Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-918 (服务端请求伪造(SSRF)) — Vulnerability Class 1487

1487 vulnerabilities classified as CWE-918 (服务端请求伪造(SSRF)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2024-33634 WordPress Piotnet Addons For Elementor Pro plugin <= 7.1.17 - Unauthenticated Server Side Request Forgery (SSRF) vulnerability — Piotnet Addons For Elementor Pro 5.4 Medium2024-04-29
CVE-2024-33629 WordPress Auto Featured Image (Auto Post Thumbnail) plugin <= 4.0.0 - Server Side Request Forgery (SSRF) vulnerability — Auto Featured Image (Auto Post Thumbnail) 4.4 Medium2024-04-29
CVE-2024-33627 WordPress AGCA – Custom Dashboard & Login Page plugin <= 7.2.2 - Server Side Request Forgery (SSRF) vulnerability — Absolutely Glamorous Custom Admin 4.4 Medium2024-04-29
CVE-2024-33592 WordPress Radio Player plugin <= 2.0.73 - Server Side Request Forgery (SSRF) vulnerability — Radio Player 5.4 Medium2024-04-25
CVE-2024-32718 WordPress The Pack Elementor addons plugin <= 2.0.8.2 - Server Side Request Forgery (SSRF) vulnerability — The Pack Elementor addons 4.9 Medium2024-04-24
CVE-2024-32775 WordPress Embed Google Photos album plugin <= 2.1.9 - Server Side Request Forgery (SSRF) vulnerability — Embed Google Photos album 4.9 Medium2024-04-24
CVE-2024-32803 WordPress SuperFaktura WooCommerce plugin <= 1.40.3 - Server Side Request Forgery (SSRF) vulnerability — SuperFaktura WooCommerce 6.4 Medium2024-04-24
CVE-2024-32812 WordPress Podlove Podcast Publisher plugin <= 4.0.11 - Server Side Request Forgery (SSRF) vulnerability — Podlove Podcast Publisher 5.4 Medium2024-04-24
CVE-2024-32819 WordPress Culqi plugin <= 3.0.14 - Server Side Request Forgery (SSRF) vulnerability — Culqi 4.9 Medium2024-04-24
CVE-2024-32955 WordPress FV Flowplayer Video Player plugin <= 7.5.43.7212 - Server Side Request Forgery (SSRF) vulnerability — FV Flowplayer Video Player 4.9 Medium2024-04-24
CVE-2024-27347 Apache HugeGraph-Hubble: SSRF in Hubble connection page — Apache HugeGraph-Hubble 9.1 -2024-04-22
CVE-2024-31993 Mealie vulnerable to a GET-based SSRF in recipe image importer (GHSL-2023-227) — mealie 6.2 Medium2024-04-19
CVE-2024-31991 Mealie vulnerable to a GET-based SSRF in recipe importer (GHSL-2023-225) — mealie 4.1 Medium2024-04-19
CVE-2024-29029 memos vulnerable to an SSRF in /o/get/image — memos 6.1 Medium2024-04-19
CVE-2024-29028 memos vulnerable to an SSRF in /o/get/httpmeta — memos 5.8 Medium2024-04-19
CVE-2024-29030 memos vulnerable to an SSRF in /api/resource — memos 5.8 Medium2024-04-19
CVE-2024-2796 SSRF in Akana API Platform — Akana API Platform 9.3 Critical2024-04-18
CVE-2024-29021 SSRF into Sandbox Escape through Unsafe Default Configuration — judge0 9.1 Critical2024-04-18
CVE-2024-31229 WordPress Really Simple SSL plugin <= 7.2.3 - Server Side Request Forgery (SSRF) vulnerability — Really Simple SSL 5.5 Medium2024-04-18
CVE-2024-29035 Umbraco's Blind SSRF Leads to Port Scan by using Webhooks — Umbraco-CMS 4.1 Medium2024-04-17
CVE-2023-6805 RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 4.4.7 - Authenticated(Contributor+) Blind Server-Side Request Forgery (SSRF) — RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator 6.4 Medium2024-04-17
CVE-2024-22329 IBM WebSphere Application Server server-side request forgery — WebSphere Application Server 4.3 Medium2024-04-17
CVE-2024-30256 Open WebUI vulnerable to server-side request forgery in utils.py — open-webui 6.4 Medium2024-04-16
CVE-2024-32430 WordPress ActiveCampaign plugin <= 8.1.14 - Server Side Request Forgery (SSRF) vulnerability — ActiveCampaign 4.4 Medium2024-04-15
CVE-2024-32454 WordPress Wappointment plugin <= 2.6.0 - Server Side Request Forgery (SSRF) vulnerability — Appointment Bookings for Zoom GoogleMeet and more – Wappointment 4.4 Medium2024-04-15
CVE-2024-31461 Plane Server-Side Request Forgery (SSRF) Vulnerability — plane 9.1 Critical2024-04-10
CVE-2024-3448 Improper Access Control Leads to Server-Side Request Forgery in Mautic — Mautic 5.0 Medium2024-04-10
CVE-2023-40148 PingFederate Server Side Request Forgery vulnerability — PingFederate 6.5 Medium2024-04-10
CVE-2024-1812 Everest Forms <= 2.0.7 - Unauthenticated Server-Side Request Forgery via font_url — Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder 7.2 High2024-04-09
CVE-2023-6964 Gutenberg Blocks by Kadence Blocks – Page Builder Features <= 3.1.26 - Authenticated(Contributor+) Server-Side Request Forgery (SSRF) — Kadence Blocks — Page Builder Toolkit for Gutenberg Editor 8.5 High2024-04-09

Vulnerabilities classified as CWE-918 (服务端请求伪造(SSRF)) represent 1487 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.