CWE-918— Server-Side Request Forgery (SSRF)
2,376 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-918page 1 of 48
- CVE-2007-6758HIGHCVSS 7.5EG 7.52020-01-23
Server-side request forgery (SSRF) vulnerability in feed-proxy.php in extjs 5.0.0.
- CVE-2010-1637MEDIUMCVSS 6.5EG 6.52010-06-22
The Mail Fetch plugin in SquirrelMail 1.4.20 and earlier allows remote authenticated users to bypass firewall restrictions and use SquirrelMail as a proxy to scan internal networks via a modified POP3 port number.
- CVE-2012-10018HIGHCVSS 8.3EG 8.32024-10-16
The Mapplic and Mapplic Lite plugins for WordPress are vulnerable to Server-Side Request Forgery in versions up to, and including 6.1, 1.0 respectively. This makes it possible for attackers to forgery requests coming from a vulnerable site…
- CVE-2013-4864CRITICALCVSS 9.8EG 9.82020-01-28
MiCasaVerde VeraLite with firmware 1.5.408 allows remote attackers to send HTTP requests to intranet servers via the url parameter to cgi-bin/cmh/proxy.sh, related to a Server-Side Request Forgery (SSRF) issue.
- CVE-2014-3990CRITICALCVSS 9.8EG 9.82018-03-20
The Cart::getProducts method in system/library/cart.php in OpenCart 1.5.6.4 and earlier allows remote attackers to conduct server-side request forgery (SSRF) attacks or possibly conduct XML External Entity (XXE) attacks and execute arbitra…
- CVE-2014-8943HIGHCVSS 8.8EG 8.82020-06-01
Lexiglot through 2014-11-20 allows SSRF via the admin.php?page=projects svn_url parameter.
- CVE-2016-10926CRITICALCVSS 10.0EG 10.02019-08-22
The nelio-ab-testing plugin before 4.5.9 for WordPress has SSRF in ajax/iesupport.php.
- CVE-2016-10927CRITICALCVSS 10.0EG 10.02019-08-22
The nelio-ab-testing plugin before 4.5.11 for WordPress has SSRF in ajax/iesupport.php.
- CVE-2016-3718MEDIUMCVSS 5.5EG 9.0⚠ KEV2016-05-05
The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted image.
- CVE-2017-0929HIGHCVSS 7.5EG 9.02018-07-03
DNN (aka DotNetNuke) before 9.2.0 suffers from a Server-Side Request Forgery (SSRF) vulnerability in the DnnImageHandler class. Attackers may be able to access information about internal network resources.
- CVE-2017-1000419HIGHCVSS 7.5EG 7.52018-01-02
phpBB version 3.2.0 is vulnerable to SSRF in the Remote Avatar function resulting allowing an attacker to perform port scanning, requesting internal content and potentially attacking such internal services via the web application.
- CVE-2017-13667CRITICALCVSS 9.9EG 9.92019-05-23
OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: SSRF.
- CVE-2017-14323CRITICALCVSS 9.8EG 9.82018-04-10
SSRF (Server Side Request Forgery) in getRemoteImage.php in Ueditor in Onethink V1.0 and V1.1 allows remote attackers to obtain sensitive information, attack intranet hosts, or possibly trigger remote command execution via the upfile param…
- CVE-2017-14611CRITICALCVSS 9.1EG 9.12018-04-10
SSRF (Server Side Request Forgery) in Cockpit 0.13.0 allows remote attackers to read arbitrary files or send TCP traffic to intranet hosts via the url parameter, related to use of the discontinued aheinze/fetch_url_contents component.
- CVE-2017-15029MEDIUMCVSS 4.3EG 4.32019-05-23
Open-Xchange GmbH OX App Suite 7.8.4 and earlier is affected by: SSRF.
- CVE-2017-16614CRITICALCVSS 9.8EG 9.82018-03-30
SSRF (Server Side Request Forgery) in tpshop 2.0.5 and 2.0.6 allows remote attackers to obtain sensitive information, attack intranet hosts, or possibly trigger remote command execution via the plugins/payment/weixin/lib/WxPay.tedatac.php …
- CVE-2017-16865MEDIUMCVSS 5.3EG 5.32018-01-17
The Trello importer in Atlassian Jira before version 7.6.1 allows remote attackers to access the content of internal network resources via a Server Side Request Forgery (SSRF). When running in an environment like Amazon EC2, this flaw mayb…
- CVE-2017-17674CRITICALCVSS 9.8EG 9.82021-05-19
BMC Remedy Mid Tier 9.1SP3 is affected by remote and local file inclusion. Due to the lack of restrictions on what can be targeted, the system can be vulnerable to attacks such as system fingerprinting, internal port scanning, Server Side …
- CVE-2017-18036MEDIUMCVSS 4.3EG 4.32018-02-02
The Github repository importer in Atlassian Bitbucket Server before version 5.3.0 allows remote attackers to determine if a service they could not otherwise reach has open ports via a Server Side Request Forgery (SSRF) vulnerability.
- CVE-2017-18096HIGHCVSS 7.2EG 7.22018-04-04
The OAuth status rest resource in Atlassian Application Links before version 5.2.7, from 5.3.0 before 5.3.4 and from 5.4.0 before 5.4.3 allows remote attackers with administrative rights to access the content of internal network resources …
- CVE-2017-18638HIGHCVSS 7.5EG 9.02019-10-11
send_email in graphite-web/webapp/graphite/composer/views.py in Graphite through 1.1.5 is vulnerable to SSRF. The vulnerable SSRF endpoint can be used by an attacker to have the Graphite web server request any resource. The response to thi…
- CVE-2017-20106MEDIUMCVSS 5.3EG 4.42022-06-28
A vulnerability, which was classified as critical, has been found in Lithium Forum 2017 Q1. This issue affects some unknown processing of the component Compose Message Handler. The manipulation of the argument upload_url leads to server-si…
- CVE-2017-20157MEDIUMCVSS 5.5EG 5.52022-12-31
A vulnerability was found in Ariadne Component Library up to 2.x. It has been classified as critical. Affected is an unknown function of the file src/url/Url.php. The manipulation leads to server-side request forgery. Upgrading to version …
- CVE-2017-3164HIGHCVSS 7.5EG 7.52019-03-08
Server Side Request Forgery in Apache Solr, versions 1.3 until 7.6 (inclusive). Since the "shards" parameter does not have a corresponding whitelist mechanism, a remote attacker with access to the server could make Solr perform an HTTP GET…
- CVE-2017-6201HIGHCVSS 8.1EG 8.12018-02-06
A Server Side Request Forgery vulnerability exists in the install app process in Sandstorm before build 0.203. A remote attacker may exploit this issue by providing a URL. It could bypass access control such as firewalls that prevent the a…
- CVE-2018-0398CRITICALCVSS 9.8EG 9.82018-07-18
Multiple vulnerabilities in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct a server-side request forgery (SSRF) attack. Cisco Bug IDs: CSCvg71018.
- CVE-2018-0399CRITICALCVSS 9.8EG 9.82018-07-18
Multiple vulnerabilities in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to retrieve a cleartext password from an affected system. Cisco Bug IDs: CSCvg71044.
- CVE-2018-0403CRITICALCVSS 9.8EG 9.82018-07-18
Multiple vulnerabilities in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to retrieve a cleartext password. Cisco Bug IDs: CSCvg71040.
- CVE-2018-1000054HIGHCVSS 8.3EG 8.32018-02-09
Jenkins CCM Plugin 3.1 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with user permissions in Jenkins to extract secrets from the Jenkins master, perform server-side request…
- CVE-2018-1000055HIGHCVSS 8.3EG 8.32018-02-09
Jenkins Android Lint Plugin 2.5 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with user permissions in Jenkins to extract secrets from the Jenkins master, perform server-sid…
- CVE-2018-1000056HIGHCVSS 8.3EG 8.32018-02-09
Jenkins JUnit Plugin 1.23 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with user permissions in Jenkins to extract secrets from the Jenkins master, perform server-side requ…
- CVE-2018-1000067MEDIUMCVSS 5.3EG 5.32018-02-16
An improper authorization vulnerability exists in Jenkins versions 2.106 and earlier, and LTS 2.89.3 and earlier, that allows an attacker to have Jenkins submit HTTP GET requests and get limited information about the response.
- CVE-2018-1000124CRITICALCVSS 10.0EG 10.02018-03-13
I Librarian I-librarian version 4.8 and earlier contains a XML External Entity (XXE) vulnerability in line 154 of importmetadata.php(simplexml_load_string) that can result in an attacker reading the contents of a file and SSRF. This attack…
- CVE-2018-1000138CRITICALCVSS 9.1EG 9.12018-03-23
I, Librarian version 4.8 and earlier contains a SSRF vulnerability in "url" parameter of getFromWeb in functions.php that can result in the attacker abusing functionality on the server to read or update internal resources.
