CWE-918
Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
2,441 vulnerabilities with CWE-918
CVE-2026-2290
LOW
Post Affiliate Pro <= 1.28.0 - Authenticated (Administrator+) Server-Side Request Forgery via 'Post Affiliate Pro URL' Field
CVSS 3.8
CVE-2026-1648
HIGH
Performance Monitor <= 1.0.6 - Unauthenticated Server-Side Request Forgery via 'url' Parameter
CVSS 7.2
CVE-2026-1313
HIGH
MimeTypes Link Icons <= 3.2.20 - Authenticated (Contributor+) Server-Side Request Forgery via Crafted Links in Post Content
CVSS 8.3
CVE-2026-4302
HIGH
WowOptin: Next-Gen Popup Maker <= 1.4.29 - Unauthenticated Server-Side Request Forgery via 'link' Parameter in REST API
CVSS 7.2
CVE-2026-33237
MEDIUM
AVideo has SSRF in Scheduler Plugin via callbackURL Missing `isSSRFSafeURL()` Validation
CVSS 5.5
CVE-2026-33226
HIGH
Budibase Unrestricted Server-Side Request Forgery (SSRF) via REST Datasource Query Preview
CVSS 8.7
CVE-2026-33126
MEDIUM
Frigate has SSRF vulnerability in /ffprobe endpoint
CVSS 5.0
CVE-2026-33081
MEDIUM
PinchTab has Blind SSRF via browser-side redirect bypass in /download URL validation
CVSS 5.8
CVE-2026-33060
MEDIUM
CKAN MCP Server: SSRF via base_url allows access to internal networks
CVSS 5.3
CVE-2026-33039
HIGH
AVideo vulnerable to unauthenticated SSRF via HTTP redirect bypass in LiveLinks proxy
CVSS 8.6
CVE-2026-33024
CRITICAL
AVideo-Encoder has Unauthenticated Blind Server-Side Request Forgery via Public Thumbnail Generator
CVSS 9.1
CVE-2026-32949
HIGH
SQLBot: SSRF to Arbitrary File Read (AFR) via Rogue MySQL
CVE-2026-32812
MEDIUM
Admidio Vulnerable to SSRF and Local File Read via Unrestricted URL Fetch in SSO Metadata Endpoint
CVSS 6.8
CVE-2026-32828
MEDIUM
Kargo: SSRF in Promotion http/http-download Steps Enables Internal Network Access and Data Exfiltration
CVSS 4.9
CVE-2026-29107
MEDIUM
SuiteCRM vulnerable to authenticated SSRF via PDF export
CVSS 5.0
CVE-2026-29097
HIGH
SuiteCRM Server-Side Request Forgery and Denial of Service via RSS Feed Dashlet
CVSS 7.5
CVE-2026-32037
MEDIUM
OpenClaw < 2026.2.22 - Redirect Chain Bypass of Media Host Allowlist in MSTeams Attachment Handling
CVSS 6.0
CVE-2026-32019
HIGH
OpenClaw < 2026.2.22 - Incomplete IPv4 Special-Use Range Blocking in SSRF Guard
CVSS 7.4
CVE-2026-33321
HIGH
OpenEMR has Out-of-Band Server-Side Request Forgery (OOB SSRF)
CVSS 7.6
CVE-2026-32169
CRITICAL
Azure Cloud Shell Elevation of Privilege Vulnerability
CVSS 10.0
CVE-2026-26139
HIGH
Microsoft Purview Elevation of Privilege Vulnerability
CVSS 8.6
CVE-2026-26138
HIGH
Microsoft Purview Elevation of Privilege Vulnerability
CVSS 8.6
CVE-2026-26137
CRITICAL
Microsoft 365 Copilot BizChat Elevation of Privilege Vulnerability
CVSS 9.9
CVE-2026-26120
MEDIUM
Microsoft Bing Tampering Vulnerability
CVSS 6.5
CVE-2026-30404
HIGH
wgcloud v3.6.3 - SSRF
CVSS 7.5
Details
Vulnerabilities
2,441