CWE-918

Server-Side Request Forgery (SSRF)

Parent: CWE-441 - Unintended Proxy or Intermediary ('Confused Deputy')

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

2,441 vulnerabilities with CWE-918
CVE-2026-2290 LOW
Post Affiliate Pro <= 1.28.0 - Authenticated (Administrator+) Server-Side Request Forgery via 'Post Affiliate Pro URL' Field
CVSS 3.8
CVE-2026-1648 HIGH
Performance Monitor <= 1.0.6 - Unauthenticated Server-Side Request Forgery via 'url' Parameter
CVSS 7.2
CVE-2026-1313 HIGH
MimeTypes Link Icons <= 3.2.20 - Authenticated (Contributor+) Server-Side Request Forgery via Crafted Links in Post Content
CVSS 8.3
CVE-2026-4302 HIGH
WowOptin: Next-Gen Popup Maker <= 1.4.29 - Unauthenticated Server-Side Request Forgery via 'link' Parameter in REST API
CVSS 7.2
CVE-2026-33237 MEDIUM
AVideo has SSRF in Scheduler Plugin via callbackURL Missing `isSSRFSafeURL()` Validation
CVSS 5.5
CVE-2026-33226 HIGH
Budibase Unrestricted Server-Side Request Forgery (SSRF) via REST Datasource Query Preview
CVSS 8.7
CVE-2026-33126 MEDIUM
Frigate has SSRF vulnerability in /ffprobe endpoint
CVSS 5.0
CVE-2026-33081 MEDIUM
PinchTab has Blind SSRF via browser-side redirect bypass in /download URL validation
CVSS 5.8
CVE-2026-33060 MEDIUM
CKAN MCP Server: SSRF via base_url allows access to internal networks
CVSS 5.3
CVE-2026-33039 HIGH
AVideo vulnerable to unauthenticated SSRF via HTTP redirect bypass in LiveLinks proxy
CVSS 8.6
CVE-2026-33024 CRITICAL
AVideo-Encoder has Unauthenticated Blind Server-Side Request Forgery via Public Thumbnail Generator
CVSS 9.1
CVE-2026-32949 HIGH
SQLBot: SSRF to Arbitrary File Read (AFR) via Rogue MySQL
CVE-2026-32812 MEDIUM
Admidio Vulnerable to SSRF and Local File Read via Unrestricted URL Fetch in SSO Metadata Endpoint
CVSS 6.8
CVE-2026-32828 MEDIUM
Kargo: SSRF in Promotion http/http-download Steps Enables Internal Network Access and Data Exfiltration
CVSS 4.9
CVE-2026-29107 MEDIUM
SuiteCRM vulnerable to authenticated SSRF via PDF export
CVSS 5.0
CVE-2026-29097 HIGH
SuiteCRM Server-Side Request Forgery and Denial of Service via RSS Feed Dashlet
CVSS 7.5
CVE-2026-32037 MEDIUM
OpenClaw < 2026.2.22 - Redirect Chain Bypass of Media Host Allowlist in MSTeams Attachment Handling
CVSS 6.0
CVE-2026-32019 HIGH
OpenClaw < 2026.2.22 - Incomplete IPv4 Special-Use Range Blocking in SSRF Guard
CVSS 7.4
CVE-2026-33321 HIGH
OpenEMR has Out-of-Band Server-Side Request Forgery (OOB SSRF)
CVSS 7.6
CVE-2026-32169 CRITICAL
Azure Cloud Shell Elevation of Privilege Vulnerability
CVSS 10.0
CVE-2026-26139 HIGH
Microsoft Purview Elevation of Privilege Vulnerability
CVSS 8.6
CVE-2026-26138 HIGH
Microsoft Purview Elevation of Privilege Vulnerability
CVSS 8.6
CVE-2026-26137 CRITICAL
Microsoft 365 Copilot BizChat Elevation of Privilege Vulnerability
CVSS 9.9
CVE-2026-26120 MEDIUM
Microsoft Bing Tampering Vulnerability
CVSS 6.5
CVE-2026-30404 HIGH
wgcloud v3.6.3 - SSRF
CVSS 7.5
Details
Vulnerabilities 2,441