CWE-918
MITRE ↗Server-Side Request Forgery (SSRF)
Xibo is an open source digital signage platform with a web content management system and Windows display player software
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, a Ser
TypeBot is a chatbot builder tool. Versions 3.15.2 and prior contain an SSRF via Open Redirect Bypass as the HTTP Reques
Budibase is an open-source low-code platform. Prior to 3.35.10, the Plugin URL upload endpoint (POST /api/plugin) valida
Budibase is an open-source low-code platform. Prior to 3.34.8, the processUrlFile function in packages/server/src/automa
Budibase is an open-source low-code platform. Prior to 3.38.1, the REST datasource integration (packages/server/src/inte
Budibase is an open-source low-code platform. Prior to 3.39.0, the OAuth2 token fetch function in packages/server/src/sd
Server-Side Request Forgery (CWE-918) in Kibana allows authenticated users with connector management privileges to bypas
A flaw was found in the OpenShift Router. A user with EndpointSlice write access can exploit this vulnerability by creat
MoviePilot v2 contains a server-side request forgery vulnerability in the image proxy endpoint that allows authenticated
FastGPT is an AI Agent building platform. Prior to 4.15.0-beta1, a Server-Side Request Forgery (SSRF) vulnerability allo
Garlic-Hub manages digital signage network — devices, content, and playlists — from a single self-hosted interface. Prio
OpenClaw before 2026.5.18 contains a server-side request forgery vulnerability in browser control that allows authentica
Koel is a free, open-source music streaming solution. Prior to version 9.3.5, Koel validates the podcast feed URL via th
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.4.0 to be
Sync-in Server is a secure, open-source platform for file storage, sharing, collaboration, and syncing. Prior to version
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, the t
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, the S
LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, LibreChat allows users t
A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) to es
LobeChat before 2.2.10-canary.18 contains a server-side request forgery vulnerability that allows authenticated attacker
FastGPT is a knowledge-based AI application platform. Prior to 4.15.0-beta4, the HTTP-tool OpenAPI schema importer valid
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 before 0.10.0, _sanitiz
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 0.12.0
ColdFusion is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature byp
Simple Machines Forum 2.1 prior to commit 4bf35cf and 3.0 prior to commit b4d23df contains a server-side request forgery
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 12.0.0, the SSRF protection on
Penpot is an open-source design tool for design and code collaboration. Prior to 2.15.0, Penpot's remote image import pa
OpenClaw versions before 2026.6.6 contain a network policy bypass vulnerability in the sandbox exec-server that allows l
OpenClaw 2026.4.14 before 2026.5.26 contain a server-side request forgery vulnerability in browser snapshot routes that
IBM Langflow OSS 1.0.0 through 1.10.0 Langflow 1.9.0 could allow server-side request forgery (SSRF) due to insecure defa
LimeSurvey through 6.17.10 and 7.0.4 contains a server-side request forgery vulnerability in the REST API survey templat
HyperDX before 2.31.0 contains a server-side request forgery vulnerability that allows authenticated team members to dir
Huginn through 2022.08.18 contains a server-side request forgery vulnerability in the fetch_url method of ScenarioImport
9Router before 0.4.72 contains a server-side request forgery (SSRF) vulnerability in the /v1/web/fetch endpoint. The end
PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 t
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, with WEB_
Flowise through 3.1.4 contains a server-side request forgery vulnerability in the SSRF guard implemented in httpSecurity
A server-side request forgery (SSRF) vulnerability in automatisch through commit 41f3c56 allows a low-privileged authent
A server-side request forgery (SSRF) vulnerability in gabehf/Koito through v0.3.2 allows an authenticated user to make t
Two SSRF findings in Gitea 1.26.2
Flyto2 Core before 2.28.0 contains a server-side request forgery guard bypass vulnerability that allows attackers to rea
A server-side request forgery (SSRF) vulnerability was found in AWX's webhook status callback mechanism. When processing
Lemur manages TLS certificate creation. Prior to 1.9.3, _validate_acme_url enforced ACME_DIRECTORY_HOST_ALLOWLIST when a
ArcadeDB before 26.8.1 contains a server-side request forgery vulnerability in the OpenCypher LOAD CSV implementation th
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2
Koel is a free, open-source music streaming solution. Prior to 9.7.0, the Subsonic-compatible createInternetRadioStation
Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an authorized attacker to disclose information o
TensorZero is an open-source LLMOps platform that unifies an LLM gateway, observability, evaluation, optimization, and e
A server-side request forgery (SSRF) vulnerability was found in multiple AWX notification backends. The webhook, Matterm
Frequently Asked Questions
What is CWE-918?
CWE-918 (Server-Side Request Forgery (SSRF)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-918?
There are 3,755 CVE records associated with CWE-918 in our database. Of these, 428 are critical severity, 1157 are high severity, and 1478 are medium severity.
How can I protect against CWE-918 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-918 using AI-powered security agents.
Detect CWE-918 Vulnerabilities
CyberStrike's AI agents automatically detect server-side request forgery (ssrf) vulnerabilities across your infrastructure.
Get Started