Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-918 (服务端请求伪造(SSRF)) — Vulnerability Class 1496

1496 vulnerabilities classified as CWE-918 (服务端请求伪造(SSRF)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2024-35172 WordPress ShortPixel Adaptive Images plugin <= 3.8.3 - Server Side Request Forgery (SSRF) vulnerability — ShortPixel Adaptive Images 4.4 Medium2024-05-13
CVE-2024-32964 lobe-chat `/api/proxy` endpoint Server-Side Request Forgery vulnerability — lobe-chat 9.0 Critical2024-05-10
CVE-2024-1467 Starter Templates — Elementor, WordPress & Beaver Builder Templates <= 4.1.6 - Authenticated (Contributor+) Server-Side Request Forgery — Starter Templates – AI-Powered Templates for Elementor & Gutenberg 4.3 Medium2024-05-09
CVE-2024-34351 Next.js Server-Side Request Forgery in Server Actions — next.js 7.5 High2024-05-09
CVE-2024-3047 PDF Invoices & Packing Slips for WooCommerce <= 3.8.0 - Unauthenticated Server-Side Request Forgery — PDF Invoices & Packing Slips for WooCommerce 7.2 High2024-05-02
CVE-2024-23336 Incomplete disallowed remote addresses list in MyBB — mybb 5.0 Medium2024-05-01
CVE-2024-2663 ZD YouTube FLV Player <= 1.2.6 - Server-Side Request Forgery — ZD YouTube FLV Player 8.3 High2024-04-30
CVE-2024-0216 Google Doc Embedder <= 2.6.4 - Authenticated (Contributor+) Blind Server Side Request Forgery — Google Doc Embedder 6.4 Medium2024-04-30
CVE-2024-33590 WordPress basepress plugin <= 2.16.1 - Server Side Request Forgery (SSRF) vulnerability — Knowledge Base documentation & wiki plugin – BasePress 5.0 Medium2024-04-29
CVE-2024-33634 WordPress Piotnet Addons For Elementor Pro plugin <= 7.1.17 - Unauthenticated Server Side Request Forgery (SSRF) vulnerability — Piotnet Addons For Elementor Pro 5.4 Medium2024-04-29
CVE-2024-33629 WordPress Auto Featured Image (Auto Post Thumbnail) plugin <= 4.0.0 - Server Side Request Forgery (SSRF) vulnerability — Auto Featured Image (Auto Post Thumbnail) 4.4 Medium2024-04-29
CVE-2024-33627 WordPress AGCA – Custom Dashboard & Login Page plugin <= 7.2.2 - Server Side Request Forgery (SSRF) vulnerability — Absolutely Glamorous Custom Admin 4.4 Medium2024-04-29
CVE-2024-33592 WordPress Radio Player plugin <= 2.0.73 - Server Side Request Forgery (SSRF) vulnerability — Radio Player 5.4 Medium2024-04-25
CVE-2024-32718 WordPress The Pack Elementor addons plugin <= 2.0.8.2 - Server Side Request Forgery (SSRF) vulnerability — The Pack Elementor addons 4.9 Medium2024-04-24
CVE-2024-32775 WordPress Embed Google Photos album plugin <= 2.1.9 - Server Side Request Forgery (SSRF) vulnerability — Embed Google Photos album 4.9 Medium2024-04-24
CVE-2024-32803 WordPress SuperFaktura WooCommerce plugin <= 1.40.3 - Server Side Request Forgery (SSRF) vulnerability — SuperFaktura WooCommerce 6.4 Medium2024-04-24
CVE-2024-32812 WordPress Podlove Podcast Publisher plugin <= 4.0.11 - Server Side Request Forgery (SSRF) vulnerability — Podlove Podcast Publisher 5.4 Medium2024-04-24
CVE-2024-32819 WordPress Culqi plugin <= 3.0.14 - Server Side Request Forgery (SSRF) vulnerability — Culqi 4.9 Medium2024-04-24
CVE-2024-32955 WordPress FV Flowplayer Video Player plugin <= 7.5.43.7212 - Server Side Request Forgery (SSRF) vulnerability — FV Flowplayer Video Player 4.9 Medium2024-04-24
CVE-2024-27347 Apache HugeGraph-Hubble: SSRF in Hubble connection page — Apache HugeGraph-Hubble 9.1 -2024-04-22
CVE-2024-31993 Mealie vulnerable to a GET-based SSRF in recipe image importer (GHSL-2023-227) — mealie 6.2 Medium2024-04-19
CVE-2024-31991 Mealie vulnerable to a GET-based SSRF in recipe importer (GHSL-2023-225) — mealie 4.1 Medium2024-04-19
CVE-2024-29029 memos vulnerable to an SSRF in /o/get/image — memos 6.1 Medium2024-04-19
CVE-2024-29028 memos vulnerable to an SSRF in /o/get/httpmeta — memos 5.8 Medium2024-04-19
CVE-2024-29030 memos vulnerable to an SSRF in /api/resource — memos 5.8 Medium2024-04-19
CVE-2024-2796 SSRF in Akana API Platform — Akana API Platform 9.3 Critical2024-04-18
CVE-2024-29021 SSRF into Sandbox Escape through Unsafe Default Configuration — judge0 9.1 Critical2024-04-18
CVE-2024-31229 WordPress Really Simple SSL plugin <= 7.2.3 - Server Side Request Forgery (SSRF) vulnerability — Really Simple SSL 5.5 Medium2024-04-18
CVE-2024-29035 Umbraco's Blind SSRF Leads to Port Scan by using Webhooks — Umbraco-CMS 4.1 Medium2024-04-17
CVE-2023-6805 RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 4.4.7 - Authenticated(Contributor+) Blind Server-Side Request Forgery (SSRF) — RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator 6.4 Medium2024-04-17

Vulnerabilities classified as CWE-918 (服务端请求伪造(SSRF)) represent 1496 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.