CWE-601— URL Redirection to Untrusted Site (Open Redirect)
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.— MITRE CWE catalog
1,776 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-601page 13 of 36
- CVE-2024-5492MEDIUMCVSS 6.1EG 6.12024-07-10
Open redirect vulnerability allows a remote unauthenticated attacker to redirect users to arbitrary websites in NetScaler ADC and NetScaler Gateway
- CVE-2024-37830MEDIUMCVSS 6.1EG 6.12024-07-09
An issue in Outline <= v0.76.1 allows attackers to redirect a victim user to a malicious site via intercepting and changing the state cookie.
- CVE-2024-5936MEDIUMCVSS 6.1EG 6.12024-06-27
An open redirect vulnerability exists in imartinez/privategpt version 0.5.0 due to improper handling of the 'file' parameter. This vulnerability allows attackers to redirect users to a URL specified by user-controlled input without proper …
- CVE-2024-4704MEDIUMCVSS 6.1EG 6.12024-06-27
The Contact Form 7 WordPress plugin before 5.9.5 has an open redirect that allows an attacker to utilize a false URL and redirect to the URL of their choosing.
- CVE-2024-4604MEDIUMCVSS 6.1EG 6.12024-06-26
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Magarsus Consultancy SSO (Single Sign On) allows Manipulating Hidden Fields. This issue affects SSO (Single Sign On): from 1.0 before 1.1.
- CVE-2024-4900MEDIUMCVSS 6.1EG 6.12024-06-24
The SEOPress WordPress plugin before 7.8 does not validate and escape one of its Post settings, which could allow contributor and above role to perform Open redirect attacks against any user viewing a malicious post
- CVE-2024-4940MEDIUMCVSS 6.1EG 6.12024-06-22
An open redirect vulnerability exists in the gradio-app/gradio, affecting the latest version. The vulnerability allows an attacker to redirect users to arbitrary websites, which can be exploited for phishing attacks, Cross-site Scripting (…
- CVE-2024-23442MEDIUMCVSS 6.1EG 6.12024-06-14
An open redirect issue was discovered in Kibana that could lead to a user being redirected to an arbitrary website if they use a maliciously crafted Kibana URL.
- CVE-2024-3032MEDIUMCVSS 6.1EG 6.12024-06-13
Themify Builder WordPress plugin before 7.5.8 does not validate a parameter before redirecting the user to its value, leading to an Open Redirect issue
- CVE-2024-23664MEDIUMCVSS 6.1EG 6.12024-06-03
A URL redirection to untrusted site ('open redirect') in Fortinet FortiAuthenticator version 6.6.0, version 6.5.3 and below, version 6.4.9 and below may allow an attacker to to redirect users to an arbitrary website via a crafted URL.
- CVE-2024-34071MEDIUMCVSS 6.1EG 6.12024-05-21
Umbraco is an ASP.NET CMS used by more than 730.000 websites. Umbraco has an endpoint that is vulnerable to open redirects. The endpoint is protected so it requires the user to be signed into backoffice before the vulnerable is exposed. Th…
- CVE-2024-34074MEDIUMCVSS 6.1EG 6.12024-05-14
Frappe is a full-stack web application framework. Prior to 15.26.0 and 14.74.0, the login page accepts redirect argument and it allowed redirect to untrusted external URls. This behaviour can be used by malicious actors for phishing. This …
- CVE-2024-4133MEDIUMCVSS 6.1EG 6.12024-05-02
The ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 4.0.30. This is due to insufficient validation on …
- CVE-2024-21065MEDIUMCVSS 6.1EG 6.12024-04-16
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Workflow). Supported versions that are affected are 8.59, 8.60 and 8.61. Easily exploitable vulnerability allows unauthenticated attacker wit…
- CVE-2024-31135MEDIUMCVSS 6.1EG 6.12024-03-28
In JetBrains TeamCity before 2024.03 open redirect was possible on the login page
- CVE-2024-29041MEDIUMCVSS 6.1EG 6.12024-03-25
Express.js minimalist web framework for node. Versions of Express.js prior to 4.19.0 and all pre-release alpha and beta versions of 5.0 are affected by an open redirect vulnerability using malformed URLs. When a user of Express performs a …
- CVE-2024-27291MEDIUMCVSS 6.1EG 6.12024-03-21
Docassemble is an expert system for guided interviews and document assembly. Prior to 1.4.97, it is possible to create a URL that acts as an open redirect. The vulnerability has been patched in version 1.4.97 of the master branch.
- CVE-2024-0337MEDIUMCVSS 6.1EG 6.12024-03-20
The Travelpayouts: All Travel Brands in One Place WordPress plugin through 1.1.15 is vulnerable to Open Redirect due to insufficient validation on the travelpayouts_redirect variable. This makes it possible for unauthenticated attackers to…
- CVE-2024-25609MEDIUMCVSS 6.1EG 6.12024-02-20
HtmlUtil.escapeRedirect in Liferay Portal 7.2.0 through 7.4.3.12, and older unsupported versions, and Liferay DXP 7.4 before update 9, 7.3 service pack 3, 7.2 fix pack 15 through 18, and older unsupported versions can be circumvented by us…
- CVE-2024-25608MEDIUMCVSS 6.1EG 6.12024-02-20
HtmlUtil.escapeRedirect in Liferay Portal 7.2.0 through 7.4.3.18, and older unsupported versions, and Liferay DXP 7.4 before update 19, 7.3 before update 4, 7.2 before fix pack 19, and older unsupported versions can be circumvented by usin…
- CVE-2023-44308MEDIUMCVSS 6.1EG 6.12024-02-20
Open redirect vulnerability in adaptive media administration page in Liferay DXP 2023.Q3 before patch 6, and 7.4 GA through update 92 allows remote attackers to redirect users to arbitrary external URLs via the _com_liferay_adaptive_media_…
- CVE-2023-5190MEDIUMCVSS 6.1EG 6.12024-02-20
Open redirect vulnerability in the Countries Management’s edit region page in Liferay Portal 7.4.3.45 through 7.4.3.101, and Liferay DXP 2023.Q3 before patch 6, and 7.4 update 45 through 92 allows remote attackers to redirect users to ar…
- CVE-2024-22854MEDIUMCVSS 6.1EG 6.12024-02-16
DOM-based HTML injection vulnerability in the main page of Darktrace Threat Visualizer version 6.1.27 (bundle version 61050) and before has been identified. A URL, crafted by a remote attacker and visited by an authenticated user, allows o…
- CVE-2024-21728MEDIUMCVSS 6.1EG 6.12024-02-15
An Open Redirect vulnerability was found in osTicky2 below 2.2.8. osTicky (osTicket Bridge) by SmartCalc is a Joomla 3.x extension that provides Joomla fronted integration with osTicket, a popular Support ticket system. The Open Redirect v…
- CVE-2024-0250MEDIUMCVSS 6.1EG 6.12024-02-12
The Analytics Insights for Google Analytics 4 (AIWP) WordPress plugin before 6.3 is vulnerable to Open Redirect due to insufficient validation on the redirect oauth2callback.php file. This makes it possible for unauthenticated attackers to…
- CVE-2024-25715MEDIUMCVSS 6.1EG 6.12024-02-11
Glewlwyd SSO server 2.x through 2.7.6 allows open redirection via redirect_uri.
- CVE-2024-24034MEDIUMCVSS 6.1EG 6.12024-02-08
Setor Informatica S.I.L version 3.0 is vulnerable to Open Redirect via the hprinter parameter, allows remote attackers to execute arbitrary code.
- CVE-2024-24291MEDIUMCVSS 6.1EG 6.12024-02-06
An issue in the component /member/index/login of yzmcms v7.0 allows attackers to direct users to malicious sites via a crafted URL.
- CVE-2024-0953MEDIUMCVSS 6.1EG 6.12024-02-05
When a user scans a QR Code with the QR Code Scanner feature, the user is not prompted before being navigated to the page specified in the code. This may surprise the user and potentially direct them to unwanted content. This vulnerabilit…
- CVE-2023-6389MEDIUMCVSS 6.1EG 6.12024-01-29
The WordPress Toolbar WordPress plugin through 2.2.6 redirects to any URL via the "wptbto" parameter. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them…
- CVE-2024-22113MEDIUMCVSS 6.1EG 6.12024-01-22
Open redirect vulnerability in Access analysis CGI An-Analyzer released in 2023 December 31 and earlier allows a remote unauthenticated attacker to redirect users to arbitrary websites and conduct phishing attacks via a specially crafted U…
- CVE-2023-3771MEDIUMCVSS 6.1EG 6.12024-01-16
The T1 WordPress theme through 19.0 is vulnerable to unauthenticated open redirect with which any attacker and redirect users to arbitrary websites.
- CVE-2023-49394MEDIUMCVSS 6.1EG 6.12024-01-10
Zentao versions 4.1.3 and before has a URL redirect vulnerability, which prevents the system from functioning properly.
- CVE-2023-6552MEDIUMCVSS 6.1EG 6.12024-01-08
Lack of "current" GET parameter validation during the action of changing a language leads to an open redirect vulnerability.
- CVE-2023-50345MEDIUMCVSS 6.1EG 6.12024-01-03
HCL DRYiCE MyXalytics is impacted by an Open Redirect vulnerability which could allow an attacker to redirect users to malicious sites, potentially leading to phishing attacks or other security threats.
- CVE-2023-52263MEDIUMCVSS 6.1EG 6.12023-12-30
Brave Browser before 1.59.40 does not properly restrict the schema for WebUI factory and redirect. This is related to browser/brave_content_browser_client.cc and browser/ui/webui/brave_web_ui_controller_factory.cc.
- CVE-2023-49438MEDIUMCVSS 6.1EG 6.12023-12-26
An open redirect vulnerability in the python package Flask-Security-Too <=5.3.2 allows attackers to redirect unsuspecting users to malicious sites via a crafted URL by abusing the ?next parameter on the /login and /register routes.
- CVE-2023-48003MEDIUMCVSS 6.1EG 6.12023-12-26
An open redirect through HTML injection in user messages in Asp.Net Zero before 12.3.0 allows remote attackers to redirect targeted victims to any URL via the '<meta http-equiv="refresh"' in the WebSocket messages.
- CVE-2023-50297MEDIUMCVSS 6.1EG 6.12023-12-26
Open redirect vulnerability in PowerCMS (6 Series, 5 Series, and 4 Series) allows a remote unauthenticated attacker to redirect users to arbitrary web sites via a specially crafted URL. Note that all versions of PowerCMS 3 Series and earli…
- CVE-2023-50704MEDIUMCVSS 6.1EG 6.12023-12-20
An attacker could construct a URL within the application that causes a redirection to an arbitrary external domain and could be leveraged to facilitate phishing attacks against application users.
- CVE-2023-46624MEDIUMCVSS 6.1EG 6.12023-12-19
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Parcel Pro.This issue affects Parcel Pro: from n/a through 1.6.11.
- CVE-2023-45105MEDIUMCVSS 6.1EG 6.12023-12-19
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in SERVIT Software Solutions affiliate-toolkit – WordPress Affiliate Plugin.This issue affects affiliate-toolkit – WordPress Affiliate Plugin: from n/a through 3.3.9.
- CVE-2023-41648MEDIUMCVSS 6.1EG 6.12023-12-19
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Swapnil V. Patil Login and Logout Redirect.This issue affects Login and Logout Redirect: from n/a through 2.0.3.
- CVE-2023-6927MEDIUMCVSS 6.1EG 6.12023-12-18
A flaw was found in Keycloak. This issue may allow an attacker to steal authorization codes or tokens from clients using a wildcard in the JARM response mode "form_post.jwt" which could be used to bypass the security patch implemented to a…
- CVE-2020-17484MEDIUMCVSS 6.1EG 6.12023-12-16
An Open Redirection vulnerability exists in Uffizio's GPS Tracker all versions allows an attacker to construct a URL within the application that causes a redirection to an arbitrary external domain.
- CVE-2023-46750MEDIUMCVSS 6.1EG 6.12023-12-14
URL Redirection to Untrusted Site ('Open Redirect') vulnerability when "form" authentication is used in Apache Shiro. Mitigation: Update to Apache Shiro 1.13.0+ or 2.0.0-alpha-4+.
- CVE-2023-50771MEDIUMCVSS 6.1EG 6.12023-12-13
Jenkins OpenId Connect Authentication Plugin 2.6 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins, allowing attackers to perform phishing attacks.
- CVE-2023-6380MEDIUMCVSS 6.1EG 6.12023-12-13
Open redirect vulnerability has been found in the Open CMS product affecting versions 14 and 15 of the 'Mercury' template. An attacker could create a specially crafted URL and send it to a specific user to redirect them to a malicious site…
- CVE-2023-28874MEDIUMCVSS 6.1EG 6.12023-12-09
The next parameter in the /accounts/login endpoint of Seafile 9.0.6 allows attackers to redirect users to arbitrary sites.
- CVE-2023-48928MEDIUMCVSS 6.1EG 6.12023-12-08
Franklin Fueling Systems System Sentinel AnyWare (SSA) version 1.6.24.492 is vulnerable to Open Redirect. The 'path' parameter of the prefs.asp resource allows an attacker to redirect a victim user to an arbitrary web site using a crafted …
Map vulnerabilities like CWE-601 to your infrastructure
EchelonGraph correlates every CVE — across CWE-601 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →