VulnSea

CWE-918

CVEs classified under CWE-918, newest first.

834 CVEsRSS

CVE-2026-94028Medium· 4.3
1w ago

A weakness has been identified in mealie-recipes Mealie up to 3.25.1

A weakness has been identified in mealie-recipes Mealie up to 3.25.1. Affected is the function payload.model_dump of the file mealie/routes/households/controller_group_recipe_actions.py of the component Recipe Action Trigger. Executing a…

▾ Sunlitmealie-recipes · MealieEPSS 0.45%via NVD
CVE-2026-16542Medium· 4.1
1w ago

The Import and export users and customers WordPress plugin before 2.4.5 does not validate a user-supplied URL before requesting it server-side during a CSV import, allowing high-privileged users to perform Server-Side Request Forgery att…

The Import and export users and customers WordPress plugin before 2.4.5 does not validate a user-supplied URL before requesting it server-side during a CSV import, allowing high-privileged users to perform Server-Side Request Forgery att…

▾ SunlitEPSS 0.18%via NVD
CVE-2026-1641Medium· 6.5
1w ago

The Wow Elements Addons for Elementor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.11.2

The Wow Elements Addons for Elementor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.11.2. This is due to the plugin passing user-controlled input from the 'Changelog File' setti…

▾ Sunlitwowelements · Wow Elements Addons for ElementorEPSS 0.28%via NVD
CVE-2026-75885Critical· 9.3
1w ago

A flaw was found in the OpenShift console

A flaw was found in the OpenShift console. Unauthenticated access to the `/api/devfile/` and `/api/devfile/samples/` endpoints allows a remote attacker to send crafted devfile payloads. This can lead to Server-Side Request Forgery (SSRF)…

▾ MidnightRed Hat · openshift4/ose-consoleEPSS 0.53%via NVD
CVE-2026-76900Medium· 6.8PoC
1w ago

CordysCRM is an open source AI-powered customer relationship management system that supports private deployment

CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. In version 1.7.3, ApprovalResourceService.sendWebHook reads WebHookConfig.webHookUrl from stored approval-node configuration…

▾ Twilight1Panel-dev · CordysCRMEPSS 0.50%via NVD
CVE-2026-18869Medium· 6.4
1w ago

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions and access internal network services due to improper validation of FTP PORT and EPRT commands.

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions and access internal network services due to improper validation of FTP PORT and EPRT commands.

▾ SunlitIBM · iEPSS 0.22%via NVD
GHSA-jgh3-fggc-mcpmHigh· 7.6
1w ago

Obot: Server-Side Request Forgery via remote MCP server URL

Obot: Server-Side Request Forgery via remote MCP server URL

▾ Twilightobot-platform · github.com/obot-platform/obotvia OSV
GHSA-39wr-7q6h-cf68High· 7.5
1w ago

LMDeploy has an SSRF bypass

LMDeploy has an SSRF bypass

▾ Twilightlmdeploy · lmdeployvia OSV
CVE-2026-93506Medium· 6.3
1w ago

A vulnerability was determined in SveltyCMS 0.0.6

A vulnerability was determined in SveltyCMS 0.0.6. This issue affects some unknown processing of the file /mediagallery/upload-media of the component File Upload Endpoint. Executing a manipulation can lead to server-side request forgery.…

▾ SunlitEPSS 0.37%via NVD
CVE-2026-62282Medium· 6.5PoC
1w ago

OpenCVE is a vulnerability intelligence platform

OpenCVE is a vulnerability intelligence platform. Prior to 3.0.0, OpenCVE notification testing for Webhook and Slack integrations does not sufficiently validate user-supplied HTTP or HTTPS destinations. An authenticated user with permiss…

▾ Twilightopencve · opencveEPSS 0.42%via NVD
CVE-2026-93597High· 7.7PoC
1w ago

ArcadeDB versions before 26.9.1 fail to validate IPv6 transition addresses in the SSRF guard used by IMPORT DATABASE and server commands

ArcadeDB versions before 26.9.1 fail to validate IPv6 transition addresses in the SSRF guard used by IMPORT DATABASE and server commands. Authenticated attackers can supply URLs resolving to NAT64, 6to4, or Teredo addresses embedding RFC…

▾ MidnightArcadeData · arcadedbEPSS 0.35%via NVD
CVE-2026-40537Medium· 4.3
1w ago

A server-side request forgery (SSRF) vulnerability in PersonMail API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to obtain non-sensitive information.

