CWE-601— URL Redirection to Untrusted Site (Open Redirect)
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.— MITRE CWE catalog
1,776 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-601page 29 of 36
- CVE-2020-36845MEDIUMCVSS 5.3EG 5.32025-04-20
The KnowBe4 Security Awareness Training application before 2020-01-10 contains a redirect function that does not validate the destination URL before redirecting. The response has a SCRIPT element that sets window.location.href to an arbitr…
- CVE-2025-0244MEDIUMCVSS 5.3EG 5.32025-01-07
When redirecting to an invalid protocol scheme, an attacker could spoof the address bar. *Note: This issue only affected Android operating systems. Other operating systems are unaffected.*. This vulnerability was fixed in Firefox 134.
- CVE-2024-4882MEDIUMCVSS 5.3EG 5.32024-07-08
The user may be redirected to an arbitrary site in Sitefinity 15.1.8321.0 and previous versions.
- CVE-2024-37881MEDIUMCVSS 5.3EG 5.32024-06-19
SiteGuard WP Plugin provides a functionality to customize the path to the login page wp-login.php and implements a measure to avoid redirection from other URLs. However, SiteGuard WP Plugin versions prior to 1.7.7 missed to implement a mea…
- CVE-2024-0545MEDIUMCVSS 5.3EG 5.32024-01-15
A vulnerability classified as problematic was found in CodeCanyon RISE Ultimate Project Manager 3.5.3. This vulnerability affects unknown code of the file /index.php/signin. The manipulation of the argument redirect with the input http://e…
- CVE-2023-50456MEDIUMCVSS 5.3EG 5.32023-12-10
An issue was discovered in Zammad before 6.2.0. An attacker can trigger phishing links in generated notification emails via a crafted first or last name.
- CVE-2022-44560MEDIUMCVSS 5.3EG 5.32022-11-09
The launcher module has an Intent redirection vulnerability. Successful exploitation of this vulnerability may cause launcher module data to be modified.
- CVE-2022-33712MEDIUMCVSS 5.3EG 5.32022-07-12
Intent redirection vulnerability using implict intent in Camera prior to versions 12.0.01.64 ,12.0.3.23, 12.0.0.98, 12.0.6.11, 12.0.3.19 in Android S(12) allows attacker to get sensitive information.
- CVE-2021-3664MEDIUMCVSS 5.3EG 5.32021-07-26
url-parse is vulnerable to URL Redirection to Untrusted Site
- CVE-2020-10775MEDIUMCVSS 5.3EG 5.32020-08-24
An Open redirect vulnerability was found in ovirt-engine versions 4.4 and earlier, where it allows remote attackers to redirect users to arbitrary web sites and attempt phishing attacks. Once the target has opened the malicious URL in thei…
- CVE-2020-1997MEDIUMCVSS 5.3EG 5.32020-05-13
An open redirection vulnerability in the GlobalProtect component of Palo Alto Networks PAN-OS allows an attacker to specify an arbitrary redirection target away from the trusted GlobalProtect gateway. If the user then successfully authenti…
- CVE-2016-6636MEDIUMCVSS 5.3EG 5.32016-09-30
The OAuth authorization implementation in Pivotal Cloud Foundry (PCF) before 242; UAA 2.x before 2.7.4.7, 3.x before 3.3.0.5, and 3.4.x before 3.4.4; UAA BOSH before 11.5 and 12.x before 12.5; Elastic Runtime before 1.6.40, 1.7.x before 1.…
- CVE-2024-41955MEDIUMCVSS 5.2EG 5.22024-07-31
Mobile Security Framework (MobSF) is a security research platform for mobile applications in Android, iOS and Windows Mobile. An open redirect vulnerability exist in MobSF authentication view. Update to MobSF v4.0.5.
- CVE-2019-19613MEDIUMCVSS 5.2EG 5.22020-03-16
An issue was discovered in Halvotec RaQuest 10.23.10801.0. The login page of the admin application is vulnerable to an Open Redirect attack allowing an attacker to redirect a user to a malicious site after authentication. The attacker need…
- CVE-2026-80327MEDIUMCVSS 5.1EG 5.12026-10-06
An open redirect vulnerability exists in the PingGateway Fragment Filter feature. This issue affects PingGateway versions 7.1.0 and later, 2023.2.0 through 2024.11.1, and 2025.3.0 through 2025.11.1. It is fixed in versions 2024.11.2, 2025.…
- CVE-2026-89307MEDIUMCVSS 5.1EG 5.12026-09-15
The "Firma Circolare" feature in the "Design Scuole Italia" WordPress theme allows an authenticated attacker to inject arbitrary HTML via the sign parameter, enabling forced redirection of visiting users to an attacker-controlled URL (Stor…
- CVE-2026-67362MEDIUMCVSS 5.1EG 5.12026-08-21
Joomla Extension - j2commerce.com - Open redirect in cart controller in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - Four task handlers accepted a base64-encoded URL from user input and redirected to it without validating the destinat…
- CVE-2026-75114MEDIUMCVSS 5.1EG 5.12026-08-19
Joomla Extension - yootheme.com - Open redirect in CommentController::twitterAuthenticate() in Zoo < 4.1.64 - The referer request parameter is passed straight to setRedirect() with no validation.
- CVE-2025-71405MEDIUMCVSS 5.1EG 5.12026-08-14
chi versions before v5.2.2 contain an open redirect vulnerability in the RedirectSlashes middleware function that uses the Host header to construct redirect URLs. Attackers can manipulate the Host header to redirect users to arbitrary host…
- CVE-2026-55252MEDIUMCVSS 5.1EG 5.12026-07-09
OpenRun is an open-source, self-hosted GitOps platform for deploying web apps and internal tools to Docker or Kubernetes. Prior to version 0.17.7, the restrictions on redirect URLs in openrun can be bypassed by attackers, leading to open r…
- CVE-2026-12863MEDIUMCVSS 5.1EG 5.12026-06-22
An unvalidated redirect was contained in Venueless' social login functionality and could be exploited for phishing using trusted domains.
- CVE-2026-55185MEDIUMCVSS 5.1EG 5.12026-06-19
Miniflux 2 is an open source feed reader. Prior to 2.3.1, IsRelativePath in internal/urllib/url.go accepts redirect targets containing backslashes because Go URL parsing treats them as path characters. Browser backslash normalization conve…
- CVE-2026-10839MEDIUMCVSS 5.1EG 5.12026-06-17
Open redirection vulnerability in the authentication system allows an attacker to use manipulated values in the X-Forwarded-Host header to alter the URLs generated by the application. A successful exploit could redirect authenticated users…
- CVE-2026-10837MEDIUMCVSS 5.1EG 5.12026-06-17
Open redirection vulnerability due to insufficient validation of the X-Forwarded-Host HTTP header. An attacker could create manipulated links that, when opened by a victim, cause the victim to be redirected to domains controlled by the att…
- CVE-2026-47377MEDIUMCVSS 5.1EG 5.12026-06-05
NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, the client-side hashRedirect plugin called window.location.replace() on a path extracted from the URL hash fragment after only checking hashPath.startsWith('/')…
- CVE-2026-42350MEDIUMCVSS 5.1EG 5.12026-05-08
Kargo manages and automates the promotion of software artifacts. Prior to versions 1.7.10, 1.8.13, 1.9.8, and 1.10.2, Kargo is vulnerable to open redirect in UI OIDC login flow via the redirectTo query parameter. This issue has been patche…
- CVE-2026-42259MEDIUMCVSS 5.1EG 5.12026-05-07
Saltcorn is an extensible, open source, no-code database application builder. Prior to versions 1.4.6, 1.5.6, and 1.6.0-beta.5, Saltcorn validates the post-login dest parameter with a string check that only blocks :/ and //. Because all WH…
- CVE-2025-64716MEDIUMCVSS 5.1EG 5.12025-11-13
Anubis is a Web AI Firewall Utility that challenges users' connections in order to protect upstream resources from scraper bots. Prior to version 1.23.0, when using subrequest authentication, Anubis did not perform validation of the redire…
- CVE-2025-10355MEDIUMCVSS 5.1EG 5.12025-10-23
Open redirection vulnerability in MOLGENIS EMX2 v11.14.0. This vulnerability allows an attacker to create a malicious URL using a manipulated redirection parameter, potentially leading users to phishing sites or other malicious destination…
- CVE-2025-55751MEDIUMCVSS 5.1EG 5.12025-08-20
OnboardLite is the result of the Influx Initiative, our vision for an improved student organization lifecycle at the University of Central Florida. An attacker can craft a link to the trusted application that, when visited, redirects the u…
- CVE-2025-55166MEDIUMCVSS 5.1EG 5.12025-08-12
savg-sanitizer is a PHP SVG/XML sanitizer. Prior to version 0.22.0, the sanitization logic in the cleanXlinkHrefs method only searches for lower-case attribute name, which allows to by-pass the isHrefSafeValue check. As a result this allow…
- CVE-2025-54414MEDIUMCVSS 5.1EG 5.12025-07-26
Anubis is a Web AI Firewall Utility that weighs the soul of users' connections using one or more challenges in order to protect upstream resources from scraper bots. In versions 1.21.2 and below, attackers can craft malicious pass-challeng…
- CVE-2024-53264MEDIUMCVSS 5.1EG 5.12024-11-27
bunkerweb is an Open-source and next-generation Web Application Firewall (WAF). A open redirect vulnerability exists in the loading endpoint, allowing attackers to redirect authenticated users to arbitrary external URLs via the "next" para…
- CVE-2026-9245MEDIUMCVSS 5.0EG 5.02026-05-26
Improper input validation in the external authentication provider flow in Devolutions Server allows an unauthenticated remote attacker to redirect victims to an attacker-controlled domain via a crafted login link. This issue affects : …
- CVE-2025-2068MEDIUMCVSS 5.0EG 5.02025-04-25
An open redirect vulnerability was reported in the FileZ client that could allow information disclosure if a crafted url is visited by a local user.
- CVE-2017-18441MEDIUMCVSS 5.0EG 5.02019-08-02
cPanel before 64.0.21 allows demo accounts to redirect web traffic (SEC-245).
- CVE-2004-2260MEDIUMCVSS v2 5.0EG 5.02004-12-31
Opera Browser 7.23, and other versions before 7.50, updates the address bar as soon as the user clicks a link, which allows remote attackers to redirect to other sites via the onUnload attribute.
- CVE-2026-51564MEDIUMCVSS 4.9EG 4.92026-07-27
An issue in the redirect parameter in Milk admin <=0.9.8 allows remote attackers to redirect users to arbitrary external URLs via a crafted request.
- CVE-2021-22526MEDIUMCVSS 4.9EG 4.92021-09-13
Open Redirection vulnerability in NetIQ Access Manager prior to 5.0.1 and 4.5.4
- CVE-2026-53573MEDIUMCVSS 4.8EG 4.82026-07-31
GeoNetwork is a catalog application to manage spatially referenced resources. From 3.12.0 until 4.2.16 and 4.4.11, unsafe redirect validation in GeonetworkOAuth2LoginAuthenticationFilter and KeycloakAuthenticationProcessingFilter permits a…
- CVE-2026-28301MEDIUMCVSS 4.8EG 4.82026-06-09
A vulnerability in which an attacker can provide a crafted external URL that may redirect a user to an unintended website.
- CVE-2026-43924MEDIUMCVSS 4.8EG 4.82026-06-03
FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the Redirect module does not validate the URL scheme of administrator-configured destination URLs before storing or issuing redirects. This al…
- CVE-2026-41513MEDIUMCVSS 4.8EG 4.82026-05-12
Horilla is an HR and CRM software. In 1.5.0, the notification endpoints trust the unvalidated next parameter and redirect users to arbitrary external URLs. This allows an attacker to turn trusted application links into phishing or social-e…
- CVE-2025-40545MEDIUMCVSS 4.8EG 4.82025-11-18
SolarWinds Observability Self-Hosted is susceptible to an open redirection vulnerability. The URL is not properly sanitized, and an attacker could manipulate the string to redirect a user to a malicious site. The attack complexity is high,…
- CVE-2025-8066MEDIUMCVSS 4.8EG 4.82025-08-15
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Bunkerity Bunker Web on Linux allows Phishing.This issue affects Bunker Web: 1.6.2.
- CVE-2025-26394MEDIUMCVSS 4.8EG 4.82025-06-10
SolarWinds Observability Self-Hosted is susceptible to an open redirection vulnerability. The URL is not properly sanitized, and an attacker could manipulate the string to redirect a user to a malicious site. The attack complexity is hig…
- CVE-2025-1269MEDIUMCVSS 4.8EG 4.82025-02-18
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in HAVELSAN Liman MYS allows Cross-Site Flashing. This issue affects Liman MYS: before 2.1.1 - 1010.
- CVE-2024-55892MEDIUMCVSS 4.8EG 4.82025-01-14
TYPO3 is a free and open source Content Management Framework. Applications that use `TYPO3\CMS\Core\Http\Uri` to parse externally provided URLs (e.g., via a query parameter) and validate the host of the parsed URL may be vulnerable to open…
- CVE-2024-7428MEDIUMCVSS 4.8EG 4.82024-08-23
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in OpenText™ Network Node Manager i (NNMi) allows URL Redirector Abuse.This issue affects Network Node Manager i (NNMi): 2022.11, 2023.05, 23.4, 24.2.
- CVE-2023-4965MEDIUMCVSS 4.8EG 4.82023-09-14
A vulnerability was found in phpipam 1.5.1. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Header Handler. The manipulation of the argument X-Forwarded-Host leads to open redirect. T…
Map vulnerabilities like CWE-601 to your infrastructure
EchelonGraph correlates every CVE — across CWE-601 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →