CWE-918
Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
2,708 vulnerabilities with CWE-918
CVE-2025-26990
MEDIUM
Royal Elementor Addons <= 1.7.1006 - Server-Side Request Forgery
CVSS 4.4
CVE-2025-31490
HIGH
AutoGPT Platform < 0.6.1 - Server-Side Request Forgery via DNS Rebinding
CVSS 7.5
CVE-2025-29720
MEDIUM
Dify v1.0 - Server-Side Request Forgery via RemoteFileUploadApi
CVSS 4.8
CVE-2025-3572
HIGH
intumit smartrobot_firmware < 8.0.0 - Unauthenticated Server-Side Request Forgery
CVSS 7.5
CVE-2025-22374
MEDIUM
Videx's CyberAudit-Web <1.1.3 - SSRF
CVE-2025-0539
HIGH
Microsoft Windows - Privilege Escalation
CVSS 8.8
CVE-2025-32691
MEDIUM
PowerPress Podcasting <11.12.4 - SSRF
CVSS 4.9
CVE-2025-32675
MEDIUM
QuantumCloud SEO Help <6.6.0 - SSRF
CVSS 6.8
CVE-2025-32487
MEDIUM
Joe Waymark <= 1.5.2 - Server-Side Request Forgery
CVSS 4.9
CVE-2025-31009
MEDIUM
IndieBlocks <= 0.13.1 - Server-Side Request Forgery
CVSS 5.4
CVE-2025-32372
MEDIUM
Dnnsoftware Dotnetnuke < 9.13.8 - SSRF
CVSS 6.5
CVE-2025-3412
MEDIUM
AIAS InferController url - Server-Side Request Forgery
CVSS 6.3
CVE-2025-3411
MEDIUM
AIAS AsrController url - Server-Side Request Forgery
CVSS 6.3
CVE-2025-32013
HIGH
lnbits < 0.12.12 - Server-Side Request Forgery via LNURL Callback URL
CVSS 7.5
CVE-2025-32358
MEDIUM
Zammad 6.4.0-6.4.1 - Authenticated Server-Side Request Forgery via Webhook Redirect
CVSS 4.0
CVE-2025-3254
MEDIUM
xujiangfei admintwo 1.0 - Server-Side Request Forgery via /resource/add Description Parameter
CVSS 6.3
CVE-2025-2245
MEDIUM
Bitdefender GravityZone Update Server < 3.5.2.689 - Server-Side Request Forgery via Null-Byte Bypass
CVSS 5.3
CVE-2025-2243
HIGH
Bitdefender GravityZone < 6.41.2-1 - Server-Side Request Forgery via DNS Truncation Bypass
CVSS 7.3
CVE-2025-3192
HIGH
spatie/browsershot - Server-Side Request Forgery via setUrl() Function
CVSS 8.2
CVE-2025-31824
MEDIUM
Wombat Plugins WP Optin Wheel <1.4.7 - SSRF
CVSS 5.4
CVE-2025-31796
MEDIUM
ElementsCSS Addons for Elementor <1.0.8.7 - SSRF
CVSS 5.4
CVE-2025-21384
HIGH
Microsoft Azure Health Bot - Authenticated Server-Side Request Forgery
CVSS 8.3
CVE-2025-31117
HIGH
OpenEMR < 7.0.3.1 - Server-Side Request Forgery
CVSS 7.5
CVE-2025-31116
MEDIUM
Mobile Security Framework < 4.3.2 - Server-Side Request Forgery via DNS Rebinding
CVSS 4.4
CVE-2025-2997
MEDIUM
zhangyanbo2007 youkefu 4.2.0 - SSRF
CVSS 6.3
Details
Vulnerabilities
2,708