CWE-601— URL Redirection to Untrusted Site (Open Redirect)
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.— MITRE CWE catalog
1,776 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-601page 7 of 36
- CVE-2024-56962MEDIUMCVSS 6.5EG 6.52025-01-27
An issue in Tencent Technology (Shanghai) Co., Ltd WeSing iOS v9.3.39 allows attackers to access sensitive user information via supplying a crafted link.
- CVE-2024-56960MEDIUMCVSS 6.5EG 6.52025-01-27
An issue in Tianjin Xiaowu Information technology Co., Ltd BeiKe Holdings iOS 1.3.50 allows attackers to access sensitive user information via supplying a crafted link.
- CVE-2024-56959MEDIUMCVSS 6.5EG 6.52025-01-27
An issue in Mashang Consumer Finance Co., Ltd Anyihua iOS 3.6.2 allows attackers to access sensitive user information via supplying a crafted link.
- CVE-2024-56957MEDIUMCVSS 6.5EG 6.52025-01-27
An issue in Kingsoft Office Software Corporation Limited WPS Office iOS 12.20.0 allows attackers to access sensitive user information via supplying a crafted link.
- CVE-2024-56955MEDIUMCVSS 6.5EG 6.52025-01-27
An issue in Tencent Technology (Shenzhen) Company Limited QQMail iOS 6.6.4 allows attackers to access sensitive user information via supplying a crafted link.
- CVE-2024-56954MEDIUMCVSS 6.5EG 6.52025-01-27
An issue in Beijing Baidu Netcom Science & Technology Co Ltd Haokan Video iOS 7.70.0 allows attackers to access sensitive user information via supplying a crafted link.
- CVE-2024-56953MEDIUMCVSS 6.5EG 6.52025-01-27
An issue in Baidu (China) Co Ltd Baidu Input Method (iOS version) v12.6.13 allows attackers to access user information via supplying a crafted link.
- CVE-2024-56952MEDIUMCVSS 6.5EG 6.52025-01-27
An issue in Beijing Baidu Netcom Science & Technology Co Ltd Baidu Lite app (iOS version) 6.40.0 allows attackers to access user information via supplying a crafted link.
- CVE-2024-56951MEDIUMCVSS 6.5EG 6.52025-01-27
An issue in Hangzhou Bobo Technology Co Ltd UU Game Booster iOS 10.6.13 allows attackers to access sensitive user information via supplying a crafted link.
- CVE-2024-56950MEDIUMCVSS 6.5EG 6.52025-01-27
An issue in KuGou Technology Co., Ltd KuGou Concept iOS 4.0.61 allows attackers to access sensitive user information via supplying a crafted link.
- CVE-2024-56949MEDIUMCVSS 6.5EG 6.52025-01-27
An issue in Guangzhou Polar Future Culture Technology Co., Ltd University Search iOS 2.27.0 allows attackers to access sensitive user information via supplying a crafted link.
- CVE-2024-56948MEDIUMCVSS 6.5EG 6.52025-01-27
An issue in KuGou Technology CO. LTD KuGou Music iOS v20.0.0 allows attackers to access sensitive user information via supplying a crafted link.
- CVE-2024-56947MEDIUMCVSS 6.5EG 6.52025-01-27
An issue in Xiamen Meitu Technology Co., Ltd. BeautyCam iOS v12.3.60 allows attackers to access sensitive user information via supplying a crafted link.
- CVE-2024-48463MEDIUMCVSS 6.5EG 6.52024-11-04
Bruno before 1.29.1 uses Electron shell.openExternal without validation (of http or https) for opening windows within the Markdown docs viewer.
- CVE-2024-4445MEDIUMCVSS 6.5EG 6.52024-05-14
The WP Compress – Image Optimizer [All-In-One] plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the several functions in versions up to, and including, 6.20.01. This makes it po…
- CVE-2024-1183MEDIUMCVSS 6.5EG 6.52024-04-16
An SSRF (Server-Side Request Forgery) vulnerability exists in the gradio-app/gradio repository, allowing attackers to scan and identify open ports within an internal network. By manipulating the 'file' parameter in a GET request, an attack…
- CVE-2024-1227MEDIUMCVSS 6.5EG 6.52024-03-12
An open redirect vulnerability, the exploitation of which could allow an attacker to create a custom URL and redirect a legitimate page to a malicious site.
- CVE-2023-50963MEDIUMCVSS 6.5EG 6.52024-01-19
IBM Storage Defender - Data Protect 1.0.0 through 1.4.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable sys…
- CVE-2023-30433MEDIUMCVSS 6.5EG 6.52023-07-19
IBM Security Verify Access 10.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to s…
- CVE-2023-23855MEDIUMCVSS 6.5EG 6.52023-02-14
SAP Solution Manager - version 720, allows an authenticated attacker to redirect users to a malicious site due to insufficient URL validation. A successful attack could lead an attacker to read or modify the information or expose the user …
- CVE-2022-39183MEDIUMCVSS 6.5EG 6.52023-01-12
Moodle Plugin - SAML Auth may allow Open Redirect through unspecified vectors.
- CVE-2022-34478MEDIUMCVSS 6.5EG 6.52022-12-22
The <code>ms-msdt</code>, <code>search</code>, and <code>search-ms</code> protocols deliver content to Microsoft applications, bypassing the browser, when a user accepts a prompt. These applications have had known vulnerabilities, exploite…
- CVE-2022-41258MEDIUMCVSS 6.5EG 6.52022-11-08
Due to insufficient input validation, SAP Financial Consolidation - version 1010, allows an authenticated attacker to inject malicious script when running a common query in the Web Administration Console. On successful exploitation, an att…
- CVE-2022-39359MEDIUMCVSS 6.5EG 6.52022-10-26
Metabase is data visualization software. Prior to versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9, custom GeoJSON map URL address would follow redirects to addresses that were otherwise disallowed, like link-loc…
- CVE-2022-20794MEDIUMCVSS 6.5EG 6.52022-05-04
Multiple vulnerabilities in the web engine of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow a remote attacker to cause a denial of service (DoS) condition, view sensitive data on an affected …
- CVE-2021-32806MEDIUMCVSS 6.5EG 6.52021-08-02
Products.isurlinportal is a replacement for isURLInPortal method in Plone. Versions of Products.isurlinportal prior to 1.2.0 have an Open Redirect vulnerability. Various parts of Plone use the 'is url in portal' check for security, mostly …
- CVE-2021-29622MEDIUMCVSS 6.5EG 6.52021-05-19
Prometheus is an open-source monitoring system and time series database. In 2.23.0, Prometheus changed its default UI to the New ui. To ensure a seamless transition, the URL's prefixed by /new redirect to /. Due to a bug in the code, it is…
- CVE-2019-3778MEDIUMCVSS 6.5EG 6.52019-03-07
Spring Security OAuth, versions 2.3 prior to 2.3.5, and 2.2 prior to 2.2.4, and 2.1 prior to 2.1.4, and 2.0 prior to 2.0.17, and older unsupported versions could be susceptible to an open redirector attack that can leak an authorization co…
- CVE-2017-15419MEDIUMCVSS 6.5EG 6.52018-08-28
Insufficient policy enforcement in Resource Timing API in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to infer browsing history by triggering a leaked cross-origin URL via a crafted HTML page.
- CVE-2018-0924MEDIUMCVSS 6.5EG 6.52018-03-14
Microsoft Exchange Server 2010 Service Pack 3 Update Rollup 20, Microsoft Exchange Server 2013 Cumulative Update 18, Microsoft Exchange Server 2013 Cumulative Update 19, Microsoft Exchange Server 2013 Service Pack 1, Microsoft Exchange Ser…
- CVE-2011-1594MEDIUMCVSS 6.5EG 6.52014-02-05
A flaw was found in Spacewalk, as used in Red Hat Network Satellite. This open redirect vulnerability allows remote attackers to redirect users to arbitrary web sites by manipulating a URL in the url_bounce parameter. This can enable attac…
- CVE-2025-55625MEDIUMCVSS 6.3EG 6.52025-08-22
An open redirect vulnerability in Reolink v4.54.0.4.20250526 allows attackers to redirect users to a malicious site via a crafted URL. NOTE: this is disputed by the Supplier because it is intentional behavior that supports redirection to A…
- CVE-2026-23817MEDIUMCVSS 6.1EG 6.52026-03-11
A vulnerability in the web-based management interface of AOS-CX Switches could allow an unauthenticated remote attacker to redirect users to an arbitrary URL.
- CVE-2025-60935MEDIUMCVSS 6.1EG 6.52025-12-24
An open redirect vulnerability in the login endpoint of Blitz Panel v1.17.0 allows attackers to redirect users to malicious domains via a crafted URL. This issue affects the next_url parameter in the login endpoint and could lead to phishi…
- CVE-2021-4000MEDIUMCVSS 6.1EG 6.52021-12-03
showdoc is vulnerable to URL Redirection to Untrusted Site
- CVE-2026-61143MEDIUMCVSS 6.4EG 6.42026-07-21
Vulnerability in the Oracle Communications Convergent Charging Controller product of Oracle Communications (component: Prov IF). Supported versions that are affected are 15.0.0.0.0 and 15.2.0.0.0. Difficult to exploit vulnerability allow…
- CVE-2025-57665MEDIUMCVSS 6.4EG 6.42025-09-09
Element Plus Link component (el-link) through 2.10.6 implements insufficient input validation for the href attribute, creating a security abstraction gap that obscures URL-based attack vectors. The component passes user-controlled href val…
- CVE-2024-9387MEDIUMCVSS 6.4EG 6.42024-12-12
An issue was discovered in GitLab CE/EE affecting all versions from 11.8 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. An attacker could potentially perform an open redirect against a given releases API endpoint.
- CVE-2024-4283MEDIUMCVSS 6.4EG 6.42024-09-16
An issue has been discovered in GitLab EE affecting all versions starting from 11.1 before 17.1.7, 17.2 before 17.2.5, and 17.3 before 17.3.2. Under certain conditions an open redirect vulnerability could allow for an account takeover by b…
- CVE-2024-4612MEDIUMCVSS 6.4EG 6.42024-09-12
An issue has been discovered in GitLab EE affecting all versions starting from 12.9 before 17.1.7, 17.2 before 17.2.5, and 17.3 before 17.3.2. Under certain conditions an open redirect vulnerability could allow for an account takeover by b…
- CVE-2023-0748MEDIUMCVSS 6.4EG 6.42023-02-08
Open Redirect in GitHub repository btcpayserver/btcpayserver prior to 1.7.6.
- CVE-2021-43812MEDIUMCVSS 6.4EG 6.42021-12-16
The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. Versions before 1.6.2 do not filter out certain returnTo parameter values from the login url, which expose the application to an open redirect…
- CVE-2020-8559MEDIUMCVSS 6.4EG 6.42020-07-22
The Kubernetes kube-apiserver in versions v1.6-v1.15, and versions prior to v1.16.13, v1.17.9 and v1.18.6 are vulnerable to an unvalidated redirect on proxied upgrade requests that could allow an attacker to escalate privileges from a node…
- CVE-2023-5375MEDIUMCVSS 6.1EG 6.42023-10-04
Open Redirect in GitHub repository mosparo/mosparo prior to 1.0.2.
- CVE-2024-58342MEDIUMCVSS 6.3EG 6.32026-04-01
XenForo before 2.2.17 and 2.3.1 allows open redirect via a specially crafted URL. The getDynamicRedirect() function does not adequately validate the redirect target, allowing attackers to redirect users to arbitrary external sites using cr…
- CVE-2024-13983MEDIUMCVSS 6.3EG 6.32025-11-14
Inappropriate implementation in Lens in Google Chrome on iOS prior to 136.0.7103.59 allowed a remote attacker to perform UI spoofing via a crafted QR code. (Chromium security severity: Low)
- CVE-2024-12924MEDIUMCVSS 6.3EG 6.32025-09-01
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Akınsoft QR Menü allows Forceful Browsing, Phishing. This issue affects QR Menü: from s1.05.05 before v1.05.12.
- CVE-2024-34328MEDIUMCVSS 6.3EG 6.32025-07-31
An open redirect in Sielox AnyWare v2.1.2 allows attackers to execute a man-in-the-middle attack via a crafted URL.
- CVE-2025-3522MEDIUMCVSS 6.3EG 6.32025-04-15
Thunderbird processes the X-Mozilla-External-Attachment-URL header to handle attachments which can be hosted externally. When an email is opened, Thunderbird accesses the specified URL to determine file size, and navigates to it when the …
- CVE-2023-3568MEDIUMCVSS 6.3EG 6.32023-07-10
Open Redirect in GitHub repository alextselegidis/easyappointments prior to 1.5.0.
Map vulnerabilities like CWE-601 to your infrastructure
EchelonGraph correlates every CVE — across CWE-601 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →