CWE-918
Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
2,678 vulnerabilities with CWE-918
CVE-2026-2948
MEDIUM
Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem <= 3.5.3 - Authenticated (Contributor+) Server-Side Request Forgery via 'imageUrl'
CVSS 6.4
CVE-2026-42140
MEDIUM
Server-Side Request Forgery (SSRF) in PlantUML Macro via 'server' parameter
CVSS 4.4
CVE-2026-7729
MEDIUM
pixelsock directus-mcp MCP index.ts validateUrl server-side request forgery
CVSS 6.3
CVE-2026-6229
HIGH
Royal Addons for Elementor <= 1.7.1057 - Authenticated (Contributor+) Server-Side Request Forgery via CSV URL Parameter
CVSS 7.2
CVE-2026-7605
MEDIUM
JeecgBoot uploadImgByHttpEndpoint CommonController.java HttpFileToMultipartFileUtil.downloadImageData server-side request forgery
CVSS 6.3
CVE-2026-7049
HIGH
PixelYourSite Pro <= 12.5.0.1 - Unauthenticated Blind Server-Side Request Forgery via 'urls[]' Parameter
CVSS 7.2
CVE-2026-6812
MEDIUM
Ona <= 1.26 - Authenticated (Administrator+) Blind Server-Side Request Forgery via 'download_link' Parameter
CVSS 4.4
CVE-2026-7604
MEDIUM
JeecgBoot OpenApi Service OpenApiController.java OpenApiController.call server-side request forgery
CVSS 6.3
CVE-2026-7603
MEDIUM
JeecgBoot LoadFile Endpoint FileDownloadUtils.jav checkPathTraversalBatch server-side request forgery
CVSS 6.3
CVE-2026-42404
MEDIUM
Apache Neethi: Unrestricted HTTP Redirect Following in Policy References
CVSS 6.5
CVE-2026-3340
MEDIUM
Server-Side Request Forgery (SSRF) in Langflow URL Component
CVSS 6.5
CVE-2026-36764
MEDIUM
SpringBlade 4.8.0 - Server-Side Request Forgery
CVSS 5.0
CVE-2026-36757
MEDIUM
Halo v2.22.14 - Server-Side Request Forgery
CVSS 4.3
CVE-2026-36759
MEDIUM
Halo v2.22.14 - Server-Side Request Forgery
CVSS 6.5
CVE-2026-36758
MEDIUM
Halo v2.22.14 - Server-Side Request Forgery
CVSS 4.3
CVE-2026-36756
MEDIUM
Halo v2.22.14 - Server-Side Request Forgery
CVSS 5.4
CVE-2026-7417
HIGH
Algovate xhs-mcp MCP mcp.server.ts xhs_publish_content server-side request forgery
CVSS 7.3
CVE-2026-42641
MEDIUM
WordPress Share This Image plugin <= 2.14 - Server Side Request Forgery (SSRF) vulnerability
CVSS 5.4
CVE-2026-23773
MEDIUM
Dell Disk Library for Mainframe DLm2700 and DLm8700 - Server-Side Request Forgery
CVSS 4.3
CVE-2026-7305
MEDIUM
Xuxueli xxl-job trigger Endpoint XxlJobServiceImpl.java triggerJob server-side request forgery
CVSS 6.3
CVE-2026-7291
MEDIUM
o2oa URL Fetching FileAction.java FileAction server-side request forgery
CVSS 6.3
CVE-2026-42430
MEDIUM
OpenClaw < 2026.4.8 - Strict Browser SSRF Bypass via Playwright Redirect Handling
CVSS 6.5
CVE-2026-41914
HIGH
OpenClaw < 2026.4.8 - Server-Side Request Forgery in QQ Bot Media Fetch Paths
CVSS 8.5
CVE-2026-41912
HIGH
OpenClaw < 2026.4.8 - Server-Side Request Forgery Policy Bypass via Interaction-Triggered Navigation
CVSS 7.6
CVE-2026-24231
MEDIUM
NVIDIA NemoClaw < 0.0.13 - Server-Side Request Forgery via validateEndpointUrl() Bypass
CVSS 6.3
Details
Vulnerabilities
2,678