CWE-918
MITRE ↗Server-Side Request Forgery (SSRF)
Server-Side Request Forgery (SSRF) vulnerability in Softaculous Team SpeedyCache – Cache, Optimization, Performance.This
Server-Side Request Forgery (SSRF) vulnerability in Leevio Happy Addons for Elementor.This issue affects Happy Addons fo
BigBlueButton is an open source virtual classroom designed to help teachers teach and learners learn. In affected versio
PostHog provides open-source product analytics, session recording, feature flagging and A/B testing that you can self-ho
WireMock is a tool for mocking HTTP services. WireMock can be configured to only permit proxying (and therefore recordin
A vulnerability in Cisco TelePresence CE and RoomOS Software could allow an authenticated, local attacker to bypass acce
Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache XML Graphics Batik.This issue affe
Server-Side Request Forgery (SSRF) vulnerability in WPGraphQL.This issue affects WPGraphQL: from n/a through 1.14.5.
Server-Side Request Forgery (SSRF) vulnerability in Poll Maker Team Poll Maker – Best WordPress Poll Plugin.This issue a
Server-Side Request Forgery (SSRF) vulnerability in Dimitar Ivanov HTTP Headers.This issue affects HTTP Headers: from n/
A blind SSRF vulnerability was identified in all versions of GitLab EE prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6 p
Server-side request forgery in the CVAT software maintained by Intel(R) before version 2.0.1 may allow an authenticated
OX App Suite before 7.10.6-rev30 allows SSRF because changing a POP3 account disregards the deny-list.
OX App Suite before 7.10.6-rev30 allows SSRF because e-mail account discovery disregards the deny-list and thus can be a
An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x befor
A server-side request forgery (SSRF) vulnerability [CWE-918] in FortiManager and FortiAnalyzer GUI 7.2.0 through 7.2.1,
External service lookups for a number of protocols were vulnerable to a time-of-check/time-of-use (TOCTOU) weakness, inv
Improper REST API permission in Apache Superset up to and including 2.1.0 allows for an authenticated Gamma users to tes
A Server-Side Request Forgery issue in the OpenID Connect Issuer in LemonLDAP::NG before 2.17.1 allows authenticated rem
Nextcloud mail is an email app for the Nextcloud home server platform. In affected versions a missing check of origin, t
A server-side request forgery (SSRF) vulnerability has been reported to affect several QNAP operating system versions. I
Server-Side Request Forgery (SSRF) in GitHub repository salesagility/suitecrm prior to 7.14.2, 8.4.2, 7.12.14.
A server-side request forgery vulnerability in ESM prior to version 11.6.8 allows a low privileged authenticated user t
Symbolicator is a symbolication service for native stacktraces and minidumps with symbol server support. An attacker cou
Symbolicator is a service used in Sentry. Starting in Symbolicator version 0.3.3 and prior to version 21.12.1, an attack
Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.7.0, Audiobookshelf is vulnerable to unauthenti
Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.7.0, Audiobookshelf is vulnerable to unauthenti
In JetBrains Hub before 2023.1.15725 SSRF protection in Auth Module integration was missing
Discourse-jira is a Discourse plugin allows Jira projects, issue types, fields and field options will be synced automati
Server-Side Request Forgery (SSRF) vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n
Server-Side Request Forgery (SSRF) vulnerability in StylemixThemes Motors – Car Dealer, Classifieds & Listing.This issue
Artifact Hub is a web-based application that enables finding, installing, and publishing packages and configurations for
google-translate-api-browser is an npm package which interfaces with the google translate web api. A Server-Side Request
A blind SSRF in GitLab CE/EE affecting all from 11.3 prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6 prior to 15.6.1 all
GLPI is a free asset and IT management software package. Starting in version 0.84 and prior to versions 9.5.13 and 10.0.
Nextcloud Mail is a mail app in Nextcloud. A blind SSRF attack allowed to send GET requests to services running in the s
A vulnerability has been found in Dahua Smart Parking Management up to 20230528 and classified as problematic. This vuln
Synapse is a Matrix protocol homeserver written in Python with the Twisted framework. A discovered oEmbed or image URL c
Mattermost fails to properly restrict requests to localhost/intranet during the interactive dialog, which could allow an
Nextcloud Mail is the mail app for Nextcloud, a self-hosted productivity platform. Starting in version 1.13.0 and prior
Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version
In case Cacheservice was configured to use a sproxyd object-storage backend, it would follow HTTP redirects issued by th
Server-Side Request Forgery (SSRF) in GitHub repository bookstackapp/bookstack prior to v23.08.
Engelsystem is a shift planning system for chaos events. A Blind SSRF in the "Import schedule" functionality makes it po
This vulnerability could allow an attacker to force the server to create and execute a web request granting access to ba
Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.17.
Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.18.
uppy is vulnerable to Server-Side Request Forgery (SSRF)
Server-Side Request Forgery (SSRF) in Pypi calibreweb prior to 0.6.16.
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below use user-controlled input to craft a URL, resulting in a Server
Frequently Asked Questions
What is CWE-918?
CWE-918 (Server-Side Request Forgery (SSRF)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-918?
There are 3,755 CVE records associated with CWE-918 in our database. Of these, 428 are critical severity, 1157 are high severity, and 1478 are medium severity.
How can I protect against CWE-918 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-918 using AI-powered security agents.
Detect CWE-918 Vulnerabilities
CyberStrike's AI agents automatically detect server-side request forgery (ssrf) vulnerabilities across your infrastructure.
Get Started