Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-918

MITRE ↗

Server-Side Request Forgery (SSRF)

428
CRITICAL
1,157
HIGH
1,478
MEDIUM
113
LOW
3,326 CVEs · Page 29/67
CVE-2026-62668

Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.6,

CVE-2026-54494

Koel is a free, open-source music streaming solution. Prior to 9.7.1, App\Helpers\Network::isPublicHost() uses filter_va

CVE-2026-77069

n8n before 1.123.69, 2.33.4, and 2.34.1 contains an SSRF protection bypass in the OAuth2 credential authorization-code-t

CVE-2026-77085

n8n before 2.34.1 and 2.33.x before 2.33.4 contains an SSRF protection bypass in the SearXNG Agent tool. The tool sent r

CVE-2026-64968

ATutor is vulnerable to Server-Side request forgery in import functionalities. An authenticated administrator can make t

CVE-2026-54508

TREK is a collaborative travel planner. Prior to 3.1.0, TREK validates only the initial URL before native redirect follo

CVE-2026-77646

A Server-Side Request Forgery (SSRF) vulnerability has been reported in PTC Windchill PDMLink and PTC FlexPLM. The vulne

CVE-2026-50288

SpecifyJS is a declarative TypeScript user interface framework. Prior to version 0.2.136, when `new URL()` throws a pars

CVE-2026-47735

Arc is an open, SQL-native time-series database for telemetry. Prior to version 26.06.1, Arc's user-SQL validator (`inte

CVE-2026-78385

RansomLook contains insufficient resource validation in the analysis PDF generation functionality. Analysis documents ar

CVE-2026-52776

Compliance-trestle (Trestle) is a tooling platform for managing compliance as code. In versions before 3.12.4 and versio

CVE-2026-55758

CC: Tweaked is a mod for Minecraft which adds programmable computers, turtles, and more to the game. Prior to 1.120.0, t

CVE-2026-78495

A server-side request forgery (SSRF) vulnerability WatchGuard Dimension Remote Backup Connection Test configuration allo

CVE-2026-78498

A server-side request forgery (SSRF) vulnerability WatchGuard Dimension Email Server Test configuration allows an authen

CVE-2026-78499

A server-side request forgery (SSRF) vulnerability WatchGuard Dimension FTP Server Test configuration allows an authenti

CVE-2026-78500

A blind server-side request forgery (SSRF) vulnerability WatchGuard Dimension Database Server Test configuration allows

CVE-2026-55245

Bifrost is an enterprise AI gateway for routing requests to model providers. Prior to 1.5.17, the isPublicIP function in

10.0
CVE-2025-2828

A Server-Side Request Forgery (SSRF) vulnerability exists in the RequestsToolkit component of the langchain-community pa

10.0
CVE-2025-54122

Manager-io/Manager is accounting software. A critical unauthenticated full read Server-Side Request Forgery (SSRF) vulne

10.0
CVE-2025-53767

Azure OpenAI Elevation of Privilege Vulnerability

10.0
CVE-2025-59503

Server-side request forgery (ssrf) in Azure Compute Gallery allows an unauthorized attacker to elevate privileges over a

10.0
CVE-2025-64180

Manager-io/Manager is accounting software. In Manager Desktop and Server versions 25.11.1.3085 and below, a critical vul

9.9
CVE-2025-29972

Server-side request forgery (ssrf) in Azure Storage Resource Provider allows an authorized attacker to perform spoofing

9.9
CVE-2025-30220

GeoServer is an open source server that allows users to share and edit geospatial data. GeoTools Schema class use of Ecl

9.9
CVE-2025-54381

BentoML is a Python library for building online serving systems optimized for AI apps and model inference. In versions 1

9.9
CVE-2025-64663

Custom Question Answering Elevation of Privilege Vulnerability

9.8
CVE-2025-22952

elestio memos v0.23.0 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of user-supplie

9.8
CVE-2025-27651

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.862 Application 20.0.2014 allows Server-Side Req

9.8
CVE-2025-27652

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.862 Application 20.0.2014 allows Server-Side Req

9.8
CVE-2025-27655

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.862 Application 20.0.2014 allows Server-Side Req

9.8
CVE-2024-12450

In infiniflow/ragflow versions 0.12.0, the `web_crawl` function in `document_app.py` contains multiple vulnerabilities.

9.8
CVE-2024-48590

Inflectra SpiraTeam 7.2.00 is vulnerable to Server-Side Request Forgery (SSRF) via the NewsReaderService. This allows an

9.8
CVE-2025-37090

A server-side request forgery vulnerability exists in HPE StoreOnce Software.

9.8
CVE-2025-45872

zrlog v3.1.5 was discovered to contain a Server-Side Request Forgery (SSRF) via the downloadUrl parameter.

9.8
CVE-2024-9408

In Eclipse GlassFish since version 6.2.5 it is possible to perform a Server Side Request Forgery attack in specific endp

9.8
CVE-2025-58045

Dataease is an open source data analytics and visualization platform. In Dataease versions up to 2.10.12, the patch intr

9.8
CVE-2025-64163

DataEase is an open source data visualization analysis tool. In versions 2.10.14 and below, the vendor added a blacklist

9.8
CVE-2025-66405

Portkey.ai Gateway is a blazing fast AI Gateway with integrated guardrails. Prior to 1.14.0, the gateway determined the

9.8
CVE-2023-53899

PodcastGenerator 3.2.9 contains a blind server-side request forgery vulnerability that allows attackers to inject XML in

9.6
CVE-2025-60279

A server-side request forgery (SSRF) vulnerability in Illia Cloud illia-Builder before v4.8.5 allows authenticated users

9.6
CVE-2025-64709

Typebot is an open-source chatbot builder. In versions prior to 3.13.1, a Server-Side Request Forgery (SSRF) vulnerabili

9.3
CVE-2024-9309

A Server-Side Request Forgery (SSRF) vulnerability exists in the POST /worker_generate_stream API endpoint of the Contro

9.3
CVE-2024-34711

GeoServer is an open source server that allows users to share and edit geospatial data. An improper URI validation vulne

9.3
CVE-2025-67494

ZITADEL is an open-source identity infrastructure tool. Versions 4.7.0 and below are vulnerable to an unauthenticated, f

9.1
CVE-2024-54819

I, Librarian before and including 5.11.1 is vulnerable to Server-Side Request Forgery (SSRF) due to improper input valid

9.1
CVE-2024-45479

SSRF vulnerability in Edit Service Page of Apache Ranger UI in Apache Ranger Version 2.4.0. Users are recommended to upg

9.1
CVE-2025-25785

JizhiCMS v2.5.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the component \c\PluginsController.ph

9.1
CVE-2025-28089

maccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) via the Scheduled Task function.

9.1
CVE-2025-28090

maccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) in the Collection Custom Interface feature.

9.1
CVE-2025-28091

maccms10 v2025.1000.4047 has a Server-Side Request Forgery (SSRF) vulnerability via Add Article.

Frequently Asked Questions

What is CWE-918?

CWE-918 (Server-Side Request Forgery (SSRF)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-918?

There are 3,755 CVE records associated with CWE-918 in our database. Of these, 428 are critical severity, 1157 are high severity, and 1478 are medium severity.

How can I protect against CWE-918 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-918 using AI-powered security agents.

Detect CWE-918 Vulnerabilities

CyberStrike's AI agents automatically detect server-side request forgery (ssrf) vulnerabilities across your infrastructure.

Get Started