VulnSea

CWE-918

CVEs classified under CWE-918, newest first.

838 CVEsRSS

CVE-2026-66304High· 7.5
2w ago

Server-side request forgery (ssrf) in Skype for Business allows an unauthorized attacker to disclose information over a network.

Server-side request forgery (ssrf) in Skype for Business allows an unauthorized attacker to disclose information over a network.

▾ Twilightmicrosoft · skype_for_business_serverEPSS 0.97%via NVD
CVE-2026-86074High· 7.1
2w ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the Instance AI credential setup flow accepted a credential test or verification URL without checking that it matched the workflow node's origin. Attacker-co…

▾ Twilightn8n · n8nEPSS 0.38%via NVD
CVE-2026-81357High· 8.2
2w ago

Server-side request forgery (ssrf) in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.

Server-side request forgery (ssrf) in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.

▾ Twilightmicrosoft · visual_studio_codeEPSS 0.51%via NVD
CVE-2026-69904Low· 3.5
2w ago

Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.

Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.

▾ Sunlitmicrosoft · sharepoint_serverEPSS 0.58%via NVD
CVE-2026-69683Medium· 6.5
2w ago

Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.

Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.

▾ Sunlitmicrosoft · sharepoint_serverEPSS 0.84%via NVD
CVE-2026-69361Medium· 6.5
2w ago

Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.

Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.

▾ SunlitMicrosoft · Microsoft Exchange Server 2016 Cumulative Update 23EPSS 0.86%via NVD
CVE-2026-48707Low· 3.1PoC
2w ago

InstantCMS is a free and open source content management system

InstantCMS is a free and open source content management system. Versions prior to 2.18.2 have a Server-Side Request Forgery (SSRF) vulnerability in the file upload functionality (`system/core/uploader.php` at lines 509-532). When the "up…

▾ Twilightinstantsoft · icms2EPSS 0.27%via NVD
CVE-2026-86735Medium· 5.0
2w ago

snipe-it versions before 8.7.0 contain a server-side request forgery vulnerability in the ExternalUrl validation rule that fails to detect IPv6 transition addresses encoding private IPv4 targets

snipe-it versions before 8.7.0 contain a server-side request forgery vulnerability in the ExternalUrl validation rule that fails to detect IPv6 transition addresses encoding private IPv4 targets. Attackers with super-admin privileges can…

▾ Sunlitsnipeitapp · snipe-itEPSS 0.31%via NVD
CVE-2026-84282Medium· 6.5
2w ago

A Server-Side Request Forgery (SSRF) vulnerability exists in the ONLYOFFICE ownCloud Integration plugin version 9.12

A Server-Side Request Forgery (SSRF) vulnerability exists in the ONLYOFFICE ownCloud Integration plugin version 9.12. The /apps/onlyoffice/ajax/settings/address endpoint does not sufficiently validate the user-supplied Document Server UR…

▾ SunlitAscensio System SIA / OnlyOffice · ONLYOFFICE ownCloud integration pluginEPSS 0.27%via NVD
CVE-2026-73315High· 8.6PoC
2w ago

XenForo before 2.3.13 contains a server-side request forgery vulnerability in the PayPal REST webhook handler that allows unauthenticated attackers to cause the server to make outbound HTTP requests to arbitrary destinations by supplying…

XenForo before 2.3.13 contains a server-side request forgery vulnerability in the PayPal REST webhook handler that allows unauthenticated attackers to cause the server to make outbound HTTP requests to arbitrary destinations by supplying…

▾ Midnightxenforo · xenforoEPSS 0.36%via NVD
CVE-2026-86590Medium· 6.3PoC
2w ago

In Eclipse Che versions 7.79.0 through 7.121.0, the dashboard backend's POST /dashboard/api/data/resolver endpoint passes a caller-supplied URL directly to an outbound HTTP GET request with no host filtering

In Eclipse Che versions 7.79.0 through 7.121.0, the dashboard backend's POST /dashboard/api/data/resolver endpoint passes a caller-supplied URL directly to an outbound HTTP GET request with no host filtering. An authenticated user can ex…

▾ TwilightEclipse Foundation · Eclipse CheEPSS 0.39%via NVD
CVE-2026-81806High· 7.2
2w ago

Server-Side Request Forgery (SSRF) vulnerability in John Darrel Hide My WP Ghost allows Server Side Request Forgery. This issue affects Hide My WP Ghost: from n/a through 7.0.09.

Server-Side Request Forgery (SSRF) vulnerability in John Darrel Hide My WP Ghost allows Server Side Request Forgery. This issue affects Hide My WP Ghost: from n/a through 7.0.09.

▾ TwilightJohn Darrel · hide-my-wpEPSS 0.27%via NVD
CVE-2026-76971Medium· 6.5
2w ago

Due to a Server-Side Request Forgery (SSRF) vulnerability in SAP Manufacturing Integration and Intelligence, an attacker could cause the server to initiate arbitrary outbound requests

Due to a Server-Side Request Forgery (SSRF) vulnerability in SAP Manufacturing Integration and Intelligence, an attacker could cause the server to initiate arbitrary outbound requests. If processed by the application, this behavior could…

▾ SunlitSAP_SE · SAP Manufacturing Integration and IntelligenceEPSS 0.25%via NVD
CVE-2026-86539High· 7.2
2w ago

knowns through 0.33.0 contains a server-side request forgery vulnerability in the POST /api/embedding-models/test endpoint that issues outbound requests to caller-supplied destinations without validation

knowns through 0.33.0 contains a server-side request forgery vulnerability in the POST /api/embedding-models/test endpoint that issues outbound requests to caller-supplied destinations without validation. Attackers can enumerate internal…

▾ Twilightknowns-dev · knownsEPSS 0.35%via NVD
CVE-2026-86503Low· 3.3
2w ago

In JetBrains IntelliJ IDEA before 2026.2.2 opening an untrusted project could trigger SSRF via Kubernetes spec-source URL fetching

In JetBrains IntelliJ IDEA before 2026.2.2 opening an untrusted project could trigger SSRF via Kubernetes spec-source URL fetching

▾ SunlitJetBrains · IntelliJ IDEAEPSS 0.14%via NVD
CVE-2026-82757Medium· 6.3
2w ago

Server-Side Request Forgery (SSRF) vulnerability in ash-project ash_authentication_oauth2_server allows an attacker who controls a client metadata URL and its DNS to make the server connect to internal or loopback addresses. public_ip?/…

Server-Side Request Forgery (SSRF) vulnerability in ash-project ash_authentication_oauth2_server allows an attacker who controls a client metadata URL and its DNS to make the server connect to internal or loopback addresses. public_ip?/…

▾ Sunlitash-project · ash_authentication_oauth2_serverEPSS 0.66%via NVD
CVE-2026-86321Medium· 5.3PoC
2w ago

A vulnerability was found in java-json-tools jackson-coreutils 2.0

A vulnerability was found in java-json-tools jackson-coreutils 2.0. Affected by this issue is the function JsonLoader.fromURL of the file src/main/java/com/github/fge/jackson/JsonLoader.java of the component URL Validation. The manipulat…

▾ Twilightjava-json-tools · jackson-coreutilsEPSS 0.66%via NVD
CVE-2026-86419Critical· 9.1⚖ disputed
2w ago

Affected versions of MISP contain insufficient validation of server-side outbound HTTP destinations in feed retrieval and TAXII discovery functionality. In feed processing, redirects were followed without validating the redirect scheme…

Affected versions of MISP contain insufficient validation of server-side outbound HTTP destinations in feed retrieval and TAXII discovery functionality. In feed processing, redirects were followed without validating the redirect scheme…

▾ Midnightmisp-project · mispEPSS 0.42%via NVD
CVE-2026-86273High· 7.3PoC
2w ago

A weakness has been identified in projeto-siga siga up to 11.1.1

A weakness has been identified in projeto-siga siga up to 11.1.1. Affected by this issue is the function DownloadExterno.getUrl of the file sigaex/src/main/java/br/gov/jfrj/siga/vraptor/ExUtilController.java of the component HTML-to-PDF …

▾ Midnightprojeto-siga · sigaEPSS 0.50%via NVD
CVE-2026-86240Medium· 4.7PoC
2w ago

A security flaw has been discovered in liufee FeehiCMS up to 2.1.1

A security flaw has been discovered in liufee FeehiCMS up to 2.1.1. This affects the function catchImage of the file backend/widgets/ueditor/Uploader.php of the component UEditor. The manipulation of the argument source[] results in serv…

▾ Twilightliufee · FeehiCMSEPSS 0.40%via NVD
CVE-2026-86237Medium· 5.3PoC
2w ago

A vulnerability was found in openagents-org openagents up to 0.8.19/0.9.3.post20

A vulnerability was found in openagents-org openagents up to 0.8.19/0.9.3.post20. Impacted is the function test_default_model of the file sdk/src/openagents/sdk/transports/http.py. Performing a manipulation of the argument base_url resul…

▾ Twilightopenagents-org · openagentsEPSS 0.54%via NVD
CVE-2026-86259High· 7.5PoC
3w ago

OpenMAIC before 1.0.1 skips server-side request forgery validation in non-production builds, allowing unauthenticated attackers to reach cloud instance metadata services

OpenMAIC before 1.0.1 skips server-side request forgery validation in non-production builds, allowing unauthenticated attackers to reach cloud instance metadata services. Attackers can supply arbitrary provider URLs via the x-base-url he…

▾ MidnightTHU-MAIC · OpenMAICEPSS 0.42%via NVD
CVE-2026-86100Medium· 6.4
3w ago

Camaleon CMS versions 2.7.5 through 2.9.1 fail to validate redirect targets when fetching remote files in the Upload from URL media feature

Camaleon CMS versions 2.7.5 through 2.9.1 fail to validate redirect targets when fetching remote files in the Upload from URL media feature. Authenticated attackers can supply URLs that pass initial validation but redirect to internal ne…

▾ Sunlitowen2345 · camaleon_cmsEPSS 0.32%via NVD
CVE-2026-86173High· 7.5PoC
3w ago

MindsDB through 26.1.0 contains a server-side request forgery vulnerability in the web crawler handler that allows unauthenticated attackers to fetch arbitrary URLs by supplying caller-controlled URLs to CrawlerTable.list

MindsDB through 26.1.0 contains a server-side request forgery vulnerability in the web crawler handler that allows unauthenticated attackers to fetch arbitrary URLs by supplying caller-controlled URLs to CrawlerTable.list. Attackers can …

▾ Midnightmindsdb · mindsdbEPSS 0.65%via NVD
CVE-2026-86123High· 8.7PoC
3w ago

SQL Chat contains four unauthenticated API endpoints that accept client-supplied database connection parameters and execute arbitrary SQL queries against attacker-specified hosts

SQL Chat contains four unauthenticated API endpoints that accept client-supplied database connection parameters and execute arbitrary SQL queries against attacker-specified hosts. Attackers can connect to internal databases, execute SQL …

▾ Midnightsqlchat · sqlchatEPSS 0.49%via NVD
CVE-2026-86122Medium· 5.0
3w ago

Rowboat through 0.9.1 fails to validate custom MCP server and webhook URLs, allowing authenticated users to configure arbitrary destinations

Rowboat through 0.9.1 fails to validate custom MCP server and webhook URLs, allowing authenticated users to configure arbitrary destinations. Attackers can point these URLs at internal services and cloud metadata endpoints to perform ser…

▾ Sunlitrowboatlabs · rowboatEPSS 0.37%via NVD
CVE-2026-86119High· 8.6
3w ago

Webstudio through 0.296.0 contains an unauthenticated server-side request forgery vulnerability in the /cgi/image, /cgi/video, and /cgi/asset proxy routes when RESIZE_ORIGIN environment variable is unset

Webstudio through 0.296.0 contains an unauthenticated server-side request forgery vulnerability in the /cgi/image, /cgi/video, and /cgi/asset proxy routes when RESIZE_ORIGIN environment variable is unset. Attackers can supply arbitrary U…

▾ Twilightwebstudio-is · webstudioEPSS 0.57%via NVD
CVE-2026-83543Medium· 4.1
3w ago

The Greenshift WordPress plugin before 13.2.0 does not validate a user-supplied URL before fetching it server-side, allowing users with contributor-level access and above to make the server issue requests to arbitrary hosts and read the…

The Greenshift WordPress plugin before 13.2.0 does not validate a user-supplied URL before fetching it server-side, allowing users with contributor-level access and above to make the server issue requests to arbitrary hosts and read the…

▾ SunlitEPSS 0.30%via NVD
CVE-2026-4361Medium· 5.0
3w ago

The Divi theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.27.6

The Divi theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.27.6. This is due to the `et_pb_set_video_oembed_thumbnail_resolution()` function using `wp_remote_get()` instead of `wp_sa…

▾ SunlitEPSS 0.36%via NVD
CVE-2026-52769High· 8.3PoC
3w ago

YesWiki is a wiki system written in PHP

YesWiki is a wiki system written in PHP. From version 4.6.2 to before version 4.6.6, the POST /api/forms/{formId}/actor/inbox route - exposed publicly with acl:"public" - accepts an HTTP Signature header whose keyId parameter is a URL. H…

▾ MidnightYesWiki · yeswikiEPSS 0.49%via NVD
CWE-918 vulnerabilities (CVEs) — page 9 · VulnSea