svgSalamander) library, when used in a web application, allows remote attackers to conduct server-side request forgery (SSRF) attacks via an xlink:href attribute in an SVG file.
1Umbraco
1Umbraco
May 13, 2026
Mar 3, 2017
N/A· v4
8.2 HIGH· v3
4.3 MEDIUM· v2
The Page_Load function in Umbraco.Web/umbraco.presentation/umbraco/dashboard/FeedProxy.aspx.cs in Umbraco before 7.4.0 allows remote attackers to conduct server-side request forgery (SSRF) attacks via the url parameter.
1Ibm
1Forms Experience Builder
May 13, 2026
Feb 1, 2017
N/A· v4
3.1 LOW· v3
3.5 LOW· v2
IBM Forms Experience Builder could be susceptible to a server-side request forgery (SSRF) from the application design interface allowing for some information disclosure of internal resources.
1Mybb
2Merge System
Mybb
May 13, 2026
Jan 31, 2017
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
The fetch_remote_file function in MyBB (aka MyBulletinBoard) before 1.8.8 and MyBB Merge System before 1.8.8 allows remote attackers to conduct server-side request forgery (SSRF) attacks via unspecified vectors.
1Phpmyadmin
1Phpmyadmin
May 13, 2026
Jan 31, 2017
N/A· v4
8.6 HIGH· v3
5.0 MEDIUM· v2
The setup script for phpMyAdmin before 4.0.10.19, 4.4.x before 4.4.15.10, and 4.6.x before 4.6.6 allows remote attackers to conduct server-side request forgery (SSRF) attacks via unspecified vectors.
1Spip
1Spip
May 13, 2026
Jan 18, 2017
N/A· v4
7.4 HIGH· v3
4.3 MEDIUM· v2
ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to conduct server side request forgery (SSRF) attacks via a URL in the var_url parameter in a valider_xml action.
1Metalgenix
1Genixcms
May 13, 2026
Jan 17, 2017
N/A· v4
7.4 HIGH· v3
4.3 MEDIUM· v2
The media-file upload feature in GeniXCMS through 0.0.8 allows remote attackers to conduct SSRF attacks via a URL, as demonstrated by a URL with an intranet IP address.
1Open Xchange
1Open Xchange Appsuite
May 6, 2026
Dec 15, 2016
N/A· v4
5.8 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in Open-Xchange OX App Suite before 7.8.1-rev11. The API to configure external mail accounts can be abused to map and access network components within the trust boundary of the operator. Users can...Show more
An issue was discovered in Open-Xchange OX App Suite before 7.8.1-rev11. The API to configure external mail accounts can be abused to map and access network components within the trust boundary of the operator. Users can inject arbitrary hosts and ports to API calls. Depending on the response type, content and latency, information about existence of hosts and services can be gathered. Attackers can get internal configuration information about the infrastructure of an operator to prepare subsequent attacks.Show less