← Back
CWE-601

1,576 CVEs • Abstraction: Base • Likelihood of Exploit: Low

URL Redirection to Untrusted Site ('Open Redirect')

A web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a Redirect. This simplifies phishing attacks.

JSON object

Loading...

CVEs (1,576)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1Sterling B2b Integrator
Jun 17, 2026
Feb 24, 2020
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site,...Show more
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 167878.Show less
4Debian
FedoraprojectOpenidc+1 more
4Debian Linux
FedoraLeap+1 more
Jun 17, 2026
Feb 20, 2020
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
A flaw was found in mod_auth_openidc before version 2.4.1. An open redirect issue exists in URLs with a slash and backslash at the beginning.
1Netsweeper
1Netsweeper
Nov 21, 2024
Feb 19, 2020
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Open redirect vulnerability in remotereporter/load_logfiles.php in Netsweeper before 4.0.5 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the url parameter.
1Lenovo
2Ez Media & Backup Center Ix2 Dl Firmware
Ez Media & Backup Center Ix2 Firmware
Jun 17, 2026
Feb 14, 2020
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
A vulnerability in the web interface of Lenovo EZ Media & Backup Center, ix2 & ix2-dl version 4.1.406.34763 and prior could allow an unauthenticated, remote attacker to redirect a user to an untrusted web page.
1Telaen Project
1Telaen
Nov 21, 2024
Feb 3, 2020
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Open Redirection Vulnerability in the redir.php script in Telaen before 1.3.1 allows remote attackers to redirect victims to arbitrary websites via a crafted URL.
1Oauth2 Proxy Project
1Oauth2 Proxy
Jun 17, 2026
Jan 30, 2020
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
OAuth2 Proxy before 5.0 has an open redirect vulnerability. Authentication tokens could be silently harvested by an attacker. This has been patched in version 5.0.
1United Security Providers
1Secure Entry Server
Nov 21, 2024
Jan 28, 2020
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Secure Entry Server before 4.7.0 contains a URI Redirection vulnerability which could allow remote attackers to conduct phishing attacks due to HSP_AbsoluteRedirects being disabled by default.
1Ibm
1Security Secret Server
Jun 17, 2026
Jan 28, 2020
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
IBM Security Secret Server 10.7 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this...Show more
IBM Security Secret Server 10.7 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 170001.Show less
1Plone
1Plone
Jun 17, 2026
Jan 23, 2020
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
An open redirect on the login form (and possibly other places) in Plone 4.0 through 5.2.1 allows an attacker to craft a link to a Plone Site that, when followed, and possibly after login, will redirect to an attacker's s...Show more
An open redirect on the login form (and possibly other places) in Plone 4.0 through 5.2.1 allows an attacker to craft a link to a Plone Site that, when followed, and possibly after login, will redirect to an attacker's site.Show less
1Tencent
1Wechat
Jun 17, 2026
Jan 7, 2020
N/A· v4
5.4 MEDIUM· v3
5.8 MEDIUM· v2
This vulnerability allows remote attackers redirect users to an external resource on affected installations of Tencent WeChat Prior to 7.0.9. User interaction is required to exploit this vulnerability in that the target...Show more
This vulnerability allows remote attackers redirect users to an external resource on affected installations of Tencent WeChat Prior to 7.0.9. User interaction is required to exploit this vulnerability in that the target must be within a chat session together with the attacker. The specific flaw exists within the parsing of a users profile. The issue lies in the failure to properly validate a users name. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-9302.Show less
1Chamilo
1Chamilo Lms
Nov 21, 2024
Jan 4, 2020
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Chamilo LMS through 1.9.10.2 allows a link_goto.php?link_url= open redirect, a related issue to CVE-2015-5503.
1Mybb
1Mybb
Jun 17, 2026
Jan 2, 2020
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
MyBB before 1.8.22 allows an open redirect on login.
1Yahoo
1Athenz
Jun 17, 2026
Dec 26, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Open redirect vulnerability in Athenz v1.8.24 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a specially crafted page.
1Sixapart
1Movable Type
Jun 17, 2026
Dec 26, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Open redirect vulnerability in Movable Type series Movable Type 7 r.4602 (7.1.3) and earlier (Movable Type 7), Movable Type 6.5.0 and 6.5.1 (Movable Type 6.5), Movable Type 6.3.9 and earlier (Movable Type 6.3.x, 6.2.x, 6...Show more
Open redirect vulnerability in Movable Type series Movable Type 7 r.4602 (7.1.3) and earlier (Movable Type 7), Movable Type 6.5.0 and 6.5.1 (Movable Type 6.5), Movable Type 6.3.9 and earlier (Movable Type 6.3.x, 6.2.x, 6.1.x, 6.0.x), Movable Type Advanced 7 r.4602 (7.1.3) and earlier (Movable Type 7), Movable Type Advanced 6.5.0 and 6.5.1 (Movable Type 6.5), Movable Type Advanced 6.3.9 and earlier (Movable Type 6.3.x, 6.2.x, 6.1.x, 6.0.x), Movable Type Premium 1.24 and earlier (Movable Type Premium), and Movable Type Premium (Advanced Edition) 1.24 and earlier (Movable Type Premium) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a specially crafted URL.Show less
1Ricoh
1Limedio
Jun 17, 2026
Dec 26, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Open redirect vulnerability in Library Information Management System LIMEDIO all versions allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a specially crafted URL.
1Alfasado
1Powercms
Jun 17, 2026
Dec 26, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Open redirect vulnerability in PowerCMS 5.12 and earlier (PowerCMS 5.x), 4.42 and earlier (PowerCMS 4.x), and 3.293 and earlier (PowerCMS 3.x) allows remote attackers to redirect users to arbitrary web sites and conduct...Show more
Open redirect vulnerability in PowerCMS 5.12 and earlier (PowerCMS 5.x), 4.42 and earlier (PowerCMS 4.x), and 3.293 and earlier (PowerCMS 3.x) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a specially crafted URL.Show less
1Crushftp
1Crushftp
Nov 21, 2024
Dec 26, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
CrushFTP through 8.3.0 is vulnerable to credentials theft via URL redirection.
1Zohocorp
1Manageengine Adselfservice Plus
Jun 17, 2026
Dec 18, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
An open redirect vulnerability was discovered in Zoho ManageEngine ADSelfService Plus 5.x before 5809 that allows attackers to force users who click on a crafted link to be sent to a specified external site.
1Apple
1Shazam
Jun 17, 2026
Dec 18, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
An issue existed in the parsing of URL schemes. This issue was addressed with improved URL validation. This issue is fixed in Shazam Android App Version 9.25.0, Shazam iOS App Version 12.11.0. Processing a maliciously cr...Show more
An issue existed in the parsing of URL schemes. This issue was addressed with improved URL validation. This issue is fixed in Shazam Android App Version 9.25.0, Shazam iOS App Version 12.11.0. Processing a maliciously crafted URL may lead to an open redirect.Show less
1Zulip
1Zulip Server
Jun 17, 2026
Dec 18, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
The image thumbnailing handler in Zulip Server versions 1.9.0 to before 2.0.8 allowed an open redirect that was visible to logged-in users.