← Back
CWE-601

1,576 CVEs • Abstraction: Base • Likelihood of Exploit: Low

URL Redirection to Untrusted Site ('Open Redirect')

A web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a Redirect. This simplifies phishing attacks.

JSON object

Loading...

CVEs (1,576)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Debian
FedoraprojectWordpress
3Debian Linux
FedoraWordpress
Jun 17, 2026
Jun 12, 2020
N/A· v4
5.7 MEDIUM· v3
4.9 MEDIUM· v2
In affected versions of WordPress, due to an issue in wp_validate_redirect() and URL sanitization, an arbitrary external link can be crafted leading to unintended/open redirect when clicked. This has been patched in vers...Show more
In affected versions of WordPress, due to an issue in wp_validate_redirect() and URL sanitization, an arbitrary external link can be crafted leading to unintended/open redirect when clicked. This has been patched in version 5.4.2, along with all the previously affected versions via a minor release (5.3.4, 5.2.7, 5.1.6, 5.0.10, 4.9.15, 4.8.14, 4.7.18, 4.6.19, 4.5.22, 4.4.23, 4.3.24, 4.2.28, 4.1.31, 4.0.31, 3.9.32, 3.8.34, 3.7.34).Show less
1Sap
1Fiori
Jun 17, 2026
Jun 10, 2020
N/A· v4
5.4 MEDIUM· v3
4.9 MEDIUM· v2
SAP Fiori for SAP S/4HANA, versions - 100, 200, 300, 400, allows an attacker to redirect users to a malicious site due to insufficient URL validation, leading to URL Redirection.
1Microsoft
2Sharepoint Enterprise Server
Sharepoint Server
Jun 17, 2026
Jun 9, 2020
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
An open redirect vulnerability exists in Microsoft SharePoint that could lead to spoofing.To exploit the vulnerability, an attacker could send a link that has a specially crafted URL and convince the user to click the li...Show more
An open redirect vulnerability exists in Microsoft SharePoint that could lead to spoofing.To exploit the vulnerability, an attacker could send a link that has a specially crafted URL and convince the user to click the link, aka 'SharePoint Open Redirect Vulnerability'.Show less
1Microsoft
1Edge
Jun 17, 2026
Jun 9, 2020
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
A spoofing vulnerability exists when theMicrosoft Edge (Chromium-based) in IE Mode improperly handles specific redirects, aka 'Microsoft Edge (Chromium-based) in IE Mode Spoofing Vulnerability'.
1Mediawiki
1Mediawiki
Jun 17, 2026
Jun 2, 2020
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
resources/src/mediawiki.page.ready/ready.js in MediaWiki before 1.35 allows remote attackers to force a logout and external redirection via HTML content in a MediaWiki page.
1Verbb
1Knock Knock
Jun 17, 2026
May 25, 2020
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
The Knock Knock plugin before 1.2.8 for Craft CMS allows malicious redirection.
1Microsoft
1Edge
Jun 17, 2026
May 21, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
A spoofing vulnerability exists when Microsoft Edge does not properly parse HTTP content, aka 'Microsoft Edge Spoofing Vulnerability'.
1Rcos
1Submitty
Jun 17, 2026
May 16, 2020
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Submitty through 20.04.01 has an open redirect via authentication/login?old= during an invalid login attempt.
1Pivotal Software
1Concourse
Jun 17, 2026
May 14, 2020
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Pivotal Concourse, most versions prior to 6.0.0, allows redirects to untrusted websites in its login flow. A remote unauthenticated attacker could convince a user to click on a link using the OAuth redirect link with an...Show more
Pivotal Concourse, most versions prior to 6.0.0, allows redirects to untrusted websites in its login flow. A remote unauthenticated attacker could convince a user to click on a link using the OAuth redirect link with an untrusted website and gain access to that user's access token in Concourse. (This issue is similar to, but distinct from, CVE-2018-15798.)Show less
1Paloaltonetworks
1Pan Os
Jun 17, 2026
May 13, 2020
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
An open redirection vulnerability in the GlobalProtect component of Palo Alto Networks PAN-OS allows an attacker to specify an arbitrary redirection target away from the trusted GlobalProtect gateway. If the user then su...Show more
An open redirection vulnerability in the GlobalProtect component of Palo Alto Networks PAN-OS allows an attacker to specify an arbitrary redirection target away from the trusted GlobalProtect gateway. If the user then successfully authenticates it will cause them to access an unexpected and potentially malicious website. This issue affects: PAN-OS 7.1 versions earlier than 7.1.26; PAN-OS 8.0 versions earlier than 8.0.14.Show less
1Dkd
1Direct Mail
Jun 17, 2026
May 13, 2020
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
The direct_mail extension through 5.2.3 for TYPO3 has an Open Redirect via jumpUrl.
1Oauth2 Proxy Project
1Oauth2 Proxy
Jun 17, 2026
May 7, 2020
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
