CWE-918— Server-Side Request Forgery (SSRF)
2,379 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-918page 9 of 48
- CVE-2021-24150HIGHCVSS 7.5EG 7.52021-04-05
The LikeBtn WordPress Like Button Rating ♥ LikeBtn WordPress plugin before 2.6.32 was vulnerable to Unauthenticated Full-Read Server-Side Request Forgery (SSRF).
- CVE-2021-24371LOWCVSS 2.7EG 2.72021-08-02
The Import feature of the RSVPMaker WordPress plugin before 8.7.3 (/wp-admin/tools.php?page=rsvpmaker_export_screen) takes an URL input and calls curl on it, without first validating it to ensure it's a remote one. As a result, a high priv…
- CVE-2021-24472CRITICALCVSS 9.8EG 9.82021-08-02
The OnAir2 WordPress theme before 3.9.9.2 and QT KenthaRadio WordPress plugin before 2.0.2 have exposed proxy functionality to unauthenticated users, sending requests to this proxy functionality will have the web server fetch and display t…
- CVE-2021-25236MEDIUMCVSS 5.3EG 5.32021-02-04
A server-side request forgery (SSRF) information disclosure vulnerability in Trend Micro OfficeScan XG SP1 and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to locate online agents via a specific sweep.
- CVE-2021-25241MEDIUMCVSS 5.3EG 5.32021-02-04
A server-side request forgery (SSRF) information disclosure vulnerability in Trend Micro Apex One and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to locate online agents via a sweep.
- CVE-2021-25640MEDIUMCVSS 6.1EG 6.12021-06-01
In Apache Dubbo prior to 2.6.9 and 2.7.9, the usage of parseURL method will lead to the bypass of white host check which can cause open redirect or SSRF vulnerability.
- CVE-2021-25939LOWCVSS 2.7EG 2.72022-02-09
In ArangoDB, versions v3.7.0 through v3.9.0-alpha.1 have a feature which allows downloading a Foxx service from a publicly available URL. This feature does not enforce proper filtering of requests performed internally, which can be abused …
- CVE-2021-25972MEDIUMCVSS 4.9EG 4.92021-10-20
In Camaleon CMS, versions 2.1.2.0 to 2.6.0, are vulnerable to Server-Side Request Forgery (SSRF) in the media upload feature, which allows admin users to fetch media files from external URLs but fails to validate URLs referencing to localh…
- CVE-2021-26072MEDIUMCVSS 4.3EG 4.32021-04-01
The WidgetConnector plugin in Confluence Server and Confluence Data Center before version 5.8.6 allowed remote attackers to manipulate the content of internal network resources via a blind Server-Side Request Forgery (SSRF) vulnerability.
- CVE-2021-26474HIGHCVSS 8.6EG 8.82021-06-08
Various Vembu products allow an attacker to execute a (non-blind) http-only Cross Site Request Forgery (Other products or versions of products in this family may be affected too.)
- CVE-2021-26699MEDIUMCVSS 5.4EG 5.42021-07-22
OX App Suite before 7.10.3-rev4 and 7.10.4 before 7.10.4-rev4 allows SSRF via a shared SVG document that is mishandled by the imageconverter component when the .png extension is used.
- CVE-2021-26715CRITICALCVSS 9.1EG 9.12021-03-25
The OpenID Connect server implementation for MITREid Connect through 1.3.3 contains a Server Side Request Forgery (SSRF) vulnerability. The vulnerability arises due to unsafe usage of the logo_uri parameter in the Dynamic Client Registrati…
- CVE-2021-26855CRITICALCVSS 9.1EG 9.8⚠ KEV2021-03-03
Microsoft Exchange Server Remote Code Execution Vulnerability
- CVE-2021-27103CRITICALCVSS 9.8EG 9.8⚠ KEV2021-02-16
Accellion FTA 9_12_411 and earlier is affected by SSRF via a crafted POST request to wmProgressstat.html. The fixed version is FTA_9_12_416 and later.
- CVE-2021-27214MEDIUMCVSS 6.1EG 6.12021-02-19
A Server-side request forgery (SSRF) vulnerability in the ProductConfig servlet in Zoho ManageEngine ADSelfService Plus through 6013 allows a remote unauthenticated attacker to perform blind HTTP requests or perform a Cross-site scripting …
- CVE-2021-27312CRITICALCVSS 9.4EG 9.02024-04-03
Server Side Request Forgery (SSRF) vulnerability in Gleez Cms 1.2.0, allows remote attackers to execute arbitrary code and obtain sensitive information via modules/gleez/classes/request.php.
- CVE-2021-27329CRITICALCVSS 10.0EG 10.02021-02-18
Friendica 2021.01 allows SSRF via parse_url?binurl= for DNS lookups or HTTP requests to arbitrary domain names.
- CVE-2021-27561CRITICALCVSS 9.8EG 9.8⚠ KEV2021-10-15
Yealink Device Management (DM) 3.6.0.20 allows command injection as root via the /sm/api/v1/firewall/zone/services URI, without authentication.
- CVE-2021-27670CRITICALCVSS 9.8EG 9.82021-02-25
Appspace 6.2.4 allows SSRF via the api/v1/core/proxy/jsonprequest url parameter.
- CVE-2021-27693CRITICALCVSS 9.8EG 9.82022-09-02
Server-side Request Forgery (SSRF) vulnerability in PublicCMS before 4.0.202011.b via /publiccms/admin/ueditor when the action is catchimage.
- CVE-2021-27738HIGHCVSS 7.5EG 7.52022-01-06
All request mappings in `StreamingCoordinatorController.java` handling `/kylin/api/streaming_coordinator/*` REST API endpoints did not include any security checks, which allowed an unauthenticated user to issue arbitrary requests, such as …
- CVE-2021-27905CRITICALCVSS 9.8EG 9.82021-04-13
The ReplicationHandler (normally registered at "/replication" under a Solr core) in Apache Solr has a "masterUrl" (also "leaderUrl" alias) parameter that is used to designate another ReplicationHandler on another Solr core to replicate ind…
- CVE-2021-28060MEDIUMCVSS 5.3EG 5.32021-04-14
A Server-Side Request Forgery (SSRF) vulnerability in Group Office 6.4.196 allows a remote attacker to forge GET requests to arbitrary URLs via the url parameter to group/api/upload.php.
- CVE-2021-28627MEDIUMCVSS 5.4EG 8.82021-08-24
Adobe Experience Manager Cloud Service offering, as well as versions 6.5.8.0 (and below) is affected by a Server-side Request Forgery. An authenticated attacker could leverage this vulnerability to contact systems blocked by the dispatcher…
- CVE-2021-28910HIGHCVSS 7.5EG 7.52021-09-09
BAB TECHNOLOGIE GmbH eibPort V3 prior version 3.9.1 contains basic SSRF vulnerability. It allow unauthenticated attackers to request to any internal and external server.
- CVE-2021-28941MEDIUMCVSS 5.3EG 5.32021-04-02
Because of no validation on a curl command in MagpieRSS 0.72 in the /extlib/Snoopy.class.inc file, when you send a request to the /scripts/magpie_debug.php or /scripts/magpie_simple.php page, it's possible to request any internal page if y…
- CVE-2021-29102CRITICALCVSS 9.1EG 9.12021-07-11
A Server-Side Request Forgery (SSRF) vulnerability in ArcGIS Server Manager version 10.8.1 and below may allow a remote, unauthenticated attacker to forge GET requests to arbitrary URLs from the system, potentially leading to network enume…
- CVE-2021-29145CRITICALCVSS 9.8EG 9.82021-04-29
A remote server side request forgery (SSRF) remote code execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s) prior to 6.9.5, 6.8.9, 6.7.14-HF1. Aruba has released patches for Aruba ClearPass Policy Manager th…
- CVE-2021-29357HIGHCVSS 8.6EG 8.62021-04-12
The ECT Provider component in OutSystems Platform Server 10 before 10.0.1104.0 and 11 before 11.9.0 (and LifeTime management console before 11.7.0) allows SSRF for arbitrary outbound HTTP requests.
- CVE-2021-29431HIGHCVSS 7.7EG 7.72021-04-15
Sydent is a reference Matrix identity server. Sydent can be induced to send HTTP GET requests to internal systems, due to lack of parameter validation or IP address blacklisting. It is not possible to exfiltrate data or control request hea…
- CVE-2021-29475CRITICALCVSS 10.0EG 10.02021-04-26
HedgeDoc (formerly known as CodiMD) is an open-source collaborative markdown editor. An attacker is able to receive arbitrary files from the file system when exporting a note to PDF. Since the code injection has to take place as note conte…
- CVE-2021-29490MEDIUMCVSS 5.8EG 9.02021-05-06
Jellyfin is a free software media system that provides media from a dedicated server to end-user devices via multiple apps. Verions prior to 10.7.3 vulnerable to unauthenticated Server-Side Request Forgery (SSRF) attacks via the imageUrl p…
- CVE-2021-29738MEDIUMCVSS 5.4EG 5.42021-11-02
IBM InfoSphere Data Flow Designer (IBM InfoSphere Information Server 11.7 ) is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to…
- CVE-2021-29749MEDIUMCVSS 5.4EG 5.42021-07-15
IBM Secure External Authentication Server 6.0.2 and IBM Secure Proxy 6.0.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to …
- CVE-2021-29844HIGHCVSS 8.8EG 8.82021-10-27
IBM Jazz Team Server products is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other att…
- CVE-2021-29863MEDIUMCVSS 4.3EG 4.32021-12-01
IBM QRadar SIEM 7.3 and 7.4 is vulnerable to server side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attac…
- CVE-2021-30108CRITICALCVSS 9.1EG 9.12021-05-24
Feehi CMS 2.1.1 is affected by a Server-side request forgery (SSRF) vulnerability. When the user modifies the HTTP Referer header to any url, the server can make a request to it.
- CVE-2021-31216HIGHCVSS 8.1EG 8.12021-07-19
Siren Investigate before 11.1.1 contains a server side request forgery (SSRF) defect in the built-in image proxy route (which is enabled by default). An attacker with access to the Investigate installation can specify an arbitrary URL in t…
- CVE-2021-31531CRITICALCVSS 9.8EG 9.82021-06-29
Zoho ManageEngine ServiceDesk Plus MSP before 10521 is vulnerable to Server-Side Request Forgery (SSRF).
- CVE-2021-31779MEDIUMCVSS 6.4EG 6.42021-04-28
The yoast_seo (aka Yoast SEO) extension before 7.2.1 for TYPO3 allows SSRF via a backend user account.
- CVE-2021-31828HIGHCVSS 7.1EG 7.12021-05-06
An SSRF issue in Open Distro for Elasticsearch (ODFE) before 1.13.1.0 allows an existing privileged user to enumerate listening services or interact with configured resources via HTTP requests exceeding the Alerting plugin's intended scope.
- CVE-2021-31910HIGHCVSS 7.5EG 7.52021-05-11
In JetBrains TeamCity before 2020.2.3, information disclosure via SSRF was possible.
- CVE-2021-31950HIGHCVSS 7.6EG 7.62021-06-08
Microsoft SharePoint Server Spoofing Vulnerability
- CVE-2021-3204MEDIUMCVSS 6.5EG 6.52021-02-19
SSRF in the document conversion component of Webware Webdesktop 5.1.15 allows an attacker to read all files from the server.
- CVE-2021-32603HIGHCVSS 8.8EG 8.82021-08-05
A server-side request forgery (SSRF) (CWE-918) vulnerability in FortiManager and FortiAnalyser GUI 7.0.0, 6.4.5 and below, 6.2.7 and below, 6.0.11 and below, 5.6.11 and below may allow a remote and authenticated attacker to access unauthor…
- CVE-2021-32639HIGHCVSS 7.2EG 7.22021-07-02
Emissary is a P2P-based, data-driven workflow engine. Emissary version 6.4.0 is vulnerable to Server-Side Request Forgery (SSRF). In particular, the `RegisterPeerAction` endpoint and the `AddChildDirectoryAction` endpoint are vulnerable to…
- CVE-2021-32663HIGHCVSS 8.7EG 8.72021-10-19
iTop is an open source web based IT Service Management tool. In affected versions an attacker can call the system setup without authentication. Given specific parameters this can lead to SSRF. This issue has been resolved in versions 2.6.5…
- CVE-2021-32682CRITICALCVSS 9.8EG 9.82021-06-14
elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Several vulnerabilities affect elFinder 2.1.58. These vulnerabilities can allow an attacker to execute arbitrary code and commands on the server hostin…
- CVE-2021-32698MEDIUMCVSS 6.8EG 6.82021-06-21
eLabFTW is an open source electronic lab notebook for research labs. This vulnerability allows an attacker to make GET requests on behalf of the server. It is "blind" because the attacker cannot see the result of the request. Issue has bee…
- CVE-2021-33181MEDIUMCVSS 6.6EG 6.62021-06-01
Server-Side Request Forgery (SSRF) vulnerability in webapi component in Synology Video Station before 2.4.10-1632 allows remote authenticated users to send arbitrary request to intranet resources via unspecified vectors.
Map vulnerabilities like CWE-918 to your infrastructure
EchelonGraph correlates every CVE — across CWE-918 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →