CWE-918


Server-Side Request Forgery (SSRF)

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.


We have discovered 3,570,304 live websites that are affected by CWE-918.

Contact us to get more info









CVEs

  • Count - 3



Countries

United States800,563 websites



Germany324,652 websites
Japan277,831 websites
France206,325 websites
Italy176,943 websites
GB157,850 websites
Russia134,346 websites
Netherlands120,867 websites
Poland116,022 websites
Spain108,349 websites

TLDs

.com1,443,475 websites
.de206,066 websites
.org142,197 websites
.it116,054 websites
.ru108,566 websites
.net106,115 websites
.nl97,652 websites
.co.uk92,872 websites
.pl85,872 websites
.fr82,781 websites

Newest CVEs

List of the most recent CVEs that are part of CWE-918
DiscoveredCVEDescriptionWebsites
Feb, 2024CVE-2023-6294 popup-builder < 4.2.6 - Admin+ SSRF & File Read804
Nov, 2023CVE-2023-31219 WordPress Download Monitor Plugin <= 4.8.1 is vulnerable to Server Side Request Forgery (SSRF)1,486
Dec, 2022CVE-2022-3590 WP <= 6.1.1 - Unauthenticated Blind SSRF via DNS Rebinding3,568,724
List of the most common CVEs that are part of CWE-918
DiscoveredCVEDescriptionWebsites
Dec, 2022CVE-2022-3590 WP <= 6.1.1 - Unauthenticated Blind SSRF via DNS Rebinding3,568,724
Nov, 2023CVE-2023-31219 WordPress Download Monitor Plugin <= 4.8.1 is vulnerable to Server Side Request Forgery (SSRF)1,486
Feb, 2024CVE-2023-6294 popup-builder < 4.2.6 - Admin+ SSRF & File Read804

Websites affected by CWE-918

Top websites that are affected by CWE-918. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
************.org Singapore***
***.*****************.com United States***
****.br Brazil***
****.******.com Singapore***
***.**********.com United States***
***.*********.com Germany***
*******.******.com United States***
***.*******.com Turkey***
****.*****.net United States***
***.*********.com United States***
See full domain list