CWE-601— URL Redirection to Untrusted Site (Open Redirect)
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.— MITRE CWE catalog
1,776 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-601page 12 of 36
- CVE-2025-47789MEDIUMCVSS 6.1EG 6.12025-05-15
Horilla is a free and open source Human Resource Management System (HRMS). In versions up to and including 1.3, an attacker can craft a Horilla URL that refers to an external domain. Upon clicking and logging in, the user is redirected to …
- CVE-2024-6690MEDIUMCVSS 6.1EG 6.12025-05-15
The wccp-pro WordPress plugin before 15.3 contains an open-redirect flaw via the referrer parameter, allowing redirection of users to external sites
- CVE-2023-6786MEDIUMCVSS 6.1EG 6.12025-05-15
The Payment Gateway for Telcell WordPress plugin through 2.0.1 does not validate the api_url parameter before redirecting the user to its value, leading to an Open Redirect issue
- CVE-2025-30010MEDIUMCVSS 6.1EG 6.12025-05-13
The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the affected SRM packages which allows an unauthenticated attacker to craft a malicious link, which when clicked by a vic…
- CVE-2025-46553MEDIUMCVSS 6.1EG 6.12025-05-05
@misskey-dev/summaly is a tool for getting a summary of a web page. Starting in version 3.0.1 and prior to version 5.2.1, a logic error in the main `summaly` function causes the `allowRedirects` option to never be passed to any plugins, an…
- CVE-2025-4143MEDIUMCVSS 6.1EG 6.12025-05-01
The OAuth implementation in workers-oauth-provider that is part of MCP framework https://github.com/cloudflare/workers-mcp , did not correctly validate that redirect_uri was on the allowed list of redirect URIs for the given client regist…
- CVE-2025-3859MEDIUMCVSS 6.1EG 6.12025-04-30
Websites directing users to long URLs that caused eliding to occur in the location view could leverage the truncating behavior to potentially trick users into thinking they were on a different webpage. This vulnerability was fixed in Focus…
- CVE-2025-32970MEDIUMCVSS 6.1EG 6.12025-04-30
XWiki is a generic wiki platform. In versions starting from 13.5-rc-1 to before 15.10.13, from 16.0.0-rc-1 to before 16.4.4, and from 16.5.0-rc-1 to before 16.8.0, an open redirect vulnerability in the HTML conversion request filter allows…
- CVE-2024-49706MEDIUMCVSS 6.1EG 6.12025-04-14
Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Open Redirect attacks by including base64 encoded URLs in the target parameter sent in a POST request to one of the endpoints. This vulnerability has been patched i…
- CVE-2025-3433MEDIUMCVSS 6.1EG 6.12025-04-08
The Advanced Advertising System plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 1.3.1. This is due to insufficient validation on the redirect url supplied via the 'redir' parameter. This makes it p…
- CVE-2025-3027MEDIUMCVSS 6.1EG 6.12025-03-31
The vulnerability exists in the EJBCA service, version 8.0 Enterprise. By making a small change to the PATH of the URL associated with the service, the server fails to find the requested file and redirects to an external page. This vulnera…
- CVE-2024-9308MEDIUMCVSS 6.1EG 6.12025-03-20
An open redirect vulnerability in haotian-liu/llava version v1.2.0 (LLaVA-1.6) allows a remote unauthenticated attacker to redirect users to arbitrary websites via a specially crafted URL. This can be exploited for phishing attacks, malwar…
- CVE-2024-8021MEDIUMCVSS 6.1EG 6.12025-03-20
An open redirect vulnerability exists in the latest version of gradio-app/gradio. The vulnerability allows an attacker to redirect users to a malicious website by URL encoding. This can be exploited by sending a crafted request to the appl…
- CVE-2024-11044MEDIUMCVSS 6.1EG 6.12025-03-20
An open redirect vulnerability in automatic1111/stable-diffusion-webui version 1.10.0 allows a remote unauthenticated attacker to redirect users to arbitrary websites via a specially crafted URL. This vulnerability can be exploited to cond…
- CVE-2024-10908MEDIUMCVSS 6.1EG 6.12025-03-20
An open redirect vulnerability in lm-sys/fastchat Release v0.2.36 allows a remote unauthenticated attacker to redirect users to arbitrary websites via a specially crafted URL. This can be exploited for phishing attacks, malware distributio…
- CVE-2024-10812MEDIUMCVSS 6.1EG 6.12025-03-20
An open redirect vulnerability exists in binary-husky/gpt_academic version 3.83. The vulnerability occurs when a user is redirected to a URL specified by user-controlled input in the 'file' parameter without proper validation or sanitizati…
- CVE-2025-1300MEDIUMCVSS 6.1EG 6.12025-02-28
CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. The CodeChecker web server contains an open redirect vulnerability due to missing protections against multiple slashes…
- CVE-2024-54957MEDIUMCVSS 6.1EG 6.12025-02-27
Nagios XI 2024R1.2.2 is vulnerable to an open redirect flaw on the Tools page, exploitable by users with read-only permissions. This vulnerability allows an attacker to craft a malicious link that redirects users to an arbitrary external U…
- CVE-2025-27143MEDIUMCVSS 6.1EG 6.12025-02-24
Better Auth is an authentication and authorization library for TypeScript. Prior to version 1.1.21, the application is vulnerable to an open redirect due to improper validation of the callbackURL parameter in the email verification endpoin…
- CVE-2025-21512MEDIUMCVSS 6.1EG 6.12025-01-21
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are Prior to 9.2.9.0. Easily exploitable vulnerability allows unauthenticated attacker wit…
- CVE-2025-24020MEDIUMCVSS 6.1EG 6.12025-01-21
WeGIA is a Web manager for charitable institutions. An Open Redirect vulnerability was identified in the `control.php` endpoint of versions up to and including 3.2.10 of the WeGIA application. The vulnerability allows the `nextPage` parame…
- CVE-2025-23086MEDIUMCVSS 6.1EG 6.12025-01-21
On most desktop platforms, Brave Browser versions 1.70.x-1.73.x included a feature to show a site's origin on the OS-provided file selector dialog when a site prompts the user to upload or download a file. However the origin was not correc…
- CVE-2024-56734MEDIUMCVSS 6.1EG 6.12024-12-30
Better Auth is an authentication library for TypeScript. An open redirect vulnerability has been identified in the verify email endpoint of all versions of Better Auth prior to v1.1.6, potentially allowing attackers to redirect users to ma…
- CVE-2024-54051MEDIUMCVSS 6.1EG 6.12024-12-10
Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. An attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of thi…
- CVE-2024-54050MEDIUMCVSS 6.1EG 6.12024-12-10
Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. An attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of thi…
- CVE-2024-52003MEDIUMCVSS 6.1EG 6.12024-11-29
Traefik (pronounced traffic) is an HTTP reverse proxy and load balancer. There is a vulnerability in Traefik that allows the client to provide the X-Forwarded-Prefix header from an untrusted source. This issue has been addressed in version…
- CVE-2024-1240MEDIUMCVSS 6.1EG 6.12024-11-15
An open redirection vulnerability exists in pyload/pyload version 0.5.0. The vulnerability is due to improper handling of the 'next' parameter in the login functionality. An attacker can exploit this vulnerability to redirect users to mali…
- CVE-2024-25566MEDIUMCVSS 6.1EG 6.12024-10-29
An Open-Redirect vulnerability exists in PingAM where well-crafted requests may cause improper validation of redirect URLs. This could allow an attacker to redirect end-users to malicious sites under their control, simplifying phishing att…
- CVE-2024-42930MEDIUMCVSS 6.1EG 6.12024-10-28
PbootCMS 3.2.8 is vulnerable to URL Redirect.
- CVE-2024-46326MEDIUMCVSS 6.1EG 6.12024-10-21
Public Knowledge Project pkp-lib 3.4.0-7 and earlier is vulnerable to Open redirect due to a lack of input sanitization in the logout function.
- CVE-2024-45247MEDIUMCVSS 6.1EG 6.12024-10-06
Sonarr – CWE-601: URL Redirection to Untrusted Site ('Open Redirect')
- CVE-2024-43683MEDIUMCVSS 6.1EG 6.12024-10-04
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Microchip TimeProvider 4100 allows XSS Through HTTP Headers.This issue affects TimeProvider 4100: from 1.0.
- CVE-2024-8148MEDIUMCVSS 6.1EG 6.12024-10-04
There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.2 and below that may allow a remote, unauthenticated attacker to craft a URL that could redirect a victim to an arbitrary website, simplifying phishing attacks.
- CVE-2024-38037MEDIUMCVSS 6.1EG 6.12024-10-04
There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.0 and below that may allow a remote, unauthenticated attacker to craft a URL that could redirect a victim to an arbitrary website, simplifying phishing attacks.
- CVE-2024-9329MEDIUMCVSS 6.1EG 6.12024-09-30
In Eclipse Glassfish versions before 7.0.17, The Host HTTP parameter could cause the web application to redirect to the specified URL, when the requested endpoint is '/management/domain'. By modifying the URL value to a malicious site, an …
- CVE-2024-8883MEDIUMCVSS 6.1EG 6.12024-09-19
A misconfiguration flaw was found in Keycloak. This issue can allow an attacker to redirect users to an arbitrary URL if a 'Valid Redirect URI' is set to http://localhost or http://127.0.0.1, enabling sensitive information such as authoriz…
- CVE-2024-8897MEDIUMCVSS 6.1EG 6.12024-09-17
Under certain conditions, an attacker with the ability to redirect users to a malicious site via an open redirect on a trusted site, may be able to spoof the address bar contents. This can lead to a malicious site to appear to have the sam…
- CVE-2024-7312MEDIUMCVSS 6.1EG 6.12024-09-11
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Payara Platform Payara Server (REST Management Interface modules) allows Session Hijacking.This issue affects Payara Server: from 6.0.0 before 6.18.0, from 6.2022.1 befor…
- CVE-2024-8646MEDIUMCVSS 6.1EG 6.12024-09-11
In Eclipse Glassfish versions prior to 7.0.10, a URL redirection vulnerability to untrusted sites existed. This vulnerability is caused by the vulnerability (CVE-2023-41080) in the Apache code included in GlassFish. This vulnerability only…
- CVE-2024-7260MEDIUMCVSS 6.1EG 6.12024-09-09
An open redirect vulnerability was found in Keycloak. A specially crafted URL can be constructed where the referrer and referrer_uri parameters are made to trick a user to visit a malicious webpage. A trusted URL can trick users and automa…
- CVE-2024-8586MEDIUMCVSS 6.1EG 6.12024-09-09
WebITR from Uniong has an Open Redirect vulnerability, which allows unauthorized remote attackers to exploit this vulnerability to forge URLs. Users, believing they are accessing a trusted domain, can be redirected to another page, potenti…
- CVE-2024-42341MEDIUMCVSS 6.1EG 6.12024-09-08
Loway - CWE-601: URL Redirection to Untrusted Site ('Open Redirect')
- CVE-2024-8386MEDIUMCVSS 6.1EG 6.12024-09-03
If a site had been granted the permission to open popup windows, it could cause Select elements to appear on top of another site to perform a spoofing attack. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, and Thunderbird <…
- CVE-2024-44776MEDIUMCVSS 6.1EG 6.12024-08-29
An Open Redirect vulnerability in the page parameter of vTiger CRM v7.4.0 allows attackers to redirect users to a malicious site via a crafted URL.
- CVE-2024-39097MEDIUMCVSS 6.1EG 6.12024-08-26
There is an Open Redirect vulnerability in Gnuboard v6.0.4 and below via the `url` parameter in login path.
- CVE-2024-43794MEDIUMCVSS 6.1EG 6.12024-08-23
OpenSearch Dashboards Security Plugin adds a configuration management UI for the OpenSearch Security features to OpenSearch Dashboards. Improper validation of the nextUrl parameter can lead to external redirect on login to OpenSearch-Dashb…
- CVE-2024-27184MEDIUMCVSS 6.1EG 6.12024-08-20
Inadequate validation of URLs could result into an invalid check whether an redirect URL is internal or not..
- CVE-2024-42353MEDIUMCVSS 6.1EG 6.12024-08-14
WebOb provides objects for HTTP requests and responses. When WebOb normalizes the HTTP Location header to include the request hostname, it does so by parsing the URL that the user is to be redirected to with Python's urlparse, and joining …
- CVE-2024-6289MEDIUMCVSS 6.1EG 6.12024-07-15
The WPS Hide Login WordPress plugin before 1.9.16.4 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated visitor to access the hidden login page.
- CVE-2024-6149MEDIUMCVSS 6.1EG 6.12024-07-10
Redirection of users to a vulnerable URL in Citrix Workspace app for HTML5
Map vulnerabilities like CWE-601 to your infrastructure
EchelonGraph correlates every CVE — across CWE-601 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →