CWE-918

Server-Side Request Forgery (SSRF)

Parent: CWE-441 - Unintended Proxy or Intermediary ('Confused Deputy')

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

2,740 vulnerabilities with CWE-918
CVE-2024-36675 CRITICAL
lylme_spage 1.9.5 - Server-Side Request Forgery via get_head Function
CVSS 9.1
CVE-2024-4219 MEDIUM
BeyondInsight < 23.2 - Server-Side Request Forgery via HTTP-based Connectors
CVSS 4.8
CVE-2024-35635 MEDIUM
Ninja Tables < 5.0.9 - Server-Side Request Forgery
CVSS 4.4
CVE-2024-35633 MEDIUM
Blocksy Companion <= 2.0.42 - Server-Side Request Forgery
CVSS 4.4
CVE-2024-35637 MEDIUM
Church Admin < 4.3.6 - Server-Side Request Forgery
CVSS 4.4
CVE-2024-4469 HIGH
WP STAGING < 3.5.0 - Authenticated Server-Side Request Forgery
CVSS 7.5
CVE-2024-36427 HIGH
TARGIT Decision Suite <24.06.19002 - Authenticated Code Execution
CVSS 8.1
CVE-2024-29415 HIGH
Node ip package <=2.0.1 - Server-Side Request Forgery via IP Misclassification
CVSS 8.1
CVE-2024-4399 CRITICAL
Apero Central Authentication Service - Unauthenticated Server-Side Request Forgery
CVSS 9.1
CVE-2024-1855 MEDIUM
WPCafe < 2.2.23 - Unauthenticated Server-Side Request Forgery via wpc_check_for_submission
CVSS 5.3
CVE-2024-25738 CRITICAL
VuFind 2.0-9.1 - Server-Side Request Forgery via /Upgrade/FixConfig Route
CVSS 9.1
CVE-2024-5031 HIGH
MemberPress < 1.11.29 - Authenticated Blind Server-Side Request Forgery via mepr-user-file Shortcode
CVSS 8.5
CVE-2024-30420 MEDIUM
a-blog cms 3.0.0-3.0.31 and 3.1.0-3.1.11 - Authenticated Server-Side Request Forgery
CVSS 4.4
CVE-2024-4789 MEDIUM
Cost Calculator Builder Pro <3.1.72 - SSRF
CVSS 6.4
CVE-2024-3970 MEDIUM
OpenText iManager <3.2.6.0200 - SSRF
CVSS 5.3
CVE-2024-3485 MEDIUM
OpenText iManager 3.0-3.2.6 - Server-Side Request Forgery
CVSS 5.3
CVE-2024-4894 MEDIUM
ITPison OMICARD EDM < 6.0 - Unauthenticated Server-Side Request Forgery via URL Parameter
CVSS 5.3
CVE-2024-4562 MEDIUM
WhatsUp Gold < 23.1.2 - Authenticated Server-Side Request Forgery in HTTP Monitoring
CVSS 5.4
CVE-2024-4561 MEDIUM
WhatsUp Gold < 23.1.2 - Server-Side Request Forgery via FaviconController
CVSS 4.2
CVE-2024-0862 MEDIUM
Proofpoint Enterprise Protection - SSRF
CVSS 5.0
CVE-2024-33864 MEDIUM
linqi < 1.4.0.1 - Server-Side Request Forgery via Document Template Generation
CVSS 5.9
CVE-2024-35172 MEDIUM
ShortPixel Adaptive Images <3.8.3 - SSRF
CVSS 4.4
CVE-2024-34351 HIGH
Next.js 13.4.0-14.1.1 - Server-Side Request Forgery via Server Actions Redirect
CVSS 7.5
CVE-2024-33250 HIGH
Open-Source Technology Committee SRS <4.0.268,4.0.195 - RCE
CVSS 7.2
CVE-2024-32964 CRITICAL
lobehub/lobe_chat < 0.150.6 - Unauthenticated Server-Side Request Forgery via /api/proxy Endpoint
CVSS 9.0
Details
Vulnerabilities 2,740