Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-918 (服务端请求伪造(SSRF)) — Vulnerability Class 1489

1489 vulnerabilities classified as CWE-918 (服务端请求伪造(SSRF)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2026-41130 Craft CMS has a host header injection leading to SSRF via resource-js endpoint — cms 10.0AICriticalAI2026-04-21
CVE-2026-41129 Craft CMS has Server-Side Request Forgery (SSRF) with Asset Uploads Mutations — cms 8.3AIHighAI2026-04-21
CVE-2026-41060 AVideo's SSRF via same-domain hostname with alternate port bypasses isSSRFSafeURL — AVideo 7.7 High2026-04-21
CVE-2026-41055 AVideo has an incomplete fix for CVE-2026-33039 (SSRF) — AVideo 8.6 High2026-04-21
CVE-2026-5921 Server-Side Request Forgery in GitHub Enterprise Server allowed extraction of sensitive environment variables via timing side-channel attack — Enterprise Server 7.5AIHighAI2026-04-21
CVE-2026-6744 Bagisto Downloadable Link copy server-side request forgery — Bagisto 6.3 Medium2026-04-21
CVE-2026-40566 FreeScout vulnerable to SSRF via IMAP/SMTP Connection Test Endpoints — freescout 4.1 Medium2026-04-21
CVE-2026-35587 Glances IP Plugin has SSRF via public_api that leads to credential leakage — glances 9.8AICriticalAI2026-04-20
CVE-2026-41302 OpenClaw < 2026.3.31 - Server-Side Request Forgery via Unguarded fetch() in Marketplace Plugin Download — OpenClaw 7.6 High2026-04-20
CVE-2026-41297 OpenClaw < 2026.3.31 - Server-Side Request Forgery via Marketplace Plugin Download Redirect — OpenClaw 7.6 High2026-04-20
CVE-2026-33626 LMDeploy Vulnerable to Server-Side Request Forgery (SSRF) via Vision-Language Image Loading — lmdeploy 7.5 High2026-04-20
CVE-2026-25883 Vexa Webhook Feature has a SSRF Vulnerability — vexa 5.8 Medium2026-04-20
CVE-2026-34428 Vvveb < 1.0.8.1 SSRF via oEmbedProxy — Vvveb 7.7 High2026-04-20
CVE-2026-6649 Qibo CMS headers server-side request forgery — CMS 6.3 Medium2026-04-20
CVE-2026-6625 moxi624 Mogu Blog v2 Picture Storage Service LocalFileServiceImpl.java LocalFileServiceImpl.uploadPictureByUrl server-side request forgery — Mogu Blog v2 7.3 High2026-04-20
CVE-2026-6618 langgenius dify ApiBasedToolSchemaParser parser.py parse_openai_plugin_json_to_tool_bundle server-side request forgery — dify 6.3 Medium2026-04-20
CVE-2026-6617 langgenius dify ApiToolManageService api_tools_manage_service.py get_api_tool_provider_remote_schema server-side request forgery — dify 6.3 Medium2026-04-20
CVE-2026-6616 TransformerOptimus SuperAGI WebScraperTool webpage_extractor.py extract_with_lxml server-side request forgery — SuperAGI 6.3 Medium2026-04-20
CVE-2026-6606 modelscope agentscope _agent_base.py _process_audio_block server-side request forgery — agentscope 7.3 High2026-04-20
CVE-2026-6605 modelscope agentscope Internal Service _common.py _get_bytes_from_web_url server-side request forgery — agentscope 7.3 High2026-04-20
CVE-2026-6604 modelscope agentscope Cloud Metadata Endpoint _openai_tools.py openai_audio_to_text server-side request forgery — agentscope 7.3 High2026-04-20
CVE-2026-6587 vibrantlabsai RAGAS Collections util.py _try_process_url server-side request forgery — RAGAS 6.3 Medium2026-04-20
CVE-2026-6573 PHPEMS Instant Exam Creation exams.master.php temppage server-side request forgery — PHPEMS 6.3 Medium2026-04-19
CVE-2026-40348 Movary has Authenticated SSRF via Jellyfin Server URL Verification that Allows Internal Network Probing — movary 7.7 High2026-04-18
CVE-2026-40346 NocoBase has SSRF in Workflow HTTP Request and Custom Request Plugins — @nocobase/plugin-workflow-request 8.3AIHighAI2026-04-17
CVE-2026-40516 OpenHarness SSRF via web_fetch and web_search — OpenHarness 8.3 High2026-04-17
CVE-2026-6497 prasathmani TinyFileManager File Upload filemanager.php server-side request forgery — TinyFileManager 6.3 Medium2026-04-17
CVE-2026-5131 Server-Side Request Forgery in GREENmod — GREENmod 9.8AICriticalAI2026-04-17
CVE-2026-5052 Vault Vulnerable to Server-Side Request Forgery in ACME Challenge Validation via Attacker-Controlled DNS — Vault 5.3 Medium2026-04-17
CVE-2026-40500 ProcessWire CMS SSRF via Add Module From URL — processwire 6.8 Medium2026-04-15

Vulnerabilities classified as CWE-918 (服务端请求伪造(SSRF)) represent 1489 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.