- CVE-2018-1000182MEDIUMCVSS 6.4EG 6.42018-06-05
A server-side request forgery vulnerability exists in Jenkins Git Plugin 3.9.0 and older in AssemblaWeb.java, GitBlitRepositoryBrowser.java, Gitiles.java, TFS2013GitRepositoryBrowser.java, ViewGitWeb.java that allows attackers with Overall…
- CVE-2018-1000184MEDIUMCVSS 5.4EG 5.42018-06-05
A server-side request forgery vulnerability exists in Jenkins GitHub Plugin 1.29.0 and older in GitHubPluginConfig.java that allows attackers with Overall/Read access to cause Jenkins to send a GET request to a specified URL.
- CVE-2018-1000185MEDIUMCVSS 4.3EG 4.32018-06-05
A server-side request forgery vulnerability exists in Jenkins GitHub Branch Source Plugin 2.3.4 and older in Endpoint.java that allows attackers with Overall/Read access to cause Jenkins to send a GET request to a specified URL.
- CVE-2018-1000188MEDIUMCVSS 5.4EG 5.42018-06-05
A server-side request forgery vulnerability exists in Jenkins CAS Plugin 1.4.1 and older in CasSecurityRealm.java that allows attackers with Overall/Read access to cause Jenkins to send a GET request to a specified URL.
- CVE-2018-1000421MEDIUMCVSS 6.5EG 6.52019-01-09
An improper authorization vulnerability exists in Jenkins Mesos Plugin 0.17.1 and earlier in MesosCloud.java that allows attackers with Overall/Read access to initiate a test connection to an attacker-specified Mesos server with attacker-s…
- CVE-2018-1000422MEDIUMCVSS 6.5EG 6.52019-01-09
An improper authorization vulnerability exists in Jenkins Crowd 2 Integration Plugin 2.0.0 and earlier in CrowdSecurityRealm.java that allows attackers to have Jenkins perform a connection test, connecting to an attacker-specified server w…
- CVE-2018-1000553HIGHCVSS 8.8EG 8.82018-06-26
Trovebox version <= 4.0.0-rc6 contains a Server-Side request forgery vulnerability in webhook component that can result in read or update internal resources. This attack appear to be exploitable via HTTP request. This vulnerability appears…
- CVE-2018-1000606MEDIUMCVSS 6.5EG 6.52018-06-26
A server-side request forgery vulnerability exists in Jenkins URLTrigger Plugin 0.41 and earlier in URLTrigger.java that allows attackers with Overall/Read access to cause Jenkins to send a GET request to a specified URL.
- CVE-2018-10174MEDIUMCVSS 6.5EG 6.52018-04-20
Digital Guardian Management Console 7.1.2.0015 has an SSRF issue that allows remote attackers to read arbitrary files via file:// URLs, send TCP traffic to intranet hosts, or obtain an NTLM hash. This can occur even if the logged-in user h…
- CVE-2018-10220HIGHCVSS 8.8EG 8.82018-04-19
Glastopf 3.1.3-dev has SSRF, as demonstrated by the abc.php a parameter. NOTE: the vendor indicates that this is intentional behavior because the product is a web application honeypot, and modules/handlers/emulators/rfi.py supports Remote …
- CVE-2018-1042MEDIUMCVSS 6.5EG 6.52018-01-22
Moodle 3.x has Server Side Request Forgery in the filepicker.
- CVE-2018-10511CRITICALCVSS 10.0EG 10.02018-08-15
A vulnerability in Trend Micro Control Manager (versions 6.0 and 7.0) could allow an attacker to conduct a server-side request forgery (SSRF) attack on vulnerable installations.
- CVE-2018-11031CRITICALCVSS 9.8EG 9.82018-05-14
application/home/controller/debug.php in PHPRAP 1.0.4 through 1.0.8 has SSRF via the /debug URI, as demonstrated by an api[url]=file:////etc/passwd&api[method]=get POST request.
- CVE-2018-11586CRITICALCVSS 9.8EG 9.82018-06-05
XML external entity (XXE) vulnerability in api/rest/status in SearchBlox 8.6.7 allows remote unauthenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request.
- CVE-2018-12571CRITICALCVSS 9.8EG 9.82018-07-05
uniquesig0/InternalSite/InitParams.aspx in Microsoft Forefront Unified Access Gateway 2010 allows remote attackers to trigger outbound DNS queries for arbitrary hosts via a comma-separated list of URLs in the orig_url parameter, possibly c…
- CVE-2018-12609MEDIUMCVSS 6.5EG 6.52019-01-30
OX App Suite 7.8.4 and earlier allows Server-Side Request Forgery.
Map vulnerabilities like CWE-918 to your infrastructure
EchelonGraph correlates every CVE — across CWE-918 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →