CWE-601
1,576 CVEs • Abstraction: Base • Likelihood of Exploit: Low
URL Redirection to Untrusted Site ('Open Redirect')
A web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a Redirect. This simplifies phishing attacks.
CVEs (1,576)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In Apache HTTP server 2.4.0 to 2.4.39, Redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an unexpected URL within the request URL. |
An issue was discovered in PRiSE adAS 1.7.0. The OPENSSO module does not properly check the goto parameter, leading to an open redirect that leaks the session cookie. |
3Canonical DebianSpip3Debian Linux SpipUbuntu LinuxJun 17, 2026 Sep 17, 2019 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 SPIP before 3.1.11 and 3.2 before 3.2.5 mishandles redirect URLs in ecrire/inc/headers.php with a %0D, %0A, or %20 character. |
Open redirect vulnerability in SHIRASAGI v1.7.0 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. |
1Fujixerox 2Apeosware Management Suite Apeosware Management Suite 2Jun 17, 2026 Sep 12, 2019 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 Open redirect vulnerability in ApeosWare Management Suite Ver.1.4.0.18 and earlier, and ApeosWare Management Suite 2 Ver.2.1.2.4 and earlier allow remote attackers to redirect users to arbitrary web sites and conduct phi...Show more |
Open redirect vulnerability in Cybozu Garoon 4.0.0 to 4.10.2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the application 'Scheduler'. |
2Debian Wordpress2Debian Linux WordpressJun 17, 2026 Sep 11, 2019 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 In WordPress before 5.2.3, validation and sanitization of a URL in wp_validate_redirect in wp-includes/pluggable.php could lead to an open redirect if a provided URL path does not start with a forward slash. |
An issue was discovered in Alfresco Community Edition versions below 5.2.6, 6.0.N and 6.1.N. The Alfresco Share application is vulnerable to an Open Redirect attack via a crafted POST request. By manipulating the POST pa...Show more |
1Login Or Logout Menu Item Project 1Login Or Logout Menu Item Jun 17, 2026 Aug 30, 2019 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 The login-or-logout-menu-item plugin before 1.2.0 for WordPress has no requirement for lolmi_save_settings authentication. |
1Webcraftic 1Simple 301 Redirects Jun 17, 2026 Aug 30, 2019 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 The simple-301-redirects-addon-bulk-uploader plugin through 1.2.4 for WordPress has no requirement for authentication for action=bulk301export or action=bulk301clearlist. |
1Wpexpertdeveloper 1Wp Private Content Plus Jun 17, 2026 Aug 30, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The wp-private-content-plus plugin before 2.0 for WordPress has no protection against option changes via save_settings_page and other save_ functions. |
1Components For Wp Bakery Page Builder Project 1Components For Wp Bakery Page Builder Jun 17, 2026 Aug 29, 2019 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 The nd-shortcodes plugin before 6.0 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting. |
1Webcraftic 1Simple 301 Redirects Addon Bulk Uploader Jun 17, 2026 Aug 29, 2019 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 The simple-301-redirects-addon-bulk-uploader plugin before 1.2.5 for WordPress has no protection against 301 redirect rule injection via a CSV file. |
1Learning Courses Project 1Learning Courses Jun 17, 2026 Aug 29, 2019 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 The nd-learning plugin before 4.8 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting. |
The nd-booking plugin before 2.5 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting. |
1Travel Management Project 1Travel Management Jun 17, 2026 Aug 29, 2019 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 The nd-travel plugin before 1.7 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting. |
1Donations Project 1Donations Jun 17, 2026 Aug 29, 2019 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 The nd-donations plugin before 1.4 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting. |
The authentication applet in Watchguard Fireware 11.11 Operating System has reflected XSS (this can also cause an open redirect). |
All versions of the HTTPie package prior to version 1.0.3 are vulnerable to Open Redirect that allows an attacker to write an arbitrary file with supplied filename and content to the current directory, by redirecting a r...Show more |
Search Guard Kibana Plugin versions before 5.6.8-7 and before 6.x.y-12 had an issue that an attacker can redirect the user to a potentially malicious site upon Kibana login. |