CWE-918

Server-Side Request Forgery (SSRF)

Parent: CWE-441 - Unintended Proxy or Intermediary ('Confused Deputy')

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

2,708 vulnerabilities with CWE-918
CVE-2025-26990 MEDIUM
Royal Elementor Addons <= 1.7.1006 - Server-Side Request Forgery
CVSS 4.4
CVE-2025-31490 HIGH
AutoGPT Platform < 0.6.1 - Server-Side Request Forgery via DNS Rebinding
CVSS 7.5
CVE-2025-29720 MEDIUM
Dify v1.0 - Server-Side Request Forgery via RemoteFileUploadApi
CVSS 4.8
CVE-2025-3572 HIGH
intumit smartrobot_firmware < 8.0.0 - Unauthenticated Server-Side Request Forgery
CVSS 7.5
CVE-2025-22374 MEDIUM
Videx's CyberAudit-Web <1.1.3 - SSRF
CVE-2025-0539 HIGH
Microsoft Windows - Privilege Escalation
CVSS 8.8
CVE-2025-32691 MEDIUM
PowerPress Podcasting <11.12.4 - SSRF
CVSS 4.9
CVE-2025-32675 MEDIUM
QuantumCloud SEO Help <6.6.0 - SSRF
CVSS 6.8
CVE-2025-32487 MEDIUM
Joe Waymark <= 1.5.2 - Server-Side Request Forgery
CVSS 4.9
CVE-2025-31009 MEDIUM
IndieBlocks <= 0.13.1 - Server-Side Request Forgery
CVSS 5.4
CVE-2025-32372 MEDIUM
Dnnsoftware Dotnetnuke < 9.13.8 - SSRF
CVSS 6.5
CVE-2025-3412 MEDIUM
AIAS InferController url - Server-Side Request Forgery
CVSS 6.3
CVE-2025-3411 MEDIUM
AIAS AsrController url - Server-Side Request Forgery
CVSS 6.3
CVE-2025-32013 HIGH
lnbits < 0.12.12 - Server-Side Request Forgery via LNURL Callback URL
CVSS 7.5
CVE-2025-32358 MEDIUM
Zammad 6.4.0-6.4.1 - Authenticated Server-Side Request Forgery via Webhook Redirect
CVSS 4.0
CVE-2025-3254 MEDIUM
xujiangfei admintwo 1.0 - Server-Side Request Forgery via /resource/add Description Parameter
CVSS 6.3
CVE-2025-2245 MEDIUM
Bitdefender GravityZone Update Server < 3.5.2.689 - Server-Side Request Forgery via Null-Byte Bypass
CVSS 5.3
CVE-2025-2243 HIGH
Bitdefender GravityZone < 6.41.2-1 - Server-Side Request Forgery via DNS Truncation Bypass
CVSS 7.3
CVE-2025-3192 HIGH
spatie/browsershot - Server-Side Request Forgery via setUrl() Function
CVSS 8.2
CVE-2025-31824 MEDIUM
Wombat Plugins WP Optin Wheel <1.4.7 - SSRF
CVSS 5.4
CVE-2025-31796 MEDIUM
ElementsCSS Addons for Elementor <1.0.8.7 - SSRF
CVSS 5.4
CVE-2025-21384 HIGH
Microsoft Azure Health Bot - Authenticated Server-Side Request Forgery
CVSS 8.3
CVE-2025-31117 HIGH
OpenEMR < 7.0.3.1 - Server-Side Request Forgery
CVSS 7.5
CVE-2025-31116 MEDIUM
Mobile Security Framework < 4.3.2 - Server-Side Request Forgery via DNS Rebinding
CVSS 4.4
CVE-2025-2997 MEDIUM
zhangyanbo2007 youkefu 4.2.0 - SSRF
CVSS 6.3
Details
Vulnerabilities 2,708