A server-side request forgery (SSRF) vulnerability in PersonMail API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to obtain non-sensitive information.

▾ SunlitSynology · DiskStation Manager (DSM)EPSS 0.33%via NVD
CVE-2026-67101Critical· 9.3
1w ago

HCL BigFix Service Management is affected by a Server-Side Request Forgery (SSRF) vulnerability in its search functionality, which could allow an attacker to force the application server to send requests to internal systems that are not …

HCL BigFix Service Management is affected by a Server-Side Request Forgery (SSRF) vulnerability in its search functionality, which could allow an attacker to force the application server to send requests to internal systems that are not …

▾ MidnightHCL Software · HCL BigFix Service ManagementEPSS 0.34%via NVD
CVE-2026-12106Medium· 6.4
1w ago

The Auto Upload Images plugin for WordPress is vulnerable to Limited Server-Side Request Forgery in all versions up to, and including, 3.3.2 via the downloadImage function

The Auto Upload Images plugin for WordPress is vulnerable to Limited Server-Side Request Forgery in all versions up to, and including, 3.3.2 via the downloadImage function. This makes it possible for authenticated attackers, with contrib…

▾ Sunlitairani · Auto Upload ImagesEPSS 0.25%via NVD
CVE-2026-90984Medium· 5.8
1w ago

The Generate PDF using Contact Form 7 WordPress plugin before 4.2.2 does not restrict the destination of the image fetch its PDF renderer performs on submitted form content, allowing unauthenticated users to make the server request inter…

The Generate PDF using Contact Form 7 WordPress plugin before 4.2.2 does not restrict the destination of the image fetch its PDF renderer performs on submitted form content, allowing unauthenticated users to make the server request inter…

▾ SunlitEPSS 0.32%via NVD
CVE-2026-77164Medium· 6.2
1w ago

Circles' remote-instance signature verification fetches the attacker-supplied keyId URL before trust in the remote instance is established, and explicitly allows local/private addresses for this request, bypassing Nextcloud's core SSRF p…

Circles' remote-instance signature verification fetches the attacker-supplied keyId URL before trust in the remote instance is established, and explicitly allows local/private addresses for this request, bypassing Nextcloud's core SSRF p…

▾ SunlitNextcloud · ServerEPSS 0.19%via NVD
CVE-2026-85917High· 7.5
1w ago

Server-side request forgery (ssrf) in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.

Server-side request forgery (ssrf) in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.

▾ Twilightmicrosoft · foundryEPSS 0.97%via NVD
CVE-2026-54734Critical· 10.0
1w ago

Prebid Server Java is the Java version of Prebid Server

Prebid Server Java is the Java version of Prebid Server. Prior to 3.43.0, certain bidder adapters interpolate user-supplied parameters into outbound request URLs without using HttpUtil to validate the resulting domain or path segment. A …

▾ Midnightprebid · prebid-server-javaEPSS 0.62%via NVD
CVE-2026-54507High· 8.4
1w ago

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.5, the oEmbedProxy() handler in admin/controller/editor/editor.php accepts an attacker-controlled url parameter and pa…

▾ Twilightgivanz · VvvebEPSS 0.45%via NVD
CVE-2026-93384Low· 3.7
1w ago

Server-side request forgery in Omnibox in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to bypass system access restrictions via crafted network traffic

Server-side request forgery in Omnibox in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to bypass system access restrictions via crafted network traffic. (Chromium security sev…

▾ Sunlitgoogle · chromeEPSS 0.24%via NVD
CVE-2026-54339High· 7.7PoC
1w ago

Glean is a self-hosted RSS reader and personal knowledge management tool

Glean is a self-hosted RSS reader and personal knowledge management tool. Prior to 0.2.6, POST /api/feeds/discover passes an attacker-supplied feed_url to discover_feed(feed_url), creates a subscription through FeedService.create_subscri…

▾ MidnightLeslieLeung · gleanEPSS 0.47%via NVD
CVE-2026-54918Medium· 5.3
1w ago

NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox

NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. In the affected repository revisions, NETBOX_DT_LIBRARY_URL in tests/test_configuration.py is a free-form tracked constant th…

▾ Sunlitnetbox-community · devicetype-libraryEPSS 0.41%via NVD
CVE-2026-54565Medium· 4.7
1w ago

rhwp is an HWP viewer and editor implemented in Rust and WebAssembly

rhwp is an HWP viewer and editor implemented in Rust and WebAssembly. Prior to rhwp 0.7.15 and rhwp Chrome and Firefox extension 0.2.4, the browser extensions use an all-URLs host permission to detect HWP and HWPX links on visited pages,…

▾ Sunlitedwardkim · rhwpEPSS 0.19%via NVD
CVE-2026-45723Low· 2.7
1w ago

Omni manages Kubernetes on bare metal, virtual machines, or in a cloud

Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.6.6 and 1.7.3, managementServer.CreateSchematic in internal/backend/grpc/schematics.go passes the caller-controlled TalosVersion field to imageFactoryClie…

▾ Sunlitsiderolabs · omniEPSS 0.49%via NVD
CVE-2026-86862Medium· 6.5
1w ago

pgAdmin 4's Restore and Maintenance tools passed the client-supplied 'database' field directly as the value of the --dbname option given to pg_restore and psql

pgAdmin 4's Restore and Maintenance tools passed the client-supplied 'database' field directly as the value of the --dbname option given to pg_restore and psql. libpq expands a database name containing an equals sign into a full connecti…

▾ Sunlitpgadmin · pgadmin_4EPSS 0.35%via NVD
CVE-2026-81446High· 7.4
1w ago

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Server-Side Request Forgery (SSRF) vulnerability

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Server-Side Request Forgery (SSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Server…

▾ TwilightDell · OpenManage Server Administrator Managed Node (Patch) for WindowsEPSS 0.37%via NVD
CVE-2026-61793Medium· 6.9PoC
1w ago

Nuxt OG Image generates OG Images with Vue templates in Nuxt

Nuxt OG Image generates OG Images with Vue templates in Nuxt. From 6.0.2 until 6.7.0, nuxt-og-image exposes the unauthenticated /_og/d/** route when the documented defaults security.strict = false and security.secret = "" are used, and b…

▾ Twilightnuxt-modules · og-imageEPSS 0.50%via NVD
CVE-2026-81443Medium· 6.4
1w ago

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Server-Side Request Forgery (SSRF) vulnerability

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Server-Side Request Forgery (SSRF) vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Server-s…

▾ SunlitDell · OpenManage Server Administrator Managed Node (Patch) for WindowsEPSS 0.23%via NVD
CVE-2026-66608Medium· 6.4
1w ago

Contributor Server Side Request Forgery (SSRF) in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.19 versions.

Contributor Server Side Request Forgery (SSRF) in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.19 versions.

▾ SunlitUnlimited Elements · unlimited-elements-for-elementorEPSS 0.23%via NVD
CVE-2026-92932Medium· 5.1
1w ago

In the MISP sachertortephp library, the Xml::build() static method in lib/Cake/Utility/Xml.php contains a logic error in the conditional that gates network-based XML fetching

In the MISP sachertortephp library, the Xml::build() static method in lib/Cake/Utility/Xml.php contains a logic error in the conditional that gates network-based XML fetching. The original condition was written as: $options['readFile'] &…

▾ Sunlitmisp · sachertortephpEPSS 0.39%via NVD
CWE-918 vulnerabilities (CVEs) — page 4 · VulnSea