In OAuth2 Proxy before 5.1.1, there is an open redirect vulnerability. Users can provide a redirect address for the proxy to send the authenticated user to at the end of the authentication flow. This is expected to be th...Show more
In OAuth2 Proxy before 5.1.1, there is an open redirect vulnerability. Users can provide a redirect address for the proxy to send the authenticated user to at the end of the authentication flow. This is expected to be the original URL that the user was trying to access. This redirect URL is checked within the proxy and validated before redirecting the user to prevent malicious actors providing redirects to potentially harmful sites. However, by crafting a redirect URL with HTML encoded whitespace characters the validation could be bypassed and allow a redirect to any URL provided. This has been patched in 5.1.1.Show less
1Cisco
1Secure Firewall Management Center
Jun 17, 2026
May 6, 2020
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
A vulnerability in the web interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. The vulnerability is due to improper in...Show more
A vulnerability in the web interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. The vulnerability is due to improper input validation of HTTP request parameters. An attacker could exploit this vulnerability by intercepting and modifying an HTTP request from a user. A successful exploit could allow the attacker to redirect the user to a specific malicious web page.Show less
1Cisco
1Content Security Management Appliance
Jun 17, 2026
May 6, 2020
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Multiple vulnerabilities in the web-based GUI of Cisco AsyncOS Software for Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. Th...Show more
Multiple vulnerabilities in the web-based GUI of Cisco AsyncOS Software for Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. The vulnerabilities are due to improper input validation of the parameters of an HTTP request. An attacker could exploit these vulnerabilities by intercepting an HTTP request and modifying it to redirect a user to a specific malicious URL. A successful exploit could allow the attacker to redirect a user to a malicious web page or to obtain sensitive browser-based information. This type of attack is commonly referred to as an open redirect attack and is used in phishing attacks to get users to unknowingly visit malicious sites.Show less
2Fedoraproject
Go Macaron
2Fedora
Macaron
Jun 17, 2026
May 5, 2020
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
macaron before 1.3.7 has an open redirect in the static handler, as demonstrated by the http://127.0.0.1:4000//example.com/ URL.
1Glpi Project
1Glpi
Jun 17, 2026
May 5, 2020
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
In GLPI before version 9.4.6, there is a vulnerability that allows bypassing the open redirect protection based which is based on a regexp. This is fixed in version 9.4.6.
1Rsa
1Archer
Jun 17, 2026
May 4, 2020
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
RSA Archer, versions prior to 6.7 P1 (6.7.0.1), contain a URL redirection vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to redirect application users to arbitrary web URLs...Show more
RSA Archer, versions prior to 6.7 P1 (6.7.0.1), contain a URL redirection vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to redirect application users to arbitrary web URLs by tricking the victim users to click on maliciously crafted links. The vulnerability could be used to conduct phishing attacks that cause users to unknowingly visit malicious sites.Show less
1Hcltech
1Connections
Jun 17, 2026
May 1, 2020
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
HCL Connections v5.5, v6.0, and v6.5 contains an open redirect vulnerability which could be exploited by an attacker to conduct phishing attacks.
1Sourcegraph
1Sourcegraph
Jun 17, 2026
Apr 30, 2020
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Sourcegraph before 3.15.1 has a vulnerable authentication workflow because of improper validation in the SafeRedirectURL method in cmd/frontend/auth/redirect.go, such as for the //foo//example.com substring.
1Prestashop
1Prestashop
Jun 17, 2026
Apr 20, 2020
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
In PrestaShop between versions 1.7.6.0 and 1.7.6.5, there is an open redirection when using back parameter. The impacts can be many, and vary from the theft of information and credentials to the redirection to malicious...Show more
In PrestaShop between versions 1.7.6.0 and 1.7.6.5, there is an open redirection when using back parameter. The impacts can be many, and vary from the theft of information and credentials to the redirection to malicious websites containing attacker-controlled content, which in some cases even cause XSS attacks. So even though an open redirection might sound harmless at first, the impacts of it can be severe should it be exploitable. The problem is fixed in 1.7.6.5Show less