Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-918 (服务端请求伪造(SSRF)) — Vulnerability Class 1496

1496 vulnerabilities classified as CWE-918 (服务端请求伪造(SSRF)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-8084 AI Engine <= 3.1.8 - Authenticated (Editor+) Server-Side Request Forgery — AI Engine – The Chatbot, AI Framework & MCP for WordPress 6.8 Medium2025-11-18
CVE-2025-11427 WP Migrate Lite <= 2.7.6 - Unauthenticated Blind Server-Side Request Forgery — WP Migrate Lite – Migration Made Easy 5.8 Medium2025-11-18
CVE-2025-12962 Local Syndication <= 1.5a - Authenticated (Contributor+) Server-Side Request Forgery via Shortcode — Local Syndication 6.4 Medium2025-11-18
CVE-2025-13174 rachelos WeRSS we-mp-rss Webhook mps.py do_job server-side request forgery — WeRSS we-mp-rss 6.3 Medium2025-11-14
CVE-2025-64752 grist-core has path to server-side requests via websocket — grist-core 6.8 Medium2025-11-13
CVE-2025-64709 Typebot May Expose AWS EKS Credentials via Server Side Request Forgery in Webhook Block — typebot.io 9.6 Critical2025-11-13
CVE-2025-64525 Astro: URL manipulation via unsanitized headers leads to path-based middleware protections bypass, potential SSRF/cache-poisoning, CVE-2025-61925 bypass — astro 6.5 Medium2025-11-13
CVE-2025-64511 MaxKB has SSRF in sandbox — MaxKB 7.4 High2025-11-13
CVE-2025-59088 Python-kdcproxy: unauthenticated ssrf via realm‑controlled dns srv — kdcproxy 8.6 High2025-11-12
CVE-2025-64522 Soft Serve is vulnerable to SSRF through its Webhooks — soft-serve 9.1 Critical2025-11-10
CVE-2025-64430 Parse Server Vulnerable to Server-Side Request Forgery (SSRF) in File Upload via URI Format — parse-server 7.5 High2025-11-07
CVE-2025-64178 Jellysweep uses uncontrolled data in image cache API endpoint — jellysweep 6.5 -2025-11-06
CVE-2025-64327 ThinkDashboard: Blind Server-Side Request Forgery (SSRF) vulnerability in /api/ping Endpoint — ThinkDashboard 5.3 Medium2025-11-06
CVE-2025-12560 Blog2Social: Social Media Auto Post & Scheduler <= 8.6.0 - Authenticated (Subscriber+) Blind Server-Side Request Forgery via post_url — Blog2Social: Social Media Auto Post & Scheduler 4.3 Medium2025-11-06
CVE-2025-64163 DataEase's DB2 is vulnerable to SSRF — dataease 10.0 -2025-11-05
CVE-2025-12388 B Carousel Block – Responsive Image and Content Carousel <= 1.1.5 - Missing Authorization to Authenticated (Subscriber+) Server-Side Request Forgery — Carousel Block – Responsive Image and Content Carousel 6.4 Medium2025-11-05
CVE-2025-11917 WPeMatico RSS Feed Fetcher <= 2.8.11 - Authenticated (Subscriber+) Server-Side Request Forgery via wpematico_test_feed — WPeMatico RSS Feed Fetcher 6.4 Medium2025-11-05
CVE-2025-62719 LinkAce: Limited Server-Side Request Forgery (SSRF) in Keyword Fetching Functionality — LinkAce 4.3AIMediumAI2025-11-04
CVE-2025-59837 astro allows bypass of image proxy domain validation leading to SSRF and potential XSS — astro 7.2 High2025-10-28
CVE-2025-36085 Multiple Vulnerabilities in IBM Concert Software. — Concert 5.4 Medium2025-10-28
CVE-2025-62988 WordPress Slider Templates plugin <= 1.0.3 - Server Side Request Forgery (SSRF) vulnerability — Slider Templates 4.9 Medium2025-10-27
CVE-2025-10861 Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers <= 2.1.4 - Unauthenticated Server-Side Request Forgery — Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers 7.5 High2025-10-24
CVE-2025-5350 SSRF and Reflected XSS Vulnerability in Deprecated Try-It Feature of Multiple WSO2 Products — WSO2 Identity Server 5.9 Medium2025-10-24
CVE-2025-12136 Real Cookie Banner: GDPR & ePrivacy Cookie Consent <= 5.2.4 - Authenticated (Admin+) Server-Side Request Forgery via scan-without-login Endpoint — Real Cookie Banner: GDPR & ePrivacy Cookie Consent 6.8 Medium2025-10-24
CVE-2025-59503 Azure Compute Resource Provider Elevation of Privilege Vulnerability — Azure Compute Resource Provider 10.0 Critical2025-10-23
CVE-2025-10705 MxChat – AI Chatbot for WordPress <= 2.4.6 - Unauthenticated Blind Server-Side Request Forgery — MxChat – AI Chatbot & Content Generation for WordPress 5.3 Medium2025-10-23
CVE-2025-11128 Feedzy RSS Feeds Lite <= 5.1.0 - Authenticated (Subscriber+) Server-Side Request Forgery — RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator 5.0 Medium2025-10-23
CVE-2025-62612 FastGPT File Reading Node SSRF Vulnerability — FastGPT 9.1AICriticalAI2025-10-22
CVE-2025-49917 WordPress Icegram Express Pro plugin <= 5.9.5 - Server Side Request Forgery (SSRF) vulnerability — Icegram Express Pro 4.4 Medium2025-10-22
CVE-2025-49374 WordPress Captcha.eu plugin <= 1.0.61 - Server Side Request Forgery (SSRF) vulnerability — Captcha.eu 5.4 Medium2025-10-22

Vulnerabilities classified as CWE-918 (服务端请求伪造(SSRF)) represent 1496 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.