CWE-918

Server-Side Request Forgery (SSRF)

Parent: CWE-441 - Unintended Proxy or Intermediary ('Confused Deputy')

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

2,740 vulnerabilities with CWE-918
CVE-2024-30531 MEDIUM
Nelio Content < 3.2.0 - Server-Side Request Forgery
CVSS 4.9
CVE-2024-24888 MEDIUM
Kadence WP Gutenberg Blocks <3.2.25 - SSRF
CVSS 6.4
CVE-2024-25187 HIGH
71cms 1.0.0 - Unauthenticated Server-Side Request Forgery via getweather.html
CVSS 8.6
CVE-2024-30453 MEDIUM
Brave Popup Builder < 0.6.5 - Server-Side Request Forgery
CVSS 5.4
CVE-2024-27775 HIGH
SysAid < 23.2.14 b18 - Server-Side Request Forgery
CVSS 7.2
CVE-2024-29090 MEDIUM
Jordy Meow AI Engine: ChatGPT Chatbot <= 2.1.4 - Authenticated Server-Side Request Forgery
CVSS 6.8
CVE-2024-23500 HIGH
Gutenberg Blocks by Kadence Blocks <= 3.2.19 - Server-Side Request Forgery
CVSS 7.7
CVE-2024-0677 MEDIUM
Pz-LinkCard < 2.5.3 - Authenticated Server-Side Request Forgery via Shortcode
CVSS 5.1
CVE-2024-2206 MEDIUM
gradio < 4.18.0 - Server-Side Request Forgery via Proxy Route URL Validation
CVSS 6.5
CVE-2024-28435 MEDIUM
Twenty CRM 0.3.0 - Server-Side Request Forgery via File Upload
CVSS 5.4
CVE-2024-29190 HIGH
MobSF <= 3.9.5 Beta - android:host Server-Side Request Forgery
CVSS 7.5
CVE-2024-2828 MEDIUM
lakernote EasyAdmin < 2024-03-15 - Server-Side Request Forgery via Thumbnail URL Parameter
CVSS 6.3
CVE-2024-2827 MEDIUM
lakernote easyadmin < 2024-03-15 - Server-Side Request Forgery via /ureport/designer/saveReportFile
CVSS 6.3
CVE-2024-27927 MEDIUM
RSSHub <1.0.0-master.a429472 - Server-Side Request Forgery via Arbitrary HTTP Fetch
CVSS 6.5
CVE-2024-24028 MEDIUM
Likeshop < 2.5.7 - Server-Side Request Forgery via Avatar Parameter
CVSS 5.9
CVE-2024-25294 CRITICAL
REBUILD 3.5 - Server-Side Request Forgery via FileDownloader.java Proxy Download URL Parameter
CVSS 9.1
CVE-2024-27098 MEDIUM
GLPI 9.5.0-10.0.12 - Authenticated Server-Side Request Forgery via Arbitrary Object Instantiation
CVSS 6.4
CVE-2024-28752 CRITICAL
Apache CXF < 3.5.8 - Server-Side Request Forgery via Aegis DataBinding
CVSS 9.3
CVE-2024-1884 MEDIUM
PaperCut NG/MF < 20.1.10 - Server-Side Request Forgery
CVSS 6.5
CVE-2024-28668 MEDIUM
DedeCMS 5.7 - Cross-Site Request Forgery in mychannel_add.php
CVSS 6.1
CVE-2024-2049 MEDIUM
Citrix SD-WAN Standard/Premium Editions 11.4.0-11.4.4.46 - Server-Side Request Forgery via Management IP Access
CVSS 6.5
CVE-2024-27707 MEDIUM
Huly Platform 0.6.202 - Server-Side Request Forgery via SVG File Upload
CVSS 4.3
CVE-2024-27565 CRITICAL
ChatGPT-wechat-personal <a0857f6 - SSRF
CVSS 9.8
CVE-2024-27564 MEDIUM
ChatGPT个人专用版 - Server Side Request Forgery
CVSS 5.8
CVE-2024-27563 MEDIUM
WonderCMS 3.1.3 - Server-Side Request Forgery via PluginThemeUrl Parameter
CVSS 5.3
Details
Vulnerabilities 2,740