← Back
CWE-601

1,576 CVEs • Abstraction: Base • Likelihood of Exploit: Low

URL Redirection to Untrusted Site ('Open Redirect')

A web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a Redirect. This simplifies phishing attacks.

JSON object

Loading...

CVEs (1,576)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Groupsession
1Groupsession
Jun 17, 2026
Dec 24, 2021
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Open redirect vulnerability in GroupSession Free edition ver5.1.1 and earlier, GroupSession byCloud ver5.1.1 and earlier, and GroupSession ZION ver5.1.1 and earlier allows a remote unauthenticated attacker to redirect us...Show more
Open redirect vulnerability in GroupSession Free edition ver5.1.1 and earlier, GroupSession byCloud ver5.1.1 and earlier, and GroupSession ZION ver5.1.1 and earlier allows a remote unauthenticated attacker to redirect users to arbitrary web sites and conduct phishing attacks by having a user to access a specially crafted URL.Show less
1Tcman
1Gim
Jun 17, 2026
Dec 17, 2021
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
TCMAN GIM is affected by an open redirect vulnerability. This vulnerability allows the redirection of user navigation to pages controlled by the attacker. The exploitation of this vulnerability might allow a remote attac...Show more
TCMAN GIM is affected by an open redirect vulnerability. This vulnerability allows the redirection of user navigation to pages controlled by the attacker. The exploitation of this vulnerability might allow a remote attacker to obtain information.Show less
1Auth0
1Nextjs Auth0
Jun 17, 2026
Dec 16, 2021
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. Versions before 1.6.2 do not filter out certain returnTo parameter values from the login url, which expose the application...Show more
The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. Versions before 1.6.2 do not filter out certain returnTo parameter values from the login url, which expose the application to an open redirect vulnerability. Users are advised to upgrade as soon as possible. There are no known workarounds for this issue.Show less
1Synacor
1Zimbra Collaboration Suite
Jun 17, 2026
Dec 15, 2021
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
An issue in /domain/service/.ewell-known/caldav of Zimbra Collaboration 8.8.12 allows attackers to redirect users to any arbitrary website of their choosing.
1Openwhyd
1Openwhyd
Jun 17, 2026
Dec 10, 2021
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
openwhyd is vulnerable to URL Redirection to Untrusted Site
1Mozilla
1Firefox
Jun 17, 2026
Dec 8, 2021
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
The 'Copy Image Link' context menu action would copy the final image URL after redirects. By embedding an image that triggered authentication flows - in conjunction with a Content Security Policy that stopped a redirecti...Show more
The 'Copy Image Link' context menu action would copy the final image URL after redirects. By embedding an image that triggered authentication flows - in conjunction with a Content Security Policy that stopped a redirection chain in the middle - the final image URL could be one that contained an authentication token used to takeover a user account. If a website tricked a user into copy and pasting the image link back to the page, the page would be able to steal the authentication tokens. This was fixed by making the action return the original URL, before any redirects. This vulnerability affects Firefox < 94.Show less
1Fortinet
1Fortiweb
Jun 17, 2026
Dec 8, 2021
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
A url redirection to untrusted site ('open redirect') in Fortinet FortiWeb version 6.4.1 and 6.4.0, version 6.3.15 and below, version 6.2.6 and below allows attacker to use the device as a proxy and reach external or pro...Show more
A url redirection to untrusted site ('open redirect') in Fortinet FortiWeb version 6.4.1 and 6.4.0, version 6.3.15 and below, version 6.2.6 and below allows attacker to use the device as a proxy and reach external or protected hosts via redirection handlers.Show less
1Fortinet
1Fortiweb
Jun 17, 2026
Dec 8, 2021
N/A· v4
5.4 MEDIUM· v3
4.9 MEDIUM· v2
A url redirection to untrusted site ('open redirect') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows attacker to use the device as proxy via crafted GET parameters in requests to error handlers
1Showdoc
1Showdoc
Jun 17, 2026
Dec 3, 2021
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
showdoc is vulnerable to URL Redirection to Untrusted Site
1Showdoc
1Showdoc
Jun 17, 2026
Dec 1, 2021
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
showdoc is vulnerable to URL Redirection to Untrusted Site
1Cryptshare
1Cryptshare Server
Jun 17, 2026
Nov 30, 2021
N/A· v4
5.4 MEDIUM· v3
4.9 MEDIUM· v2
An open redirect through HTML injection in confidential messages in Cryptshare before 5.1.0 allows remote attackers (with permission to provide confidential messages via Cryptshare) to redirect targeted victims to any UR...Show more
An open redirect through HTML injection in confidential messages in Cryptshare before 5.1.0 allows remote attackers (with permission to provide confidential messages via Cryptshare) to redirect targeted victims to any URL via the '<meta http-equiv="refresh"' substring in the editor parameter.Show less
1Redash
1Redash
Jun 17, 2026
Nov 24, 2021
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Redash is a package for data visualization and sharing. In Redash version 10.0 and prior, the implementation of Google Login (via OAuth) incorrectly uses the `state` parameter to pass the next URL to redirect the user to...Show more
Redash is a package for data visualization and sharing. In Redash version 10.0 and prior, the implementation of Google Login (via OAuth) incorrectly uses the `state` parameter to pass the next URL to redirect the user to after login. The `state` parameter should be used for a Cross-Site Request Forgery (CSRF) token, not a static and easily predicted value. This vulnerability does not affect users who do not use Google Login for their instance of Redash. A patch in the `master` and `release/10.x.x` branches addresses this by replacing `Flask-Oauthlib` with `Authlib` which automatically provides and validates a CSRF token for the state variable. The new implementation stores the next URL on the user session object. As a workaround, one may disable Google Login to mitigate the vulnerability.Show less
3Debian
FedoraprojectGoogle
3Chrome
Debian LinuxFedora
Jun 17, 2026
Nov 23, 2021
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 95.0.4638.69 allowed a remote attacker to arbitrarily browser to a malicious URL via a crafted HTML page.
1Dell
1Emc Cloud Link
Jun 17, 2026
Nov 23, 2021
N/A· v4
5.4 MEDIUM· v3
4.9 MEDIUM· v2
Dell EMC CloudLink 7.1 and all prior versions contain a HTML and Javascript Injection Vulnerability. A remote low privileged attacker, may potentially exploit this vulnerability, directing end user to arbitrary and poten...Show more
Dell EMC CloudLink 7.1 and all prior versions contain a HTML and Javascript Injection Vulnerability. A remote low privileged attacker, may potentially exploit this vulnerability, directing end user to arbitrary and potentially malicious websites.Show less
1Oppia
1Oppia
Jun 17, 2026
Nov 8, 2021
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Oppia 3.1.4 does not verify that certain URLs are valid before navigating to them.
1Cisco
2Collaboration Meeting Rooms
Webex Video Mesh
Jun 17, 2026
Nov 4, 2021
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
A vulnerability in the web-based management interface of Cisco Webex Video Mesh could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper input vali...Show more
A vulnerability in the web-based management interface of Cisco Webex Video Mesh could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper input validation of the URL parameters in an HTTP request. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to redirect a user to a malicious website. Attackers may use this type of vulnerability, known as an open redirect attack, as part of a phishing attack to persuade users to unknowingly visit malicious sites.Show less
1Replicated
1Replicated Classic
Jun 17, 2026
Nov 1, 2021
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
An open redirect vulnerability exists in Replicated Classic versions prior to 2.53.1 that could lead to spoofing. To exploit this vulnerability, an attacker could send a link that has a specially crafted URL and convince...Show more
An open redirect vulnerability exists in Replicated Classic versions prior to 2.53.1 that could lead to spoofing. To exploit this vulnerability, an attacker could send a link that has a specially crafted URL and convince the user to click the link, redirecting the user to an untrusted site.Show less
1Cisco
3Firepower Management Center Virtual Appliance
Firepower Threat DefenseSourcefire Defense Center
Jun 17, 2026
Oct 27, 2021
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an attacker to execute a cross-site scripting (XSS) attack or an open redirect attack. For mo...Show more
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an attacker to execute a cross-site scripting (XSS) attack or an open redirect attack. For more information about these vulnerabilities, see the Details section of this advisory.Show less
1Cisco
3Firepower Management Center Virtual Appliance
Firepower Threat DefenseSourcefire Defense Center
Jun 17, 2026
Oct 27, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an attacker to execute a cross-site scripting (XSS) attack or an open redirect attack. For mo...Show more
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an attacker to execute a cross-site scripting (XSS) attack or an open redirect attack. For more information about these vulnerabilities, see the Details section of this advisory.Show less
1Firefly Iii
1Firefly Iii
Jun 17, 2026
Oct 19, 2021
N/A· v4
5.4 MEDIUM· v3
4.9 MEDIUM· v2
firefly-iii is vulnerable to URL Redirection to Untrusted Site