CWE-601— URL Redirection to Untrusted Site (Open Redirect)
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.— MITRE CWE catalog
1,776 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-601page 14 of 36
- CVE-2023-47548MEDIUMCVSS 6.1EG 6.12023-12-07
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in SoftLab Integrate Google Drive – Browse, Upload, Download, Embed, Play, Share, Gallery, and Manage Your Google Drive Files Into Your WordPress Site.This issue affects I…
- CVE-2023-45762MEDIUMCVSS 6.1EG 6.12023-12-07
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Michael Uno (miunosoft) Responsive Column Widgets.This issue affects Responsive Column Widgets: from n/a through 1.2.7.
- CVE-2023-48325MEDIUMCVSS 6.1EG 6.12023-12-07
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in PluginOps Landing Page Builder – Lead Page – Optin Page – Squeeze Page – WordPress Landing Pages.This issue affects Landing Page Builder – Lead Page – Optin P…
- CVE-2023-47779MEDIUMCVSS 6.1EG 6.12023-12-07
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks. Integration for Constant Contact and Contact Form 7, WPForms, Elementor, Ninja Forms.This issue affects Integration for Constant Contact and Contact Form 7, WP…
- CVE-2023-46688MEDIUMCVSS 6.1EG 6.12023-12-06
Open redirect vulnerability in Pleasanter 1.3.47.0 and earlier allows a remote unauthenticated attacker to redirect users to arbitrary web sites via a specially crafted URL.
- CVE-2023-48815MEDIUMCVSS 6.1EG 6.12023-12-04
kkFileView v4.3.0 is vulnerable to Incorrect Access Control.
- CVE-2023-49281MEDIUMCVSS 6.1EG 6.12023-12-01
Calendarinho is an open source calendaring application to manage large teams of consultants. An Open Redirect issue occurs when a web application redirects users to external URLs without proper validation. This can lead to phishing attacks…
- CVE-2023-47168MEDIUMCVSS 6.1EG 6.12023-11-27
Mattermost fails to properly check a redirect URL parameter allowing for an open redirect was possible when the user clicked "Back to Mattermost" after providing a invalid custom url scheme in /oauth/{service}/mobile_login?redirect_to=
- CVE-2023-49061MEDIUMCVSS 6.1EG 6.12023-11-21
An attacker could have performed HTML template injection via Reader Mode and exfiltrated user information. This vulnerability affects Firefox for iOS < 120.
- CVE-2023-41699MEDIUMCVSS 6.1EG 6.12023-11-15
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Payara Platform Payara Server, Micro and Embedded (Servlet Implementation modules) allows Redirect Access to Libraries.This issue affects Payara Server, Micro and Embedde…
- CVE-2019-25155MEDIUMCVSS 6.1EG 6.12023-11-07
DOMPurify before 1.0.11 allows reverse tabnabbing in demos/hooks-target-blank-demo.html because links lack a 'rel="noopener noreferrer"' attribute.
- CVE-2023-45203MEDIUMCVSS 6.1EG 6.12023-11-01
Online Examination System v1.0 is vulnerable to multiple Open Redirect vulnerabilities. The 'q' parameter of the login.php resource allows an attacker to redirect a victim user to an arbitrary web site using a crafted URL.
- CVE-2023-45202MEDIUMCVSS 6.1EG 6.12023-11-01
Online Examination System v1.0 is vulnerable to multiple Open Redirect vulnerabilities. The 'q' parameter of the feed.php resource allows an attacker to redirect a victim user to an arbitrary web site using a crafted URL.
- CVE-2023-45201MEDIUMCVSS 6.1EG 6.12023-11-01
Online Examination System v1.0 is vulnerable to multiple Open Redirect vulnerabilities. The 'q' parameter of the admin.php resource allows an attacker to redirect a victim user to an arbitrary web site using a crafted URL.
- CVE-2023-20264MEDIUMCVSS 6.1EG 6.12023-11-01
A vulnerability in the implementation of Security Assertion Markup Language (SAML) 2.0 single sign-on (SSO) for remote access VPN in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could a…
- CVE-2023-36085MEDIUMCVSS 6.1EG 6.12023-10-25
The sisqualWFM 7.1.319.103 thru 7.1.319.111 for Android, has a host header injection vulnerability in its "/sisqualIdentityServer/core/" endpoint. By modifying the HTTP Host header, an attacker can change webpage links and even redirect us…
- CVE-2021-46898MEDIUMCVSS 6.1EG 6.12023-10-22
views/switch.py in django-grappelli (aka Django Grappelli) before 2.15.2 attempts to prevent external redirection with startswith("/") but this does not consider a protocol-relative URL (e.g., //example.com) attack.
- CVE-2023-45909MEDIUMCVSS 6.1EG 6.12023-10-18
zzzcms v2.2.0 was discovered to contain an open redirect vulnerability.
- CVE-2018-25091MEDIUMCVSS 6.1EG 6.12023-10-15
urllib3 before 1.24.2 does not remove the authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the authorization header to be exposed t…
- CVE-2023-40779MEDIUMCVSS 6.1EG 6.12023-09-14
An issue in IceWarp Mail Server Deep Castle 2 v.13.0.1.2 allows a remote attacker to execute arbitrary code via a crafted request to the URL.
- CVE-2023-41609MEDIUMCVSS 6.1EG 6.12023-09-11
An open redirect vulnerability in the sanitize_url() parameter of CouchCMS v2.3 allows attackers to redirect a victim user to an arbitrary web site via a crafted URL.
- CVE-2023-40306MEDIUMCVSS 6.1EG 6.12023-09-08
SAP S/4HANA Manage Catalog Items and Cross-Catalog searches Fiori apps allow an attacker to redirect users to a malicious site due to insufficient URL validation. As a result, it may have a slight impact on confidentiality and integrity.
- CVE-2023-38574MEDIUMCVSS 6.1EG 6.12023-09-05
Open redirect vulnerability in VI Web Client prior to 7.9.6 allows a remote unauthenticated attacker to redirect users to arbitrary web sites and conduct phishing attacks via a specially crafted URL.
- CVE-2023-41080MEDIUMCVSS 6.1EG 6.12023-08-25
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Tomcat.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.0.12, from 9.0.0-M1 through 9.0.7…
- CVE-2022-45582MEDIUMCVSS 6.1EG 6.12023-08-22
Open Redirect vulnerability in Horizon Web Dashboard 19.4.0 thru 20.1.4 via the success_url parameter.
- CVE-2022-44215MEDIUMCVSS 6.1EG 6.12023-08-22
There is an open redirect vulnerability in Titan FTP server 19.0 and below. Users are redirected to any target URL.
- CVE-2023-38998MEDIUMCVSS 6.1EG 6.12023-08-09
An open redirect in the Login page of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to redirect a victim user to an arbitrary web site via a crafted URL.
- CVE-2023-34917MEDIUMCVSS 6.1EG 6.12023-07-31
Fuge CMS v1.0 contains an Open Redirect vulnerability in member/RegisterAct.java.
- CVE-2023-34916MEDIUMCVSS 6.1EG 6.12023-07-31
Fuge CMS v1.0 contains an Open Redirect vulnerability via /front/ProcessAct.java.
- CVE-2023-35791MEDIUMCVSS 6.1EG 6.12023-07-31
Vound Intella Connect 2.6.0.3 has an Open Redirect vulnerability.
- CVE-2021-36580MEDIUMCVSS 6.1EG 6.12023-07-27
Open Redirect vulnerability exists in IceWarp MailServer IceWarp Server Deep Castle 2 Update 1 (13.0.1.2) via the referer parameter.
- CVE-2023-37624MEDIUMCVSS 6.1EG 6.12023-07-26
Netdisco before v2.063000 was discovered to contain an open redirect vulnerability. An attacker may exploit this vulnerability to redirect users to arbitrary web URLs by tricking the victim users to click on crafted links.
- CVE-2021-39425MEDIUMCVSS 6.1EG 6.12023-07-20
SeedDMS v6.0.15 was discovered to contain an open redirect vulnerability. An attacker may exploit this vulnerability to redirect users to arbitrary web URLs by tricking the victim users to click on crafted links.
- CVE-2023-37561MEDIUMCVSS 6.1EG 6.12023-07-13
Open redirect vulnerability in ELECOM wireless LAN routers and ELECOM wireless LAN repeaters allows a remote unauthenticated attacker to redirect users to arbitrary web sites and conduct phishing attacks via a specially crafted URL. Affect…
- CVE-2023-37947MEDIUMCVSS 6.1EG 6.12023-07-12
Jenkins OpenShift Login Plugin 1.1.0.227.v27e08dfb_1a_20 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins, allowing attackers to perform phishing attacks.
- CVE-2023-35934MEDIUMCVSS 6.1EG 6.12023-07-06
yt-dlp is a command-line program to download videos from video sites. During file downloads, yt-dlp or the external downloaders that yt-dlp employs may leak cookies on HTTP redirects to a different host, or leak them when the host for down…
- CVE-2023-3139MEDIUMCVSS 6.1EG 6.12023-07-04
The Protect WP Admin WordPress plugin before 4.0 discloses the URL of the admin panel via a redirection of a crafted URL, bypassing the protection offered.
- CVE-2023-28364MEDIUMCVSS 6.1EG 6.12023-07-01
An Open Redirect vulnerability exists prior to version 1.52.117, where the built-in QR scanner in Brave Browser Android navigated to scanned URLs automatically without showing the URL first. Now the user must manually navigate to the URL.
- CVE-2023-34415MEDIUMCVSS 6.1EG 6.12023-06-19
When choosing a site-isolated process for a document loaded from a data: URL that was the result of a redirect, Firefox would load that document in the same process as the site that issued the redirect. This bypassed the site-isolation pro…
- CVE-2023-24030MEDIUMCVSS 6.1EG 6.12023-06-15
An open redirect vulnerability exists in the /preauth Servlet in Zimbra Collaboration Suite through 9.0 and 8.8.15. To exploit the vulnerability, an attacker would need to have obtained a valid zimbra auth token or a valid preauth token. O…
- CVE-2023-35029MEDIUMCVSS 6.1EG 6.12023-06-15
Open redirect vulnerability in the Layout module's SEO configuration in Liferay Portal 7.4.3.70 through 7.4.3.76, and Liferay DXP 7.4 update 70 through 76 allows remote attackers to redirect users to arbitrary external URLs via the `_com_l…
- CVE-2023-34247MEDIUMCVSS 6.1EG 6.12023-06-13
Keystone is a content management system for Node.JS. There is an open redirect in the `@keystone-6/auth` package versions 7.0.0 and prior, where the redirect leading `/` filter can be bypassed. Users may be redirected to domains other than…
- CVE-2023-32551MEDIUMCVSS 6.1EG 6.12023-06-06
Landscape allowed URLs which caused open redirection.
- CVE-2023-29540MEDIUMCVSS 6.1EG 6.12023-06-02
Using a redirect embedded into <code>sourceMappingUrls</code> could allow for navigation to external protocol links in sandboxed iframes without <code>allow-top-navigation-to-custom-protocols</code>. This vulnerability affects Firefox for …
- CVE-2023-32218MEDIUMCVSS 6.1EG 6.12023-05-30
Avaya IX Workforce Engagement v15.2.7.1195 - CWE-601: URL Redirection to Untrusted Site ('Open Redirect')
- CVE-2023-23754MEDIUMCVSS 6.1EG 6.12023-05-30
An issue was discovered in Joomla! 4.2.0 through 4.3.1. Lack of input validation caused an open redirect and XSS issue within the new mfa selection screen.
- CVE-2023-20884MEDIUMCVSS 6.1EG 6.12023-05-30
VMware Workspace ONE Access and VMware Identity Manager contain an insecure redirect vulnerability. An unauthenticated malicious actor may be able to redirect a victim to an attacker controlled domain due to improper path handling leading…
- CVE-2023-28370MEDIUMCVSS 6.1EG 6.12023-05-25
Open redirect vulnerability in Tornado versions 6.3.1 and earlier allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having user access a specially crafted URL.
- CVE-2023-25829MEDIUMCVSS 6.1EG 6.12023-05-09
There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.0 and below that may allow a remote, unauthenticated attacker to craft a URL that could redirect a victim to an arbitrary website, simplifying phishing attacks.
- CVE-2020-21038MEDIUMCVSS 6.1EG 6.12023-05-08
Open redirect vulnerability in typecho 1.1-17.10.30-release via the referer parameter to Login.php.
Map vulnerabilities like CWE-601 to your infrastructure
EchelonGraph correlates every CVE — across CWE-601 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →