CWE-601
1,576 CVEs • Abstraction: Base • Likelihood of Exploit: Low
URL Redirection to Untrusted Site ('Open Redirect')
A web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a Redirect. This simplifies phishing attacks.
CVEs (1,576)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
PowerMux is a drop-in replacement for Go's http.ServeMux. In PowerMux versions prior to 1.1.1, attackers may be able to craft phishing links and other open redirects by exploiting the trailing slash redirection feature....Show more |
Machform prior to version 16 is vulnerable to an open redirect in Safari_init.php due to an improperly sanitized 'ref' parameter. |
Umbraco CMS before 7.15.7 is vulnerable to Open Redirection due to insufficient url sanitization on booting.aspx. |
1Avaya 1Aura Experience Portal Jun 17, 2026 Jun 24, 2021 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 A vulnerability in the system Service Menu component of Avaya Aura Experience Portal may allow URL Redirection to any untrusted site through a crafted attack. Affected versions include 7.0 through 7.2.3 (without hotfix)...Show more |
GetSimpleCMS <=3.3.15 has an open redirect in admin/changedata.php via the redirect function to the url parameter. |
Gitpod before 0.6.0 allows unvalidated redirects. |
1Vanillaforums 1Vanilla Forums Nov 21, 2024 Jun 22, 2021 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 It was found in vanilla forums before 2.0.10 a potential linkbait vulnerability in dispatcher. |
Advantech WebAccess/SCADA Versions 9.0.1 and prior is vulnerable to redirection, which may allow an attacker to send a maliciously crafted URL that could result in redirecting a user to a malicious webpage. |
1Posimyth 1The Plus Addons For Elementor Jun 17, 2026 Jun 14, 2021 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.10 did not validate a redirect parameter on a specifically crafted URL before redirecting the user to it, leading to an Open Redirect issue. |
The actionpack ruby gem before 6.1.3.2 suffers from a possible open redirect vulnerability. Specially crafted Host headers in combination with certain "allowed host" formats can cause the Host Authorization middleware in...Show more |
1Flask Unchained Project 1Flask Unchained Jun 17, 2026 Jun 11, 2021 N/A· v4 5.4 MEDIUM· v3 5.8 MEDIUM· v2 This affects the package Flask-Unchained before 0.9.0. When using the the _validate_redirect_url function, it is possible to bypass URL validation and redirect a user to an arbitrary URL by providing multiple back slashe...Show more |
Open Redirect in Z-BlogPHP v1.5.2 and earlier allows remote attackers to obtain sensitive information via the "redirect" parameter in the component "zb_system/cmd.php." |
1Chiyu Tech 14Bf 430 Firmware Bf 431 FirmwareBf 450m Firmware+11 moreJun 17, 2026 Jun 4, 2021 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 An open redirect vulnerability exists in BF-630, BF-450M, BF-430, BF-431, BF631-W, BF830-W, Webpass, and SEMAC devices from CHIYU Technology that can be exploited by sending a link that has a specially crafted URL to con...Show more |
1Cisco 2Webex Meetings Online Webex Meetings ServerJun 17, 2026 Jun 4, 2021 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 A vulnerability in Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to redirect users to a malicious file. This vulnerability is due to improper validation of URL paths...Show more |
In Apache Dubbo prior to 2.6.9 and 2.7.9, the usage of parseURL method will lead to the bypass of white host check which can cause open redirect or SSRF vulnerability. |
Tenancy multi-tenant is an open source multi-domain controller for the Laravel web framework. In some situations, it is possible to have open redirects where users can be redirected from your site to any other site using...Show more |
1Trailing Slash Project 1Trailing Slash Jun 17, 2026 May 24, 2021 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 The package trailing-slash before 2.0.1 are vulnerable to Open Redirect via the use of trailing double slashes in the URL when accessing the vulnerable endpoint (such as https://example.com//attacker.example/). The vulne...Show more |
A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to redirect a user to an undesired web page. This vulnerability is due to improper input validation o...Show more |
Prometheus is an open-source monitoring system and time series database. In 2.23.0, Prometheus changed its default UI to the New ui. To ensure a seamless transition, the URL's prefixed by /new redirect to /. Due to a bug...Show more |
Smartstore (aka SmartStoreNET) before 4.1.0 allows CommonController.ClearCache, ClearDatabaseCache, RestartApplication, and ScheduleTaskController.Edit open redirect. |