CVE-2026-34428
Vvveb prior to 1.0.8.1 contains a server-side request forgery vulnerability in the oEmbedProxy action of the editor/editor module where the
CVSS
7.7
Alto
EPSS
0.3%
p17
KEV
—
Exploit Today
5
0-100
Publicado: 20 abr 2026 · Última mod.: 14 jul 2026 · CWE-918
0.3%EPSS · 30 días0.3%
2026-06-302026-07-20
Vvveb prior to 1.0.8.1 contains a server-side request forgery vulnerability in the oEmbedProxy action of the editor/editor module where the url parameter is passed directly to getUrl() via curl without scheme or destination validation. Authenticated backend users can supply file:// URLs to read arbitrary files readable by the web server process or http:// URLs targeting internal network addresses to probe internal services, with response bodies returned directly to the caller.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-202308.6 ALT98.5%
KEV—80Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability20dCVE-2026-1540910.0 CRÍ66.5%
KEV—70SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability5dCVE-2020-248819.8 CRÍ99.4%
——30SSRF exists in osTicket before 1.14.3, where an attacker can add malicious file to server or perform port scanning.11dCVE-2026-445788.6 ALT98.4%
——30Next.js is a React framework for building full-stack web applications. From 13.4.13 to before 15.5.16 and 16.2.5, self-hosted applications using the built-in Node.js server can be vulnerable to server-side request forgery through crafted WebSocket upgrade requests. An attacker can cause the server to proxy requests to arbitrary internal or external destinations, which may expose internal services or cloud metadata endpoints. Vercel-hosted deployments are not affected. This vulnerability is fixed in 15.5.16 and 16.2.5.5dCVE-2023-271597.5 ALT98.3%
——29Appwrite up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /v1/avatars/favicon. This vulnerability allows attackers to access network resources and sensitive information via a crafted GET request.12dCVE-2026-483327.7 ALT95.7%
——29ColdFusion is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction. Scope is changed.6d