CWE-601— URL Redirection to Untrusted Site (Open Redirect)
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.— MITRE CWE catalog
1,776 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-601page 28 of 36
- CVE-2021-1218MEDIUMCVSS 5.4EG 5.42021-01-20
A vulnerability in the web management interface of Cisco Smart Software Manager satellite could allow an authenticated, remote attacker to redirect a user to an undesired web page. The vulnerability is due to improper input validation of t…
- CVE-2020-6266MEDIUMCVSS 5.4EG 5.42020-06-10
SAP Fiori for SAP S/4HANA, versions - 100, 200, 300, 400, allows an attacker to redirect users to a malicious site due to insufficient URL validation, leading to URL Redirection.
- CVE-2020-9517MEDIUMCVSS 5.4EG 5.42020-03-09
There is an improper restriction of rendered UI layers or frames vulnerability in Micro Focus Service Manager Release Control versions 9.50 and 9.60. The vulnerability may result in the ability of malicious users to perform UI redress atta…
- CVE-2020-6803MEDIUMCVSS 5.4EG 5.42020-02-28
An open redirect is present on the gateway's login page, which could cause a user to be redirected to a malicious site after logging in.
- CVE-2019-17151MEDIUMCVSS 5.4EG 5.42020-01-07
This vulnerability allows remote attackers redirect users to an external resource on affected installations of Tencent WeChat Prior to 7.0.9. User interaction is required to exploit this vulnerability in that the target must be within a ch…
- CVE-2010-3669MEDIUMCVSS 5.4EG 5.42019-11-04
TYPO3 before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows XSS and Open Redirection in the frontend login box.
- CVE-2019-5823MEDIUMCVSS 5.4EG 5.42019-06-27
Insufficient policy enforcement in service workers in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
- CVE-2019-11269MEDIUMCVSS 5.4EG 5.42019-06-12
Spring Security OAuth versions 2.3 prior to 2.3.6, 2.2 prior to 2.2.5, 2.1 prior to 2.1.5, and 2.0 prior to 2.0.18, as well as older unsupported versions could be susceptible to an open redirector attack that can leak an authorization code…
- CVE-2017-5871MEDIUMCVSS 5.4EG 5.42019-05-22
Odoo Version <= 8.0-20160726 and Version 9 is affected by: CWE-601: Open redirection. The impact is: obtain sensitive information (remote).
- CVE-2019-5433MEDIUMCVSS 5.4EG 5.42019-05-06
A user having access to the UI of a Revive Adserver instance could be tricked into clicking on a specifically crafted admin account-switch.php URL that would eventually lead them to another (unsafe) domain, potentially used for stealing cr…
- CVE-2019-4035MEDIUMCVSS 5.4EG 5.42019-03-22
IBM Content Navigator 3.0CD could allow attackers to direct web traffic to a malicious site. If attackers make a fake IBM Content Navigator site, they can send a link to ICN users to send request to their Edit client directly. Then Edit cl…
- CVE-2018-15403MEDIUMCVSS 5.4EG 5.42018-10-05
A vulnerability in the web interface of Cisco Emergency Responder, Cisco Unified Communications Manager, Cisco Unified Communications Manager IM & Presence Service, and Cisco Unity Connection could allow an authenticated, remote attacker t…
- CVE-2016-0329MEDIUMCVSS 5.4EG 5.42018-02-02
Open redirect vulnerability in IBM Emptoris Sourcing 10.0.0.x before 10.0.0.1_iFix3, 10.0.1.x before 10.0.1.3_iFix3, 10.0.2.x before 10.0.2.8_iFix1, 10.0.4.0 before 10.0.4.0_iFix8, and 10.1.0.0 before 10.1.0.0_iFix3 allows remote attackers…
- CVE-2017-14725MEDIUMCVSS 5.4EG 5.42017-09-23
Before version 4.8.2, WordPress was susceptible to an open redirect attack in wp-admin/edit-tag-form.php and wp-admin/user-edit.php.
- CVE-2017-1449MEDIUMCVSS 5.4EG 5.42017-08-31
IBM Emptoris Sourcing 9.5 - 10.1.3 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability t…
- CVE-2017-1448MEDIUMCVSS 5.4EG 5.42017-08-09
IBM Emptoris Supplier Lifecycle Management 10.0.x and 10.1.x could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could ex…
- CVE-2016-8949MEDIUMCVSS 5.4EG 5.42017-08-09
IBM Emptoris Supplier Lifecycle Management 10.0.x and 10.1.x could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could ex…
- CVE-2017-11725MEDIUMCVSS 5.4EG 5.42017-07-29
The share function in Thycotic Secret Server before 10.2.000019 mishandles the Back Button, leading to unintended redirections.
- CVE-2017-1287MEDIUMCVSS 5.4EG 5.42017-07-24
IBM Rhapsody DM 5.0 and 6.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof…
- CVE-2016-8953MEDIUMCVSS 5.4EG 5.42017-07-12
IBM Emptoris Sourcing 9.5.x through 10.1.x could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnera…
- CVE-2017-1159MEDIUMCVSS 5.4EG 5.42017-05-22
IBM Business Process Manager 8.0 and 8.5 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerabi…
- CVE-2017-3528MEDIUMCVSS 5.4EG 5.42017-04-24
Vulnerability in the Oracle Applications Framework component of Oracle E-Business Suite (subcomponent: Popup windows (lists of values, datepicker, etc.)). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. …
- CVE-2016-0228MEDIUMCVSS 5.4EG 5.42017-04-17
IBM Marketing Platform 10.0 could allow a remote attacker to conduct phishing attacks, caused by an open redirect vulnerability in various scripts. An attacker could exploit this vulnerability to redirect a victim to arbitrary Web sites. I…
- CVE-2017-3810MEDIUMCVSS 5.4EG 5.42017-02-03
A vulnerability in the web framework of Cisco Prime Service Catalog could allow an authenticated, remote attacker to conduct a web URL redirect attack against a user who is logged in to an affected system. More Information: CSCvb21745. Kno…
- CVE-2017-3799MEDIUMCVSS 5.4EG 5.42017-01-26
A vulnerability in a URL parameter of Cisco WebEx Meeting Center could allow an unauthenticated, remote attacker to perform site redirection. More Information: CSCzu78401. Known Affected Releases: T28.1.
- CVE-2016-4604MEDIUMCVSS 5.4EG 5.42016-07-22
Safari in Apple iOS before 9.3.3 allows remote attackers to spoof the displayed URL via an HTTP response specifying redirection to an invalid TCP port number.
- CVE-2022-1209MEDIUMCVSS 4.3EG 5.42022-05-10
The Ultimate Member plugin for WordPress is vulnerable to arbitrary redirects due to insufficient validation on supplied URLs in the social fields of the Profile Page, which makes it possible for attackers to redirect unsuspecting victims …
- CVE-2023-22641MEDIUMCVSS 4.1EG 5.42023-04-11
A url redirection to untrusted site ('open redirect') in Fortinet FortiOS version 7.2.0 through 7.2.3, FortiOS version 7.0.0 through 7.0.9, FortiOS versions 6.4.0 through 6.4.12, FortiOS all versions 6.2, FortiOS all versions 6.0, FortiPro…
- CVE-2026-102778MEDIUMCVSS 5.3EG 5.32026-10-05
Joomla Extension - svenbluege.de - Cross-site scripting and open redirect on the share mini page in Event Gallery extension < 6.6.0 - The page a shared image link opens (the share mini page of the front end) can link the article the image …
- CVE-2026-97165MEDIUMCVSS 5.3EG 5.32026-09-27
Joomla Extension - svenbluege.de - Reflected XSS and open redirect in Event Gallery extension < 6.5.0 - The “return” parameter is base64-decoded and written to the “Back” link without being validated.
- CVE-2026-86823MEDIUMCVSS 5.3EG 5.32026-09-16
The Newsletter WordPress plugin before 9.3.7 does not validate the destination of the redirect performed after a public subscription action, allowing unauthenticated attackers to redirect users to arbitrary external sites and to disclose …
- CVE-2026-78079MEDIUMCVSS 5.3EG 5.32026-08-31
Joomla Extension - joomshaper.com - Open Redirect via Base64 Return Parameter in Helix Ultimate < 2.2.10 - Return redirect parameters accepted arbitrary Base64 strings without verifying whether the resolved target was an internal site URL …
- CVE-2026-40465MEDIUMCVSS 5.3EG 5.32026-08-31
NSP is vulnerable to an open redirect due to insufficient server-side validation of the URL (or redirect) parameter.
- CVE-2026-77028MEDIUMCVSS 5.3EG 5.32026-08-21
Joomla Extension - yootheme.com - Reflected XSS and open redirect via the submission redirect parameter in Zoo < 4.1.66
- CVE-2026-53654MEDIUMCVSS 5.3EG 5.32026-08-19
Grav is a file-based Web platform. Prior to 3.8.5, the Login plugin twofa_cancel task accepts a client-controlled _redirect field without a nonce and allows an unauthenticated request to set an external http, https, or protocol-relative Lo…
- CVE-2026-54215MEDIUMCVSS 5.3EG 5.32026-08-07
Tobit Laboratories AG TeamDavid's Webbox contains an open redirect vulnerability via the “replyUrl” parameter. An attacker can exploit this vulnerability to craft a URL within the application that, when visited, redirects the user�…
- CVE-2026-54214MEDIUMCVSS 5.3EG 5.32026-08-07
Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to HTTP header injection through the “cType” URL parameter, which allows arbitrary modification of the Content-Type header in HTTP responses. Because the parameter do…
- CVE-2026-12071MEDIUMCVSS 5.3EG 5.32026-08-07
The Webbox of TeamDavid by Tobit Laboratories AG constructs redirect URLs using user-supplied input, which is appended to the redirect target in a 302 HTTP response. By using URL-encoded characters such as “%2e” (representing a dot…
- CVE-2026-62517MEDIUMCVSS 5.3EG 5.32026-07-21
Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated atta…
- CVE-2026-13163MEDIUMCVSS 5.3EG 5.32026-06-24
Open redirect vulnerability (CWE-601) in the _safe_redirect function of the click-tracking endpoint (/c/<token>/) in Mailerup <1.0.0 on all platforms allows remote unauthenticated attackers to redirect victims to arbitrary external sites …
- CVE-2026-47347MEDIUMCVSS 5.3EG 5.32026-06-09
Applications that use GeneralUtility::sanitizeLocalUrl to allow only local URLs are vulnerable to open redirect attacks if the URL is used after it has passed the aforementioned sanitization checks. This enables attackers to redirect users…
- CVE-2026-3318MEDIUMCVSS 5.3EG 5.32026-05-08
Open redirection vulnerability in the latest demo version of the Cradle eCommerce platform. The vulnerability occurs in the login form endpoint, where the ‘returnUrl’ parameter allows redirection because the web application accepts a U…
- CVE-2026-40332MEDIUMCVSS 5.3EG 5.32026-05-06
Masa CMS is affected by an Open Redirect vulnerability due to improper handling of scheme-relative URLs. The application incorrectly interprets paths beginning with double slashes (//) as internal paths, failing to validate the redirect ta…
- CVE-2026-39940MEDIUMCVSS 5.3EG 5.32026-04-13
ChurchCRM is an open-source church management system. Prior to 7.0.0, it was possible in many places across the ChurchCRM application to create a link that, when visited by an authenticated user, would redirect them to any URL chosen by an…
- CVE-2026-22560MEDIUMCVSS 5.3EG 5.32026-04-10
An open redirect vulnerability in Rocket.Chat versions prior to 8.4.0 allows users to be redirected to arbitrary URLs by manipulating parameters within a SAML endpoint.
- CVE-2025-14524MEDIUMCVSS 5.3EG 5.32026-01-08
When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a cross-protocol redirect to a second URL that uses an IMAP, LDAP, POP3 or SMTP scheme, curl might wrongly pass on the bearer token to the new target h…
- CVE-2025-65581MEDIUMCVSS 5.3EG 5.32025-12-16
An open redirect vulnerability exists in the Account module in Volosoft ABP Framework >= 5.1.0 and < 10.0.0-rc.2. Improper validation of the returnUrl parameter in the register function allows an attacker to redirect users to arbitrary ext…
- CVE-2025-55624MEDIUMCVSS 5.3EG 5.32025-08-22
An intent redirection vulnerability in Reolink v4.54.0.4.20250526 allows unauthorized attackers to access internal functions or access non-public components.
- CVE-2025-50182MEDIUMCVSS 5.3EG 5.32025-06-19
urllib3 is a user-friendly HTTP client library for Python. Starting in version 2.2.0 and prior to 2.5.0, urllib3 does not control redirects in browsers and Node.js. urllib3 supports being used in a Pyodide runtime utilizing the JavaScript …
- CVE-2025-50181MEDIUMCVSS 5.3EG 5.32025-06-19
urllib3 is a user-friendly HTTP client library for Python. Prior to 2.5.0, it is possible to disable redirects for all requests by instantiating a PoolManager and specifying retries in a way that disable redirects. By default, requests and…
Map vulnerabilities like CWE-601 to your infrastructure
EchelonGraph correlates every CVE — across CWE-601 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →