Known CVE
Ech0 < 4.2.8 - Server-Side Request Forgery
Ech0 before 4.2.8 exposes an unauthenticated SSRF vulnerability in GET /api/website/title. The website_url query parameter is fetched server-side without validating the target host or IP address.
CVE-2026-35037
High2026CVSS 7.2CWE-918
cve2026 · ech0 · ssrf · oast · oss
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website