CWE-918
MITRE ↗Server-Side Request Forgery (SSRF)
Ech0 before 4.7.3 contains a server-side request forgery vulnerability in the fetchPeerConnectInfo function that uses un
Spring Cloud Gateway JsonToGrpcGatewayFilterFactory allows arbitrary Spring Resource locations for defining the proto de
The SmartAIPress WordPress plugin through 1.2.0 does not perform a capability check on one of its AJAX actions and does
Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, a hostn
OpenClaw is a personal AI assistant. Prior to OpenClaw version 2026.2.14, the Gateway tool accepted a tool-supplied `gat
OpenClaw versions prior to 2026.3.2 contain a DNS pinning bypass vulnerability in strict URL fetch paths that allows att
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.
In KubePlus 4.1.4, the mutating webhook and kubeconfiggenerator components have an SSRF vulnerability when processing th
InvoiceShelf is an open-source web & mobile app that helps track expenses, payments and create professional invoices and
InvoiceShelf is an open-source web & mobile app that helps track expenses, payments and create professional invoices and
InvoiceShelf is an open-source web & mobile app that helps track expenses, payments and create professional invoices and
OpenClaw before 2026.3.31 contains a server-side request forgery vulnerability in the marketplace plugin download functi
OpenClaw before 2026.3.31 contains a server-side request forgery vulnerability in the marketplace plugin download functi
OpenClaw before 2026.4.8 contains a server-side request forgery policy bypass vulnerability allowing attackers to trigge
TypeBot is a chatbot builder tool. In versions prior to 3.16.0, SSRF protection for Webhook / HTTP Request blocks valida
Karakeep is a elf-hostable bookmark-everything app. A Server-Side Request Forgery (SSRF) protection bypass vulnerability
In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.4.26
ApostropheCMS is an open-source Node.js content management system. Versions up to and including 4.29.0 contain an authen
SurrealDB before 2.2.2 fails to validate HTTP redirects in http functions, allowing authenticated users to bypass deny-n
A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows user able t
A flaw was found in the koku-metrics-operator for Red Hat OpenShift. The operator's CostManagementMetricsConfig custom r
Gitea prior to 1.27.0 contains a server-side request forgery vulnerability that allows authenticated attackers to bypass
Prowler is a cloud security platform. Prior to 5.33.1, an authenticated user with Lighthouse provider configuration acce
Budibase Server before 3.41.3 contains a server-side request forgery vulnerability in the datasource verify endpoint tha
Mastodon is a free, open-source social network server based on ActivityPub. By nature, Mastodon performs a lot of outbou
The Librarian contains an internal port scanning vulnerability, facilitated by the `web_fetch` tool, which can be used w
WeasyPrint helps web developers to create PDF documents. Prior to version 68.0, a server-side request forgery (SSRF) pro
A Local File Inclusion (LFI) and a Server-Side Request Forgery (SSRF) vulnerability was found in the InsertFromHtmlStrin
FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Versions 1.5.10.1754 and below conta
OpenClaw is a personal AI assistant. Prior to version 2026.2.14, OpenClaw's SSRF protection could be bypassed using full
esm.sh is a no-build content delivery network (CDN) for web development. In version 136, esm.sh is vulnerable to a full-
esm.sh is a no-build content delivery network (CDN) for web development. Versions up to and including 137 have an SSRF v
TerriaJS-Server is a NodeJS Express server for TerriaJS, a library for building web-based geospatial data explorers. A v
An XML External Entity (XXE) vulnerability allows malicious user to perform Server-Side Request Forgery (SSRF) via craft
An Arbitrary File Read vulnerability exists in the ImageTextPromptValue class in Exploding Gradients RAGAS v0.2.3 to v0.
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, the url parameter can be
PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. Prior to version 0.7.7,
A server-side request forgery (SSRF) vulnerability in IKEA Dirigera v2.866.4 allows an attacker to exfiltrate private ke
Server-side request forgery (ssrf) in Azure IoT Explorer allows an unauthorized attacker to perform spoofing over a netw
Server-Side Request Forgery (SSRF) vulnerability in pdfmake versions 0.3.0-beta.2 through 0.3.5 allows a remote attacker
An issue pertaining to CWE-918: Server-Side Request Forgery was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4. This
Backstage is an open framework for building developer portals. Prior to 0.27.1, a Server-Side Request Forgery (SSRF) vul
The backend database management connection test feature in wgcloud v3.6.3 has a server-side request forgery (SSRF) vulne
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions prior
SQLBot is an intelligent data query system based on a large language model and RAG. Versions prior to 1.7.0 contain a Se
Saloon is a PHP library that gives users tools to build API integrations and SDKs. Prior to version 4.0.0, when building
Server-Side Request Forgery (SSRF) vulnerability exists in the AnnounContent of the /admin/read.php in OTCMS V7.66 and b
A Server-Side Request Forgery (SSRF) vulnerability exists in parisneo/lollms versions prior to 2.2.0, specifically in th
Gotenberg is an API for converting document formats. Prior to version 8.29.0, the fix introduced for CVE-2024-21527 can
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, on Windows the
Frequently Asked Questions
What is CWE-918?
CWE-918 (Server-Side Request Forgery (SSRF)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-918?
There are 3,755 CVE records associated with CWE-918 in our database. Of these, 428 are critical severity, 1157 are high severity, and 1478 are medium severity.
How can I protect against CWE-918 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-918 using AI-powered security agents.
Detect CWE-918 Vulnerabilities
CyberStrike's AI agents automatically detect server-side request forgery (ssrf) vulnerabilities across your infrastructure.
Get Started