CWE-918


Server-Side Request Forgery (SSRF)

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.


We have discovered 6,951,576 live websites that are affected by CWE-918.

Contact us to get more info









CVEs

  • Count - 158



Website Distribution by Country

Number of websites using CWE-918
United States1,646,462 websites



Germany1,205,350 websites
France392,698 websites
Japan351,194 websites
Netherlands293,374 websites
Russia245,925 websites
GB233,719 websites
Italy218,990 websites
Poland137,895 websites
Spain136,963 websites

Website Distribution by TLD

Number of websites using CWE-918
.com2,600,690 websites
.de779,500 websites
.org289,695 websites
.nl268,556 websites
.net223,871 websites
.ru206,551 websites
.it165,561 websites
.fr149,248 websites
.co.uk147,725 websites
.pl108,541 websites

Newest CVEs

List of the most recent CVEs that are part of CWE-918
DiscoveredCVEDescriptionWebsites
Oct, 2025CVE-2025-10735 Block For Mailchimp – Easy Mailchimp Form Integration <= 1.1.12 - Unauthenticated Blind Server-Side Request Forgery92
Sep, 2025CVE-2025-53461 WordPress Beaf Plugin <= 1.6.2 - Server Side Request Forgery (SSRF) Vulnerability154
Sep, 2025CVE-2025-58962 WordPress Publitio Plugin <= 2.2.1 - Server Side Request Forgery (SSRF) Vulnerability188
Sep, 2025CVE-2025-9862 Ghost 6.0.6 - SSRF via oEmbed Bookmark7,035
Sep, 2025CVE-2025-47437 WordPress LiteSpeed Cache plugin <= 7.0.1 - Server Side Request Forgery (SSRF) vulnerability351,708
Sep, 2025CVE-2025-49430 WordPress Ultimate Video Player Plugin <= 10.1 - Server Side Request Forgery (SSRF) Vulnerability299
Sep, 2025CVE-2025-8085 Ditty < 3.1.58 - Unauthenticated SSRF16,566
Sep, 2025CVE-2025-43763 A server-side request forgery (SSRF) vulnerability exist in the Liferay Portal 7.4.0 through 7.4.3....72
Sep, 2025CVE-2025-58829 WordPress Ai Auto Tool Content Writing Assistant (Gemini Writer, ChatGPT ) All in One Plugin <= 2.2.6 - Server Side Request Forgery (SSRF) Vulnerability50
Sep, 2025CVE-2025-58615 WordPress WP Bannerize Pro Plugin <= 1.10.0 - Server Side Request Forgery (SSRF) Vulnerability409
List of the most common CVEs that are part of CWE-918
DiscoveredCVEDescriptionWebsites
Jul, 2025CVE-2024-43204 Apache HTTP Server: SSRF with mod_headers setting Content-Type header2,443,002
Jul, 2025CVE-2024-43394 Apache HTTP Server: SSRF on Windows due to UNC paths2,443,002
Jul, 2025CVE-2025-1220 Null byte termination in hostnames1,901,072
Jul, 2024CVE-2024-38472 Apache HTTP Server on WIndows UNC SSRF1,836,707
Dec, 2022CVE-2022-3590 WP <= 6.1.1 - Unauthenticated Blind SSRF via DNS Rebinding1,812,530
Jul, 2024CVE-2024-40898 Apache HTTP Server: SSRF with mod_rewrite in server/vhost context on Windows1,468,426
Sep, 2021CVE-2021-40438 mod_proxy SSRF1,033,403
Sep, 2025CVE-2025-47437 WordPress LiteSpeed Cache plugin <= 7.0.1 - Server Side Request Forgery (SSRF) vulnerability351,708
Jul, 2024CVE-2024-4260 CoBlocks < 3.1.12 - Contributor+ SSRF158,691
Feb, 2025CVE-2024-13695 Enfold <= 6.0.9 - Authenticated (Subscriber+) Server-Side Request Forgery via attachment_id132,801

Websites affected by CWE-918

Top websites that are affected by CWE-918. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********.com United States**
*******.com Singapore***
************.org Singapore***
********.com United States***
*****************.com United States***
****.br Brazil***
**********.com United States***
*****.net Singapore***
****.******.com Singapore***
*************.***.****.****.************.net United States***
See full domain list