Skip to content

Known CVE

Ech0 < 4.2.8 - Server-Side Request Forgery

Ech0 before 4.2.8 exposes an unauthenticated SSRF vulnerability in GET /api/website/title. The website_url query parameter is fetched server-side without validating the target host or IP address.

CVE-2026-35037

High2026CVSS 7.2CWE-918

cve2026 · ech0 · ssrf · oast · oss

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website