← Back
CWE-601

1,576 CVEs • Abstraction: Base • Likelihood of Exploit: Low

URL Redirection to Untrusted Site ('Open Redirect')

A web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a Redirect. This simplifies phishing attacks.

JSON object

Loading...

CVEs (1,576)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apache
1Http Server
Jun 17, 2026
Sep 25, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
In Apache HTTP server 2.4.0 to 2.4.39, Redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an unexpected URL within the request URL.
1Prise
1Adas
Jun 17, 2026
Sep 20, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
An issue was discovered in PRiSE adAS 1.7.0. The OPENSSO module does not properly check the goto parameter, leading to an open redirect that leaks the session cookie.
3Canonical
DebianSpip
3Debian Linux
SpipUbuntu Linux
Jun 17, 2026
Sep 17, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
SPIP before 3.1.11 and 3.2 before 3.2.5 mishandles redirect URLs in ecrire/inc/headers.php with a %0D, %0A, or %20 character.
1Ss Proj
1Shirasagi
Jun 17, 2026
Sep 12, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Open redirect vulnerability in SHIRASAGI v1.7.0 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
1Fujixerox
2Apeosware Management Suite
Apeosware Management Suite 2
Jun 17, 2026
Sep 12, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Open redirect vulnerability in ApeosWare Management Suite Ver.1.4.0.18 and earlier, and ApeosWare Management Suite 2 Ver.2.1.2.4 and earlier allow remote attackers to redirect users to arbitrary web sites and conduct phi...Show more
Open redirect vulnerability in ApeosWare Management Suite Ver.1.4.0.18 and earlier, and ApeosWare Management Suite 2 Ver.2.1.2.4 and earlier allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.Show less
1Cybozu
1Garoon
Jun 17, 2026
Sep 12, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Open redirect vulnerability in Cybozu Garoon 4.0.0 to 4.10.2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the application 'Scheduler'.
2Debian
Wordpress
2Debian Linux
Wordpress
Jun 17, 2026
Sep 11, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
In WordPress before 5.2.3, validation and sanitization of a URL in wp_validate_redirect in wp-includes/pluggable.php could lead to an open redirect if a provided URL path does not start with a forward slash.
1Alfresco
1Alfresco
Jun 17, 2026
Sep 6, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
An issue was discovered in Alfresco Community Edition versions below 5.2.6, 6.0.N and 6.1.N. The Alfresco Share application is vulnerable to an Open Redirect attack via a crafted POST request. By manipulating the POST pa...Show more
An issue was discovered in Alfresco Community Edition versions below 5.2.6, 6.0.N and 6.1.N. The Alfresco Share application is vulnerable to an Open Redirect attack via a crafted POST request. By manipulating the POST parameters, an attacker can redirect a victim to a malicious website over any protocol the attacker desires (e.g.,http, https, ftp, smb, etc.).Show less
1Login Or Logout Menu Item Project
1Login Or Logout Menu Item
Jun 17, 2026
Aug 30, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
The login-or-logout-menu-item plugin before 1.2.0 for WordPress has no requirement for lolmi_save_settings authentication.
1Webcraftic
1Simple 301 Redirects
Jun 17, 2026
Aug 30, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
The simple-301-redirects-addon-bulk-uploader plugin through 1.2.4 for WordPress has no requirement for authentication for action=bulk301export or action=bulk301clearlist.
1Wpexpertdeveloper
1Wp Private Content Plus
Jun 17, 2026
Aug 30, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The wp-private-content-plus plugin before 2.0 for WordPress has no protection against option changes via save_settings_page and other save_ functions.
1Components For Wp Bakery Page Builder Project
1Components For Wp Bakery Page Builder
Jun 17, 2026
Aug 29, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
The nd-shortcodes plugin before 6.0 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting.
1Webcraftic
1Simple 301 Redirects Addon Bulk Uploader
Jun 17, 2026
Aug 29, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
The simple-301-redirects-addon-bulk-uploader plugin before 1.2.5 for WordPress has no protection against 301 redirect rule injection via a CSV file.
1Learning Courses Project
1Learning Courses
Jun 17, 2026
Aug 29, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
The nd-learning plugin before 4.8 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting.
1Booking Project
1Booking
Jun 17, 2026
Aug 29, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
The nd-booking plugin before 2.5 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting.
1Travel Management Project
1Travel Management
Jun 17, 2026
Aug 29, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
The nd-travel plugin before 1.7 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting.
1Donations Project
1Donations
Jun 17, 2026
Aug 29, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
The nd-donations plugin before 1.4 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting.
1Watchguard
1Fireware
Nov 21, 2024
Aug 23, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
The authentication applet in Watchguard Fireware 11.11 Operating System has reflected XSS (this can also cause an open redirect).
1Httpie
1Httpie
Jun 17, 2026
Aug 23, 2019
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
All versions of the HTTPie package prior to version 1.0.3 are vulnerable to Open Redirect that allows an attacker to write an arbitrary file with supplied filename and content to the current directory, by redirecting a r...Show more
All versions of the HTTPie package prior to version 1.0.3 are vulnerable to Open Redirect that allows an attacker to write an arbitrary file with supplied filename and content to the current directory, by redirecting a request from HTTP to a crafted URL pointing to a server in his or hers control.Show less
1Search Guard
1Search Guard
Jun 17, 2026
Aug 23, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Search Guard Kibana Plugin versions before 5.6.8-7 and before 6.x.y-12 had an issue that an attacker can redirect the user to a potentially malicious site upon Kibana login.