CWE-918
Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
2,697 vulnerabilities with CWE-918
CVE-2026-24902
HIGH
TrustTunnel < 0.9.114 - Server-Side Request Forgery via Numeric IP Bypass
CVSS 7.1
CVE-2026-24767
MEDIUM
NocoDB < 0.301.0 - Server-Side Request Forgery via UploadViaURL HEAD Request
CVSS 4.9
CVE-2026-24779
HIGH
vllm < 0.14.1 - Server-Side Request Forgery via MediaConnector URL Host Parsing Bypass
CVSS 7.1
CVE-2026-24736
CRITICAL
Squidex < 7.21.0 - Server-Side Request Forgery via Webhook URL Parameter
CVSS 9.1
CVE-2026-0746
MEDIUM
WordPress AI Engine <= 3.3.2 get_audio - Subscriber Server-Side Request Forgery
CVSS 6.4
CVE-2026-22039
CRITICAL
Kyverno < 1.15.3 - Authenticated Server-Side Request Forgery via Namespaced Policy apiCall
CVSS 9.9
CVE-2026-24470
HIGH
Skipper <0.24.0 - Privilege Escalation
CVSS 8.1
CVE-2026-0807
HIGH
Frontis Blocks <= 1.1.6 - Unauthenticated SSRF via 'url' Parameter
CVSS 7.2
CVE-2026-24548
MEDIUM
Radio Player <= 2.0.91 - Server-Side Request Forgery
CVSS 5.4
CVE-2026-24138
HIGH
FOG Project <= 1.5.10.1754 getversion.php - Unauthenticated Server-Side Request Forgery
CVSS 7.5
CVE-2026-24117
MEDIUM
Rekor < 1.5.0 - Server-Side Request Forgery via Public Key Retrieval Endpoint
CVSS 5.3
CVE-2026-24381
MEDIUM
ThemeGoods PhotoMe < 5.7.2 - Server-Side Request Forgery
CVSS 5.4
CVE-2026-24360
MEDIUM
Craig Hewitt Seriously Simple Podcasting <4 - SSRF
CVSS 4.4
CVE-2026-22482
MEDIUM
wbolt.com IMGspider <= 2.3.12 - SSRF
CVSS 4.9
CVE-2026-22358
MEDIUM
SmartDataSoft Electrician - Electrical Service WordPress <=5.6 - SSRF
CVSS 5.4
CVE-2026-24048
LOW
Backstage backend-defaults < 0.12.2 - Server-Side Request Forgery via FetchUrlReader Redirect Handling
CVSS 3.5
CVE-2026-1180
MEDIUM
Keycloak - Server-Side Request Forgery via OpenID Connect Dynamic Client Registration
CVSS 5.8
CVE-2026-22219
HIGH
chainlit < 2.9.4 - Authenticated Server-Side Request Forgery via Project Element Update
CVSS 7.7
CVE-2026-23845
MEDIUM
Mailpit < 1.28.3 - Server-Side Request Forgery via HTML Check CSS Download
CVSS 5.8
CVE-2026-1062
MEDIUM
xiweicheng teamwork_management_system < 2.28.0 - Server-Side Request Forgery via HtmlUtil Summary Function
CVSS 6.3
CVE-2026-0682
LOW
Church Admin <= 5.0.28 - Authenticated Server-Side Request Forgery via audio_url Parameter
CVSS 2.2
CVE-2026-23529
HIGH
Kafka Connect BigQuery Connector <2.11.0 - Info Disclosure
CVSS 7.7
CVE-2026-0613
HIGH
The Librarian - Server-Side Request Forgery via web_fetch Tool
CVSS 7.5
CVE-2026-23768
MEDIUM
lucy-xss-filter < 2025-06-08 - Server-Side Request Forgery via Object/Embed Tag src Attribute
CVSS 6.1
CVE-2026-0600
MEDIUM
Sonatype Nexus Repository <3.88.0 - SSRF
Details
Vulnerabilities
2,697