CWE-918
MITRE ↗Server-Side Request Forgery (SSRF)
Subscriber Server Side Request Forgery (SSRF) in Kirki <= 6.0.11 versions.
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.
A server-side request forgery (SSRF) vulnerability in Palo Alto Networks PAN-OS software enables an authenticated admini
Server-Side Request Forgery (SSRF) vulnerability in Themeisle Auto Featured Image (Auto Post Thumbnail) auto-post-thumbn
Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.24 and 6.20.1, the Glide image prox
Custom role Server Side Request Forgery (SSRF) in JetBooking <= 4.1.2 versions.
Contributor Server Side Request Forgery (SSRF) in JetEngine <= 3.8.11 versions.
Contributor Server Side Request Forgery (SSRF) in Feedzy <= 5.2.4 versions.
The WP CTA plugin for WordPress is vulnerable to Server-Side Request Forgery via the 'sticky_s_media' parameter in impor
Subscriber Server Side Request Forgery (SSRF) in FluentCRM Pro <= 3.1.12 versions.
The Converter for Media – Optimize images | Convert WebP & AVIF plugin for WordPress is vulnerable to Server-Side Reques
Axios is a promise based HTTP client for the browser and Node.js. Versions prior to 1.15.0 and 0.3.1 are vulnerable to a
Server-Side Request Forgery in the markdown_to_pdf action of Rapid7 InsightConnect Markdown Plugin on Linux in versions
A flaw has been found in go-sonic sonic up to 1.1.4. The affected element is the function FetchTheme of the file service
A security vulnerability has been detected in invoiceninja up to 5.12.38. The affected element is the function copy of t
A weakness has been identified in ZenTao up to 21.7.6-85642. The impacted element is the function fetchHook of the file
A security vulnerability has been detected in ContiNew Admin up to 4.2.0. This issue affects the function URI.create of
A vulnerability was determined in taoofagi easegen-admin up to 8f87936ac774065b92fb20aab55b274a6ea76433. This issue affe
Streamlit is a data oriented application development framework for python. Streamlit Open Source versions prior to 1.54.
A vulnerability was determined in Dataease SQLbot up to 1.6.0. This issue affects the function get_es_data_by_http of th
A weakness has been identified in Casdoor 2.356.0. This vulnerability affects unknown code of the component Webhook URL
A vulnerability was identified in HummerRisk up to 1.5.0. This vulnerability affects the function ServerService.addServe
A vulnerability was identified in pagekit up to 1.0.18. Affected by this issue is some unknown functionality of the file
A security vulnerability has been detected in jishenghua jshERP up to 3.6. This affects the function getUserByWeixinCode
python-utcp is the python implementation of UTCP. Prior to 1.1.3, the utcp-http plugin is vulnerable to a blind Server-S
The MCP Registry provides MCP clients with a list of MCP servers, like an app store for MCP servers. Prior to 1.7.6, the
A vulnerability has been found in YunaiV yudao-cloud 2026.03. This affects the function IotDataSinkHttpConfig of the fil
typescript-utcp is a typescript implementation of UTCP. Prior to 1.1.2, the @utcp/http package is vulnerable to a blind
A security vulnerability has been detected in nextlevelbuilder GoClaw up to 3.11.3. Affected by this issue is the functi
A flaw has been found in jishenghua jshERP up to 3.6. Impacted is the function insertPlatformConfig of the file jshERP-b
A vulnerability was determined in Poesis Rhymix CMS up to 2.1.33. This impacts the function procImporterAdminCheckXmlFil
CAI Content Credentials is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege
Server-Side Request Forgery (SSRF) vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting
Server-Side Request Forgery (SSRF) vulnerability in totalsoft TS Poll poll-wp allows Server Side Request Forgery.This is
The Ona theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.26 via
PlantUML Macro is a macro for rendering UML diagrams from simple textual schemes. Prior to version 2.4.1, the PlantUML M
Administrator Server Side Request Forgery (SSRF) in PopAd <= 1.0.4 versions.
A flaw has been found in foreman when HTTP parameters are modified in http_proxies_controller and http_proxy files. Atta
Author Server Side Request Forgery (SSRF) in Photo Block <= 1.7.1 versions.
Author Server Side Request Forgery (SSRF) in Complianz <= 7.5.0 versions.
The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up
Tiny File Manager through 2.6 contains a server-side request forgery (SSRF) vulnerability in the URL upload feature. Due
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.0 before 18.6.6, 18.7 before 18.7.4, and 1
The Gutenberg Blocks with AI by Kadence WP plugin for WordPress is vulnerable to Server-Side Request Forgery in all vers
Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Version
SPIP before 4.4.9 allows Blind Server-Side Request Forgery (SSRF) via syndicated sites in the private area. When editing
A flaw was found in the FTP GVfs backend. A malicious FTP server can exploit this vulnerability by providing an arbitrar
melange allows users to build apk packages using declarative pipelines. In version 0.40.5 and prior, melange update-cach
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, testwebhooknotifications.
Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to canonicalize IPv4-mapped IPv6 addres
Frequently Asked Questions
What is CWE-918?
CWE-918 (Server-Side Request Forgery (SSRF)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-918?
There are 3,755 CVE records associated with CWE-918 in our database. Of these, 428 are critical severity, 1157 are high severity, and 1478 are medium severity.
How can I protect against CWE-918 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-918 using AI-powered security agents.
Detect CWE-918 Vulnerabilities
CyberStrike's AI agents automatically detect server-side request forgery (ssrf) vulnerabilities across your infrastructure.
Get Started