CWE-918

Server-Side Request Forgery (SSRF)

Parent: CWE-441 - Unintended Proxy or Intermediary ('Confused Deputy')

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

2,742 vulnerabilities with CWE-918
CVE-2023-35817 MEDIUM
DevExpress < 23.1.3 - Server-Side Request Forgery via AsyncDownloader
CVSS 5.0
CVE-2023-6195 LOW
GitLab CE/EE <16.9.7, <16.10.5, <16.11.2 - SSRF
CVSS 2.6
CVE-2023-50733 HIGH
Lexmark Web Services - Server-Side Request Forgery
CVSS 8.6
CVE-2023-50913 CRITICAL
Oxide control plane software < 5 - Server-Side Request Forgery
CVSS 9.1
CVE-2023-37230 HIGH
Loftware Spectrum < 5.1 - Server-Side Request Forgery via testDeviceConnection
CVSS 8.8
CVE-2023-37229 HIGH
Loftware Spectrum < 5.1 - Server-Side Request Forgery
CVSS 8.8
CVE-2023-31456 MEDIUM
Fluid Topics < 4.3 - Authenticated Server-Side Request Forgery
CVSS 5.4
CVE-2023-50952 MEDIUM
IBM InfoSphere Information Server 11.7 - Authenticated Server-Side Request Forgery
CVSS 5.4
CVE-2023-45195 MEDIUM
AdminerEvo < 4.8.4 - Unauthenticated Server-Side Request Forgery via Database Connection Fields
CVSS 5.3
CVE-2023-7073 MEDIUM
WordPress Auto Featured Image <4.0.0 - SSRF
CVSS 6.4
CVE-2023-46784 HIGH
ICS Calendar <10.12.0.3 - Path Traversal
CVSS 8.2
CVE-2023-46295 CRITICAL
Teledyne FLIR M300 2.00-19 - Unauthenticated Remote Code Execution via PHP Page
CVSS 9.8
CVE-2023-7253 MEDIUM
Import WP < 2.13.1 - Authenticated Server-Side Request Forgery
CVSS 6.1
CVE-2023-6805 MEDIUM
RSS Aggregator by Feedzy < 4.4.7 - Authenticated Blind Server-Side Request Forgery via fetch_feed
CVSS 6.4
CVE-2023-40148 MEDIUM
PingFederate 11.0-11.3 - Unauthenticated Server-Side Request Forgery
CVSS 6.5
CVE-2023-6964 HIGH
Kadence Blocks < 3.1.26 - Authenticated SSRF via kadence_import_get_new_connection_data
CVSS 8.5
CVE-2023-45705 LOW
HCL BigFix Platform 10.0.0-10.0.10 - Authenticated Server-Side Request Forgery via SMTP Configuration
CVSS 3.5
CVE-2023-50374 MEDIUM
CMP - Coming Soon & Maintenance < 4.1.10 - Server-Side Request Forgery
CVSS 5.5
CVE-2023-39313 HIGH
ThemeFusion Avada < 7.11.1 - Authenticated Server-Side Request Forgery
CVSS 7.7
CVE-2023-36679 HIGH
Brainstorm Force Spectra <= 2.6.6 - Server-Side Request Forgery
CVSS 7.1
CVE-2023-34370 HIGH
Brainstorm Force Starter Templates - SSRF
CVSS 7.1
CVE-2023-49785 CRITICAL
NextChat < 2.11.2 - Server-Side Request Forgery and Cross-Site Scripting
CVSS 9.1
CVE-2023-47635 MEDIUM
Decidim 0.23.0-0.27.4 - Server-Side Request Forgery via Questionnaire Templates Preview
CVSS 4.5
CVE-2023-5122 MEDIUM
Grafana CSV Datasource Plugin - Server-Side Request Forgery via Bare Host URL
CVSS 5.0
CVE-2023-6294 HIGH
Popup Builder < 4.2.6 - Authenticated Server-Side Request Forgery via Unvalidated Parameter
CVSS 7.2
Details
Vulnerabilities 2,742