← Back
CWE-601

1,576 CVEs • Abstraction: Base • Likelihood of Exploit: Low

URL Redirection to Untrusted Site ('Open Redirect')

A web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a Redirect. This simplifies phishing attacks.

JSON object

Loading...

CVEs (1,576)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Powermux Project
1Powermux
Jun 17, 2026
Jun 29, 2021
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
PowerMux is a drop-in replacement for Go's http.ServeMux. In PowerMux versions prior to 1.1.1, attackers may be able to craft phishing links and other open redirects by exploiting the trailing slash redirection feature....Show more
PowerMux is a drop-in replacement for Go's http.ServeMux. In PowerMux versions prior to 1.1.1, attackers may be able to craft phishing links and other open redirects by exploiting the trailing slash redirection feature. This may lead to users being redirected to untrusted sites after following an attacker crafted link. The issue is resolved in v1.1.1. There are no existing workarounds.Show less
1Machform
1Machform
Jun 17, 2026
Jun 29, 2021
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Machform prior to version 16 is vulnerable to an open redirect in Safari_init.php due to an improperly sanitized 'ref' parameter.
1Umbraco
1Umbraco Cms
Jun 17, 2026
Jun 28, 2021
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Umbraco CMS before 7.15.7 is vulnerable to Open Redirection due to insufficient url sanitization on booting.aspx.
1Avaya
1Aura Experience Portal
Jun 17, 2026
Jun 24, 2021
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
A vulnerability in the system Service Menu component of Avaya Aura Experience Portal may allow URL Redirection to any untrusted site through a crafted attack. Affected versions include 7.0 through 7.2.3 (without hotfix)...Show more
A vulnerability in the system Service Menu component of Avaya Aura Experience Portal may allow URL Redirection to any untrusted site through a crafted attack. Affected versions include 7.0 through 7.2.3 (without hotfix) and 8.0.0 (without hotfix).Show less
1Get Simple
1Getsimplecms
Jun 17, 2026
Jun 23, 2021
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
GetSimpleCMS <=3.3.15 has an open redirect in admin/changedata.php via the redirect function to the url parameter.
1Gitpod
1Gitpod
Jun 17, 2026
Jun 22, 2021
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Gitpod before 0.6.0 allows unvalidated redirects.
1Vanillaforums
1Vanilla Forums
Nov 21, 2024
Jun 22, 2021
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
It was found in vanilla forums before 2.0.10 a potential linkbait vulnerability in dispatcher.
1Advantech
1Webaccess/scada
Jun 17, 2026
Jun 18, 2021
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Advantech WebAccess/SCADA Versions 9.0.1 and prior is vulnerable to redirection, which may allow an attacker to send a maliciously crafted URL that could result in redirecting a user to a malicious webpage.
1Posimyth
1The Plus Addons For Elementor
Jun 17, 2026
Jun 14, 2021
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.10 did not validate a redirect parameter on a specifically crafted URL before redirecting the user to it, leading to an Open Redirect issue.
1Rubyonrails
1Rails
Jun 17, 2026
Jun 11, 2021
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
The actionpack ruby gem before 6.1.3.2 suffers from a possible open redirect vulnerability. Specially crafted Host headers in combination with certain "allowed host" formats can cause the Host Authorization middleware in...Show more
The actionpack ruby gem before 6.1.3.2 suffers from a possible open redirect vulnerability. Specially crafted Host headers in combination with certain "allowed host" formats can cause the Host Authorization middleware in Action Pack to redirect users to a malicious website. This is similar to CVE-2021-22881. Strings in config.hosts that do not have a leading dot are converted to regular expressions without proper escaping. This causes, for example, `config.hosts << "sub.example.com"` to permit a request with a Host header value of `sub-example.com`.Show less
1Flask Unchained Project
1Flask Unchained
Jun 17, 2026
Jun 11, 2021
N/A· v4
5.4 MEDIUM· v3
5.8 MEDIUM· v2
This affects the package Flask-Unchained before 0.9.0. When using the the _validate_redirect_url function, it is possible to bypass URL validation and redirect a user to an arbitrary URL by providing multiple back slashe...Show more
This affects the package Flask-Unchained before 0.9.0. When using the the _validate_redirect_url function, it is possible to bypass URL validation and redirect a user to an arbitrary URL by providing multiple back slashes such as \\\evil.com/path. This vulnerability is only exploitable if an alternative WSGI server other than Werkzeug is used, or the default behaviour of Werkzeug is modified using 'autocorrect_location_header=False.Show less
1Zblogcn
1Z Blogphp
Jun 17, 2026
Jun 7, 2021
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Open Redirect in Z-BlogPHP v1.5.2 and earlier allows remote attackers to obtain sensitive information via the "redirect" parameter in the component "zb_system/cmd.php."
1Chiyu Tech
14Bf 430 Firmware
Bf 431 FirmwareBf 450m Firmware+11 more
Jun 17, 2026
Jun 4, 2021
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
An open redirect vulnerability exists in BF-630, BF-450M, BF-430, BF-431, BF631-W, BF830-W, Webpass, and SEMAC devices from CHIYU Technology that can be exploited by sending a link that has a specially crafted URL to con...Show more
An open redirect vulnerability exists in BF-630, BF-450M, BF-430, BF-431, BF631-W, BF830-W, Webpass, and SEMAC devices from CHIYU Technology that can be exploited by sending a link that has a specially crafted URL to convince the user to click on it.Show less
1Cisco
2Webex Meetings Online
Webex Meetings Server
Jun 17, 2026
Jun 4, 2021
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
A vulnerability in Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to redirect users to a malicious file. This vulnerability is due to improper validation of URL paths...Show more
A vulnerability in Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to redirect users to a malicious file. This vulnerability is due to improper validation of URL paths in the application interface. An attacker could exploit this vulnerability by persuading a user to follow a specially crafted URL that is designed to cause Cisco Webex Meetings to include a remote file in the web UI. A successful exploit could allow the attacker to cause the application to offer a remote file to a user, which could allow the attacker to conduct further phishing or spoofing attacks.Show less
1Apache
1Dubbo
Jun 17, 2026
Jun 1, 2021
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
In Apache Dubbo prior to 2.6.9 and 2.7.9, the usage of parseURL method will lead to the bypass of white host check which can cause open redirect or SSRF vulnerability.
1Tenancy
1Multi Tenant
Jun 17, 2026
May 27, 2021
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Tenancy multi-tenant is an open source multi-domain controller for the Laravel web framework. In some situations, it is possible to have open redirects where users can be redirected from your site to any other site using...Show more
Tenancy multi-tenant is an open source multi-domain controller for the Laravel web framework. In some situations, it is possible to have open redirects where users can be redirected from your site to any other site using a specially crafted URL. This is only the case for installations where the default Hostname Identification is used and the environment uses tenants that have `force_https` set to `true` (default: `false`). Version 5.7.2 contains the relevant patches to fix this bug. Stripping the URL from special characters to prevent specially crafted URL's from being redirected to. As a work around users can set the `force_https` to every tenant to `false`, however this may degrade connection security.Show less
1Trailing Slash Project
1Trailing Slash
Jun 17, 2026
May 24, 2021
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
The package trailing-slash before 2.0.1 are vulnerable to Open Redirect via the use of trailing double slashes in the URL when accessing the vulnerable endpoint (such as https://example.com//attacker.example/). The vulne...Show more
The package trailing-slash before 2.0.1 are vulnerable to Open Redirect via the use of trailing double slashes in the URL when accessing the vulnerable endpoint (such as https://example.com//attacker.example/). The vulnerable code is in index.js::createTrailing(), as the web server uses relative URLs instead of absolute URLs.Show less
1Cisco
1Finesse
Jun 17, 2026
May 22, 2021
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to redirect a user to an undesired web page. This vulnerability is due to improper input validation o...Show more
A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to redirect a user to an undesired web page. This vulnerability is due to improper input validation of the URL parameters in an HTTP request that is sent to an affected system. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to cause the interface to redirect the user to a specific, malicious URL. This type of vulnerability is known as an open redirect and is used in phishing attacks that get users to unknowingly visit malicious sites.Show less
1Prometheus
1Prometheus
Jun 17, 2026
May 19, 2021
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Prometheus is an open-source monitoring system and time series database. In 2.23.0, Prometheus changed its default UI to the New ui. To ensure a seamless transition, the URL's prefixed by /new redirect to /. Due to a bug...Show more
Prometheus is an open-source monitoring system and time series database. In 2.23.0, Prometheus changed its default UI to the New ui. To ensure a seamless transition, the URL's prefixed by /new redirect to /. Due to a bug in the code, it is possible for an attacker to craft an URL that can redirect to any other URL, in the /new endpoint. If a user visits a prometheus server with a specially crafted address, they can be redirected to an arbitrary URL. The issue was patched in the 2.26.1 and 2.27.1 releases. In 2.28.0, the /new endpoint will be removed completely. The workaround is to disable access to /new via a reverse proxy in front of Prometheus.Show less
1Smartstore
1Smartstorenet
Jun 17, 2026
May 19, 2021
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Smartstore (aka SmartStoreNET) before 4.1.0 allows CommonController.ClearCache, ClearDatabaseCache, RestartApplication, and ScheduleTaskController.Edit open redirect.