CWE-601— URL Redirection to Untrusted Site (Open Redirect)
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.— MITRE CWE catalog
1,776 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-601page 25 of 36
- CVE-2017-14802MEDIUMCVSS 5.4EG 6.12018-03-02
Novell Access Manager Admin Console and IDP servers before 4.3.3 have a URL that could be used by remote attackers to trigger unvalidated redirects to third party sites.
- CVE-2022-37940MEDIUMCVSS 5.3EG 6.12023-03-22
Potential security vulnerabilities have been identified in the HPE FlexFabric 5700 Switch Series. These vulnerabilities could be remotely exploited to allow host header injection and URL redirection. HPE has made the following software to …
- CVE-2022-1019MEDIUMCVSS 5.2EG 6.12022-04-19
Automated Logic's WebCtrl Server Version 6.1 'Help' index pages are vulnerable to open redirection. The vulnerability allows an attacker to send a maliciously crafted URL which could result in redirecting the user to a malicious webpage or…
- CVE-2022-4317MEDIUMCVSS 5.0EG 6.12023-03-09
An issue has been discovered in GitLab DAST analyzer affecting all versions starting from 1.47 before 3.0.51, which sends custom request headers in redirects.
- CVE-2025-34440MEDIUMCVSS 4.8EG 6.12025-12-17
AVideo versions prior to 20.1 contain an open redirect vulnerability caused by insufficient validation of the siteRedirectUri parameter during user registration. Attackers can redirect users to external sites, facilitating phishing attacks.
- CVE-2025-34439MEDIUMCVSS 4.8EG 6.12025-12-17
AVideo versions prior to 20.1 are vulnerable to an open redirect flaw due to missing validation of the cancelUri parameter during user login. An attacker can craft a link to redirect users to arbitrary external sites, enabling phishing at…
- CVE-2026-41226MEDIUMCVSS 4.7EG 6.12026-04-30
Open redirect vulnerability exists in Multiple laser printers and MFPs which implement Ricoh Web Image Monitor. When accessing a specially crafted URL, the user may be redirected to an arbitrary website. As a result, the user may become a …
- CVE-2025-68602MEDIUMCVSS 4.7EG 6.12025-12-24
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Scott Paterson Accept Donations with PayPal & Stripe easy-paypal-donation allows Phishing.This issue affects Accept Donations with PayPal & Stripe: from n/a through <= 1.…
- CVE-2025-68509MEDIUMCVSS 4.7EG 6.12025-12-24
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Jeff Starr User Submitted Posts user-submitted-posts allows Phishing.This issue affects User Submitted Posts: from n/a through <= 20251121.
- CVE-2025-64250MEDIUMCVSS 4.7EG 6.12025-12-16
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in wpWax Directorist directorist allows Phishing.This issue affects Directorist: from n/a through <= 8.6.6.
- CVE-2022-3486MEDIUMCVSS 4.7EG 6.12022-11-09
An open redirect vulnerability in GitLab EE/CE affecting all versions from 9.3 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2, allows an attacker to redirect users to an arbitrary location if they trust the URL.
- CVE-2022-2250MEDIUMCVSS 4.7EG 6.12022-07-01
An open redirect vulnerability in GitLab EE/CE affecting all versions from 11.1 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows an attacker to redirect users to an arbitrary location if they trust the URL.
- CVE-2022-0283MEDIUMCVSS 4.7EG 6.12022-03-28
An issue has been discovered affecting GitLab versions prior to 13.5. An open redirect vulnerability was fixed in GitLab integration with Jira that a could cause the web application to redirect the request to the attacker specified URL.
- CVE-2021-38343MEDIUMCVSS 4.7EG 6.12021-08-30
The Nested Pages WordPress plugin <= 3.1.15 was vulnerable to an Open Redirect via the `page` POST parameter in the `npBulkActions`, `npBulkEdit`, `npListingSort`, and `npCategoryFilter` `admin_post` actions.
- CVE-2020-3558MEDIUMCVSS 4.7EG 6.12020-10-21
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. The vulnerability is due to improper inpu…
- CVE-2019-1943MEDIUMCVSS 4.7EG 6.12019-07-17
A vulnerability in the web interface of Cisco Small Business 200, 300, and 500 Series Switches software could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. The vulnerability is due to improper input …
- CVE-2015-10052MEDIUMCVSS 4.6EG 6.12023-01-15
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as problematic, was found in calesanz gibb-modul-151. This affects the function bearbeiten/login. The manipulation leads to open redirect. It is possible to initiate the…
- CVE-2022-22797MEDIUMCVSS 4.6EG 6.12022-05-12
Sysaid – sysaid Open Redirect - An Attacker can change the redirect link at the parameter "redirectURL" from"GET" request from the url location: /CommunitySSORedirect.jsp?redirectURL=https://google.com. Unvalidated redirects and forwards…
- CVE-2025-20291MEDIUMCVSS 4.3EG 6.12025-09-03
A vulnerability in Cisco Webex Meetings could have allowed an unauthenticated, remote attacker to redirect a targeted Webex Meetings user to an untrusted website. Cisco has addressed this vulnerability in the Cisco Webex Meetings service, …
- CVE-2023-0681MEDIUMCVSS 4.3EG 6.12023-03-20
Rapid7 InsightVM versions 6.6.178 and lower suffers from an open redirect vulnerability, whereby an attacker has the ability to redirect the user to a site of the attacker’s choice using the ‘page’ parameter of the ‘data/console/re…
- CVE-2022-3381MEDIUMCVSS 4.3EG 6.12023-03-09
An issue has been discovered in GitLab affecting all versions starting from 10.0 to 15.7.8, 15.8 prior to 15.8.4 and 15.9 prior to 15.9.2. A crafted URL could be used to redirect users to arbitrary sites
- CVE-2022-41273MEDIUMCVSS 4.3EG 6.12022-12-13
Due to improper input sanitization in SAP Sourcing and SAP Contract Lifecycle Management - version 1100, an attacker can redirect a user to a malicious website. In order to perform this attack, the attacker sends an email to the victim wit…
- CVE-2021-44054MEDIUMCVSS 4.3EG 6.12022-05-05
An open redirect vulnerability has been reported to affect QNAP device running QuTScloud, QuTS hero and QTS. If exploited, this vulnerability allows attackers to redirect users to an untrusted page that contains malware. We have already fi…
- CVE-2022-26326MEDIUMCVSS 4.0EG 6.12022-05-02
Potential open redirection vulnerability when URL is crafted in specific format in NetIQ Access Manager prior to 5.0.2
- CVE-2016-15030MEDIUMCVSS 3.5EG 6.12023-03-25
A vulnerability classified as problematic has been found in Arno0x TwoFactorAuth. This affects an unknown part of the file login/login.php. The manipulation of the argument from leads to open redirect. It is possible to initiate the attack…
- CVE-2022-3280MEDIUMCVSS 3.5EG 6.12022-11-09
An open redirect in GitLab CE/EE affecting all versions from 10.1 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to trick users into visiting a trustworthy URL and being redirected to arbitrary content.
- CVE-2017-20119MEDIUMCVSS 3.5EG 6.12022-06-29
A vulnerability classified as problematic has been found in TrueConf Server 4.3.7. This affects an unknown part of the file /admin/general/change-lang. The manipulation of the argument redirect_url leads to open redirect. It is possible to…
- CVE-2018-7674MEDIUMCVSS 2.1EG 6.12018-03-28
The NetIQ Identity Manager user console, in versions prior to 4.7, is susceptible to URL redirection.
- CVE-2022-23078MEDIUMEG 6.12022-06-22
In habitica versions v4.119.0 through v4.232.2 are vulnerable to open redirect via the login page.
- CVE-2026-66773MEDIUMCVSS 5.9EG 5.92026-08-11
A malicious or compromised OData service could disclose sensitive authentication information and inject untrusted data into the application, which may leads to a high impact on confidentiality and low impact on integrity and no impact on A…
- CVE-2026-55806MEDIUMCVSS 5.9EG 5.92026-07-10
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Drupal Drupal core allows Content Spoofing. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to…
- CVE-2026-10562MEDIUMCVSS 5.9EG 5.92026-06-30
An unauthenticated URL redirection vulnerability has been identified in Archer AX20 V2 due to improper validation of user-supplied URL input within the web interface. An unauthenticated attacker can craft URLs containing URL-encoded path…
- CVE-2024-8526MEDIUMCVSS 5.9EG 5.92024-11-21
A vulnerability in Automated Logic WebCTRL 7.0 could allow an attacker to send a maliciously crafted URL, which when visited by an authenticated WebCTRL user, could result in the redirection of the user to a malicious webpage via "index.js…
- CVE-2024-24818MEDIUMCVSS 5.9EG 5.92024-03-21
EspoCRM is an Open Source Customer Relationship Management software. An attacker can inject arbitrary IP or domain in "Password Change" page and redirect victim to malicious page that could lead to credential stealing or another attack. T…
- CVE-2020-5233MEDIUMCVSS 5.9EG 5.92020-01-30
OAuth2 Proxy before 5.0 has an open redirect vulnerability. Authentication tokens could be silently harvested by an attacker. This has been patched in version 5.0.
- CVE-2009-3832MEDIUMCVSS v2 5.8EG 5.82009-10-30
Opera before 10.01 on Windows does not prevent use of Web fonts in rendering the product's own user interface, which allows remote attackers to spoof the address field via a crafted web site.
- CVE-2005-0420MEDIUMCVSS v2 5.8EG 5.82005-04-27
Microsoft Outlook Web Access (OWA), when used with Exchange, allows remote attackers to redirect users to arbitrary URLs for login via a link to the owalogon.asp application.
- CVE-2026-75628MEDIUMCVSS 5.7EG 5.72026-08-20
Punk::OAuth2 versions before 0.03 for Perl allow an attacker-chosen off-site redirect after login because same_origin_path accepts a backslash or tab in the return parameter. oauth2_login reads the return parameter from the initiation req…
- CVE-2026-44520MEDIUMCVSS 5.7EG 5.72026-05-14
Docling-Graph turns documents into validated Pydantic objects, then builds a directed knowledge graph with explicit semantic relationships. Prior to 1.5.1, the URLInputHandler class in docling_graph/core/input/handlers.py makes HTTP reques…
- CVE-2022-41965MEDIUMCVSS 5.7EG 5.72022-11-28
Opencast is a free, open-source platform to support the management of educational audio and video content. Prior to Opencast 12.5, Opencast's Paella authentication page could be used to redirect to an arbitrary URL for authenticated users.…
- CVE-2022-36087MEDIUMCVSS 5.7EG 5.72022-09-09
OAuthLib is an implementation of the OAuth request-signing logic for Python 3.6+. In OAuthLib versions 3.1.1 until 3.2.1, an attacker providing malicious redirect uri can cause denial of service. An attacker can also leverage usage of `uri…
- CVE-2021-29456MEDIUMCVSS 5.7EG 5.72021-04-21
Authelia is an open-source authentication and authorization server providing 2-factor authentication and single sign-on (SSO) for your applications via a web portal. In versions 4.27.4 and earlier, utilizing a HTTP query parameter an attac…
- CVE-2021-21337MEDIUMCVSS 5.7EG 5.72021-03-08
Products.PluggableAuthService is a pluggable Zope authentication and authorization framework. In Products.PluggableAuthService before version 2.6.0 there is an open redirect vulnerability. A maliciously crafted link to the login form and l…
- CVE-2020-4048MEDIUMCVSS 5.7EG 5.72020-06-12
In affected versions of WordPress, due to an issue in wp_validate_redirect() and URL sanitization, an arbitrary external link can be crafted leading to unintended/open redirect when clicked. This has been patched in version 5.4.2, along wi…
- CVE-2025-0608MEDIUMCVSS 5.5EG 5.52025-10-06
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Logo Software Inc. Logo Cloud allows Phishing, Forceful Browsing. This issue affects Logo Cloud: before 2025.R6.
- CVE-2025-55207MEDIUMCVSS 5.5EG 5.52025-08-15
Astro is a web framework for content-driven websites. Following CVE-2025-54793 there's still an Open Redirect vulnerability in a subset of Astro deployment scenarios prior to version 9.4.1. Astro 5.12.8 addressed CVE-2025-54793 where https…
- CVE-2022-46886MEDIUMCVSS 5.5EG 5.52023-04-14
There exists an open redirect within the response list update functionality of ServiceNow. This allows attackers to redirect users to arbitrary domains when clicking on a URL within a service-now domain.
- CVE-2020-36665MEDIUMCVSS 5.5EG 5.52023-03-04
A vulnerability was found in Artesãos SEOTools up to 0.17.1 and classified as critical. This issue affects the function eachValue of the file TwitterCards.php. The manipulation of the argument value leads to open redirect. Upgrading to ve…
- CVE-2020-36664MEDIUMCVSS 5.5EG 5.52023-03-04
A vulnerability has been found in Artesãos SEOTools up to 0.17.1 and classified as problematic. This vulnerability affects the function setTitle of the file SEOMeta.php. The manipulation of the argument title leads to open redirect. Upgra…
- CVE-2020-36663MEDIUMCVSS 5.5EG 5.52023-03-04
A vulnerability, which was classified as problematic, was found in Artesãos SEOTools up to 0.17.1. This affects the function makeTag of the file OpenGraph.php. The manipulation of the argument value leads to open redirect. Upgrading to ve…
Map vulnerabilities like CWE-601 to your infrastructure
EchelonGraph correlates every CVE — across CWE-601 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →