CWE-601
1,576 CVEs • Abstraction: Base • Likelihood of Exploit: Low
URL Redirection to Untrusted Site ('Open Redirect')
A web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a Redirect. This simplifies phishing attacks.
CVEs (1,576)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Jenkins 1Gitlab Authentication Jun 17, 2026 Feb 15, 2022 N/A· v4 5.4 MEDIUM· v3 4.9 MEDIUM· v2 Jenkins GitLab Authentication Plugin 1.13 and earlier records the HTTP Referer header as part of the URL query parameters when the authentication process starts, allowing attackers with access to Jenkins to craft a URL t...Show more |
Open Redirect in Packagist microweber/microweber prior to 1.2.11. |
The WordPress Newsletter Plugin WordPress plugin before 1.6.5 does not validate the to parameter before redirecting the user to its given value, leading to an open redirect issue |
An issue in the Login page of Magnolia CMS v6.2.3 and below allows attackers to exploit both an Open Redirect vulnerability and Cross-Site Request Forgery (CSRF) in order to brute force and exfiltrate users' credentials. |
Open Redirect in Packagist microweber/microweber prior to 1.2.11. |
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions there is no protection against URL redirection to untrusted sites, in particular some well kno...Show more |
1Siemens 1Sinema Remote Connect Server Jun 17, 2026 Feb 9, 2022 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0). Affected products contain an open redirect vulnerability. An attacker could trick a valid authenticated user to the device into c...Show more |
Gitea before 1.4.3 is affected by URL Redirection to Untrusted Site ('Open Redirect') via internal URLs. |
1Octopus 2Octopus Deploy Octopus ServerJun 17, 2026 Feb 7, 2022 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 In affected Octopus Server versions when the server HTTP and HTTPS bindings are configured to localhost, Octopus Server will allow open redirects. |
Open Redirect vulnerability exists in SeedDMS 6.0.15 in out.Login.php, which llows remote malicious users to redirect users to malicious sites using the "referuri" parameter. |
1Adenza 1Axiomsl Controllerview Jun 17, 2026 Jan 30, 2022 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 Adenza AxiomSL ControllerView through 10.8.1 allows redirection for SSO login URLs. |
Products.ATContentTypes are the core content types for Plone 2.1 - 4.3. Versions of Plone that are dependent on Products.ATContentTypes prior to version 3.0.6 are vulnerable to reflected cross site scripting and open red...Show more |
1Webp Converter For Media Project 1Webp Converter For Media Jun 17, 2026 Jan 24, 2022 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 The WebP Converter for Media WordPress plugin before 4.0.3 contains a file (passthru.php) which does not validate the src parameter before redirecting the user to it, leading to an Open Redirect issue |
The Event Tickets WordPress plugin before 5.2.2 does not validate the tribe_tickets_redirect_to parameter before redirecting the user to the given value, leading to an arbitrary redirect issue |
The AnyComment WordPress plugin before 0.3.5 has an API endpoint which passes user input via the redirect parameter to the wp_redirect() function without being validated first, leading to an Open Redirect issue, which ac...Show more |
3Debian Node Fetch ProjectSiemens3Debian Linux Node FetchSinec InsJun 17, 2026 Jan 16, 2022 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 node-fetch is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor |
An open redirect vulnerability has been reported to affect QNAP device running QcalAgent. If exploited, this vulnerability allows attackers to redirect users to an untrusted page that contains malware. We have already fi...Show more |
A open redirect vulnerability exists in Action Pack >= 6.0.0 that could allow an attacker to craft a "X-Forwarded-Host" headers in combination with certain "allowed host" formats can cause the Host Authorization middlewa...Show more |
forge is vulnerable to URL Redirection to Untrusted Site |
Shopware is an open source e-commerce software platform. An open redirect vulnerability has been discovered. Users may be arbitrary redirected due to incomplete URL handling in the shopware router. This issue has been re...Show more |