CWE-918
MITRE ↗Server-Side Request Forgery (SSRF)
9Router is an AI router & token saver. Prior to 0.5.6, the Kiro API-key validation endpoint POST /api/oauth/kiro/api-key
SurrealDB before 3.1.0 contains a capability bypass vulnerability in HTTP redirect handling that allows authenticated us
AVideo versions from commit 0dbadbca through latest master contain a server-side request forgery vulnerability in the en
WACRM is a self-hostable CRM template for WhatsApp. In 0.7.0 and earlier, the automation send_webhook action in src/lib/
Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.3
The ProSolution WP Client WordPress plugin before 2.0.9 does not validate a user-supplied URL, and does not check the ca
Lightdash stores the webhook URL supplied with a scheduled delivery and later posts to it from sendWebhook in packages/b
Contributor Server Side Request Forgery (SSRF) in Shared Files <= 1.7.69 versions.
A server-side request forgery (SSRF) vulnerability was found in galaxy_ng, the Ansible Galaxy server plugin for Pulp. An
wallabag 2 through 2.6.14 allows SSRF because a crafted title or content field is mishandled during PDF export.
A flaw has been found in xiweicheng TMS up to 2.28.0. This affects the function Summary of the file src/main/java/com/lh
A security vulnerability has been detected in MindsDB up to 25.14.1. This vulnerability affects the function clear_filen
A vulnerability was detected in lintsinghua DeepAudit up to 3.0.3. This issue affects some unknown processing of the fil
A security vulnerability has been detected in cskefu up to 8.0.1. This issue affects some unknown processing of the file
A flaw has been found in GeekAI up to 4.2.4. The affected element is the function Download of the file api/handler/net_h
A weakness has been identified in huggingface smolagents 1.24.0. Impacted is the function requests.get/requests.post of
A weakness has been identified in JeecgBoot 3.9.0. Affected by this vulnerability is an unknown functionality of the fil
A security flaw has been discovered in Tiandy Video Surveillance System 视频监控平台 7.17.0. This impacts the function downloa
A vulnerability was found in DataLinkDC dinky up to 1.2.5. The impacted element is the function proxyUba of the file din
A vulnerability has been found in SourceCodester Website Link Extractor 1.0. This vulnerability affects the function fil
A vulnerability has been found in psi-probe PSI Probe up to 5.3.0. This affects the function lookup of the file psi-prob
A vulnerability was identified in itwanger paicoding 1.0.0/1.0.1/1.0.2/1.0.3. The impacted element is the function Save
A weakness has been identified in welovemedia FFmate up to 2.0.15. This affects the function fireWebhook of the file /in
A vulnerability was detected in bufanyun HotGo up to 2.0. This issue affects the function ImageTransferStorage of the fi
A vulnerability was detected in xuxueli xxl-job up to 3.3.2. This impacts an unknown function of the file source-code/sr
A security vulnerability has been detected in Bytedesk up to 1.3.9. This impacts the function getModels of the file sour
A vulnerability was detected in Bytedesk up to 1.3.9. Affected is the function getModels of the file source-code/src/mai
A vulnerability has been found in Woahai321 ListSync up to 0.6.6. This issue affects the function requests.post of the f
A vulnerability was determined in zyddnys manga-image-translator up to beta-0.3. The affected element is the function to
A vulnerability was detected in 648540858 wvp-GB28181-pro up to 2.7.4-20260107. Affected by this vulnerability is the fu
A security flaw has been discovered in FlowCI flow-core-x up to 1.23.01. The impacted element is the function Save of th
A weakness has been identified in frdel/agent0ai agent-zero 0.9.7. This affects the function handle_pdf_document of the
A vulnerability was identified in kalcaddle kodbox 1.64. The affected element is the function PathDriverUrl of the file
A vulnerability was identified in Page-Replica Page Replica up to e4a7f52e75093ee318b4d5a9a9db6751050d2ad0. The impacted
A security vulnerability has been detected in letta-ai letta 0.16.4. This vulnerability affects the function _convert_me
A flaw has been found in SourceCodester RSS Feed Parser 1.0. Affected by this issue is the function file_get_contents. T
A vulnerability was identified in chatwoot up to 4.11.2. Affected by this vulnerability is the function Webhooks::Trigge
A vulnerability was determined in AutohomeCorp frostmourne up to 1.0. The affected element is an unknown function of the
A security vulnerability has been detected in mixelpixx Google-Research-MCP 1e062d7bd887bfe5f6e582b6cc288bb897b35cf2/ca6
A flaw has been found in Ollama up to 0.18.1. This issue affects some unknown processing of the file server/download.go
A vulnerability was detected in QingdaoU OnlineJudge up to 1.6.1. Affected by this issue is the function service_url of
A security vulnerability has been detected in imprvhub mcp-browser-agent up to 0.8.0. This impacts the function CallTool
A vulnerability was identified in hcengineering Huly Platform 0.7.382. This affects an unknown part of the file server/f
Server-Side Request Forgery (CWE-918) in Kibana One Workflow can lead to information disclosure. An authenticated user w
A security flaw has been discovered in bigsk1 openai-realtime-ui up to 188ccde27fdf3d8fab8da81f3893468f53b2797c. The aff
GeoNode versions 4.0 before 4.4.5 and 5.0 before 5.0.2 contain a server-side request forgery vulnerability that allows a
GeoNode versions 4.4.5 and 5.0.2 (and prior within their respective releases) contain a server-side request forgery vuln
A security flaw has been discovered in FoundationAgents MetaGPT up to 0.8.1. This impacts the function decode_image of t
A vulnerability was identified in AstrBotDevs AstrBot up to 4.22.1. The affected element is the function post_data.get o
A weakness has been identified in DbGate up to 7.1.4. The impacted element is the function apiServerUrl1 of the file pac
Frequently Asked Questions
What is CWE-918?
CWE-918 (Server-Side Request Forgery (SSRF)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-918?
There are 3,755 CVE records associated with CWE-918 in our database. Of these, 428 are critical severity, 1157 are high severity, and 1478 are medium severity.
How can I protect against CWE-918 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-918 using AI-powered security agents.
Detect CWE-918 Vulnerabilities
CyberStrike's AI agents automatically detect server-side request forgery (ssrf) vulnerabilities across your infrastructure.
Get Started