CWE-918

Server-Side Request Forgery (SSRF)

Parent: CWE-441 - Unintended Proxy or Intermediary ('Confused Deputy')

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

2,697 vulnerabilities with CWE-918
CVE-2026-24902 HIGH
TrustTunnel < 0.9.114 - Server-Side Request Forgery via Numeric IP Bypass
CVSS 7.1
CVE-2026-24767 MEDIUM
NocoDB < 0.301.0 - Server-Side Request Forgery via UploadViaURL HEAD Request
CVSS 4.9
CVE-2026-24779 HIGH
vllm < 0.14.1 - Server-Side Request Forgery via MediaConnector URL Host Parsing Bypass
CVSS 7.1
CVE-2026-24736 CRITICAL
Squidex < 7.21.0 - Server-Side Request Forgery via Webhook URL Parameter
CVSS 9.1
CVE-2026-0746 MEDIUM
WordPress AI Engine <= 3.3.2 get_audio - Subscriber Server-Side Request Forgery
CVSS 6.4
CVE-2026-22039 CRITICAL
Kyverno < 1.15.3 - Authenticated Server-Side Request Forgery via Namespaced Policy apiCall
CVSS 9.9
CVE-2026-24470 HIGH
Skipper <0.24.0 - Privilege Escalation
CVSS 8.1
CVE-2026-0807 HIGH
Frontis Blocks <= 1.1.6 - Unauthenticated SSRF via 'url' Parameter
CVSS 7.2
CVE-2026-24548 MEDIUM
Radio Player <= 2.0.91 - Server-Side Request Forgery
CVSS 5.4
CVE-2026-24138 HIGH
FOG Project <= 1.5.10.1754 getversion.php - Unauthenticated Server-Side Request Forgery
CVSS 7.5
CVE-2026-24117 MEDIUM
Rekor < 1.5.0 - Server-Side Request Forgery via Public Key Retrieval Endpoint
CVSS 5.3
CVE-2026-24381 MEDIUM
ThemeGoods PhotoMe < 5.7.2 - Server-Side Request Forgery
CVSS 5.4
CVE-2026-24360 MEDIUM
Craig Hewitt Seriously Simple Podcasting <4 - SSRF
CVSS 4.4
CVE-2026-22482 MEDIUM
wbolt.com IMGspider <= 2.3.12 - SSRF
CVSS 4.9
CVE-2026-22358 MEDIUM
SmartDataSoft Electrician - Electrical Service WordPress <=5.6 - SSRF
CVSS 5.4
CVE-2026-24048 LOW
Backstage backend-defaults < 0.12.2 - Server-Side Request Forgery via FetchUrlReader Redirect Handling
CVSS 3.5
CVE-2026-1180 MEDIUM
Keycloak - Server-Side Request Forgery via OpenID Connect Dynamic Client Registration
CVSS 5.8
CVE-2026-22219 HIGH
chainlit < 2.9.4 - Authenticated Server-Side Request Forgery via Project Element Update
CVSS 7.7
CVE-2026-23845 MEDIUM
Mailpit < 1.28.3 - Server-Side Request Forgery via HTML Check CSS Download
CVSS 5.8
CVE-2026-1062 MEDIUM
xiweicheng teamwork_management_system < 2.28.0 - Server-Side Request Forgery via HtmlUtil Summary Function
CVSS 6.3
CVE-2026-0682 LOW
Church Admin <= 5.0.28 - Authenticated Server-Side Request Forgery via audio_url Parameter
CVSS 2.2
CVE-2026-23529 HIGH
Kafka Connect BigQuery Connector <2.11.0 - Info Disclosure
CVSS 7.7
CVE-2026-0613 HIGH
The Librarian - Server-Side Request Forgery via web_fetch Tool
CVSS 7.5
CVE-2026-23768 MEDIUM
lucy-xss-filter < 2025-06-08 - Server-Side Request Forgery via Object/Embed Tag src Attribute
CVSS 6.1
CVE-2026-0600 MEDIUM
Sonatype Nexus Repository <3.88.0 - SSRF
Details
Vulnerabilities 2,697