CWE-918
Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
2,683 vulnerabilities with CWE-918
CVE-2026-26118
HIGH
Azure MCP Server - Authenticated Server-Side Request Forgery
CVSS 8.8
CVE-2026-24316
MEDIUM
SAP NetWeaver Application Server for ABAP - Server-Side Request Forgery via ABAP Test Report
CVSS 6.4
CVE-2026-25960
HIGH
vLLM 0.15.1-0.17.0 - Server-Side Request Forgery via URL Parsing Inconsistency
CVSS 7.1
CVE-2026-25737
HIGH
Budibase <=3.24.0 - Arbitrary File Upload
CVSS 8.9
CVE-2026-3588
HIGH
IKEA Dirigera < 2.866.4 - Server-Side Request Forgery
CVSS 7.5
CVE-2026-3789
MEDIUM
Bytedesk <= 1.3.9 - Server-Side Request Forgery via SpringAIGitee apiUrl
CVSS 6.3
CVE-2026-3788
MEDIUM
bytedesk < 1.4.5.4 - Server-Side Request Forgery via SpringAIOpenrouterRestController getModels Function
CVSS 6.3
CVE-2026-3750
MEDIUM
continew_admin < 4.1.0 - Server-Side Request Forgery via S3ClientFactory URI.create
CVSS 4.7
CVE-2026-3733
MEDIUM
xxl-job <= 3.3.2 - Server-Side Request Forgery
CVSS 6.3
CVE-2026-3683
MEDIUM
HotGo <= 2.0 - Server-Side Request Forgery via ImageTransferStorage Function
CVSS 6.3
CVE-2026-3681
MEDIUM
FFmate <= 2.0.15 - Server-Side Request Forgery via fireWebhook Function
CVSS 6.3
CVE-2026-30858
MEDIUM
WeKnora < 0.3.0 - Unauthenticated Server-Side Request Forgery via DNS Rebinding
CVSS 6.5
CVE-2026-30834
HIGH
PinchTab < 0.7.7 - Server-Side Request Forgery via Download Endpoint
CVSS 7.5
CVE-2026-30832
CRITICAL
Soft Serve 0.6.0-0.11.3 - Authenticated Server-Side Request Forgery via LFS Endpoint URL
CVSS 9.1
CVE-2026-30840
HIGH
wallos < 4.6.2 - Server-Side Request Forgery via Notification Tester
CVSS 8.8
CVE-2026-30839
MEDIUM
wallos < 4.6.2 - Server-Side Request Forgery via testwebhooknotifications.php
CVSS 4.3
CVE-2026-30828
HIGH
wallos < 4.6.2 - Server-Side Request Forgery via URL Parameter
CVSS 7.5
CVE-2026-27797
MEDIUM
homarr < 1.54.0 - Unauthenticated Server-Side Request Forgery
CVSS 5.3
CVE-2026-30247
MEDIUM
WeKnora < 0.2.12 - Server-Side Request Forgery via Redirect Chain Bypass
CVSS 5.9
CVE-2026-30242
HIGH
Plane < 1.2.3 - Authenticated Server-Side Request Forgery via Webhook URL Validation Bypass
CVSS 8.5
CVE-2026-30844
HIGH
Wekan 8.32-8.33 - Authenticated Server-Side Request Forgery via Attachment URL Loading
CVSS 8.1
CVE-2026-29178
HIGH
Lemmy < 0.19.16 - Unauthenticated Server-Side Request Forgery via Image Endpoint File Type Parameter
CVE-2026-29049
MEDIUM
melange < 0.40.5 - Server-Side Request Forgery via Unbounded URI Download
CVSS 4.3
CVE-2026-28680
CRITICAL
ghostfolio < 2.245.0 - Server-Side Request Forgery via Manual Asset Import Feature
CVSS 9.3
CVE-2026-28677
HIGH
OpenSift < 1.6.3 - Server-Side Request Forgery via URL Ingest Pipeline
CVSS 8.2
Details
Vulnerabilities
2,683