← Back
CWE-601

1,576 CVEs • Abstraction: Base • Likelihood of Exploit: Low

URL Redirection to Untrusted Site ('Open Redirect')

A web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a Redirect. This simplifies phishing attacks.

JSON object

Loading...

CVEs (1,576)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Atlassian
1Jira Server
Jun 17, 2026
Aug 23, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
The ChangeSharedFilterOwner resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to attack users, in some cases be able to o...Show more
The ChangeSharedFilterOwner resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to attack users, in some cases be able to obtain a user's Cross-site request forgery (CSRF) token, via a open redirect vulnerability.Show less
1Atlassian
2Jira
Jira Server
Jun 17, 2026
Aug 23, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
The startup.jsp resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to redirect users to a different website which they may...Show more
The startup.jsp resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to redirect users to a different website which they may use as part of performing a phishing attack via an open redirect.Show less
1Cisco
1Webex Meetings Server
Jun 17, 2026
Aug 8, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
A vulnerability in the web-based management interface of Cisco Webex Meetings Server Software could allow an unauthenticated, remote attacker to redirect a user to an undesired web page. The vulnerability is due to impro...Show more
A vulnerability in the web-based management interface of Cisco Webex Meetings Server Software could allow an unauthenticated, remote attacker to redirect a user to an undesired web page. The vulnerability is due to improper input validation of the URL parameters in an HTTP request that is sent to an affected device. An attacker could exploit this vulnerability by crafting an HTTP request that could cause the web application to redirect the request to a specified malicious URL. A successful exploit could allow the attacker to redirect a user to a malicious website.Show less
1Jenkins
1Gitlab Oauth
Jun 17, 2026
Aug 7, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
An open redirect vulnerability in Jenkins Gitlab Authentication Plugin 1.4 and earlier in GitLabSecurityRealm.java allows attackers to redirect users to a URL outside Jenkins after successful login.
1Cpanel
1Cpanel
Nov 21, 2024
Aug 5, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
cPanel before 60.0.25 allows an open redirect via /cgi-sys/FormMail-clone.cgi (SEC-162).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 2, 2019
N/A· v4
5.0 MEDIUM· v3
4.0 MEDIUM· v2
cPanel before 64.0.21 allows demo accounts to redirect web traffic (SEC-245).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 2, 2019
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
cPanel before 67.9999.103 allows an open redirect in /unprotected/redirect.html (SEC-300).
1Happypointcard
1Happypoint
Jun 17, 2026
Aug 1, 2019
N/A· v4
8.1 HIGH· v3
5.8 MEDIUM· v2
When processing Deeplink scheme, Happypoint mobile app 6.3.19 and earlier versions doesn't check Deeplink URL correctly. This could lead to javascript code execution, url redirection, sensitive information disclosure. An...Show more
When processing Deeplink scheme, Happypoint mobile app 6.3.19 and earlier versions doesn't check Deeplink URL correctly. This could lead to javascript code execution, url redirection, sensitive information disclosure. An attacker can exploit this issue by enticing an unsuspecting user to open a specific malicious URL.Show less
1Cpanel
1Cpanel
Nov 21, 2024
Aug 1, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
cPanel before 70.0.23 allows an open redirect via the /unprotected/redirect.html endpoint (SEC-392).
1Cpanel
1Cpanel
Jun 17, 2026
Jul 30, 2019
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
cPanel before 78.0.18 offers an open mail relay because of incorrect domain-redirect routing (SEC-483).
1Cpanel
1Cpanel
Nov 21, 2024
Jul 30, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
cPanel before 76.0.8 has an open redirect when resetting connections (SEC-462).
1Ash Aio Project
1Ash Aio
Jun 17, 2026
Jul 29, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
ASH-AIO before 2.0.0.3 allows an open redirect.
1Cisco
57Sf200 24 Firmware
Sf200 24fp FirmwareSf200 24p Firmware+54 more
Jun 17, 2026
Jul 17, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
A vulnerability in the web interface of Cisco Small Business 200, 300, and 500 Series Switches software could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. The vulnerability is due...Show more
A vulnerability in the web interface of Cisco Small Business 200, 300, and 500 Series Switches software could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. The vulnerability is due to improper input validation of the parameters of an HTTP request. An attacker could exploit this vulnerability by intercepting a user's HTTP request and modifying it into a request that causes the web interface to redirect the user to a specific malicious URL. This type of vulnerability is known as an open redirect attack and is used in phishing attacks that get users to unknowingly visit malicious sites.Show less
1Cmsmadesimple
1Bable\
Jun 17, 2026
Jul 16, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Babel: Multilingual site Babel All is affected by: Open Redirection. The impact is: Redirection to any URL, which is supplied to redirect.php in a "newurl" parameter. The component is: redirect.php. The attack vector is:...Show more
Babel: Multilingual site Babel All is affected by: Open Redirection. The impact is: Redirection to any URL, which is supplied to redirect.php in a "newurl" parameter. The component is: redirect.php. The attack vector is: The victim must open a link created by an attacker. Attacker may use any legitimate site using Babel to redirect user to a URL of his/her choosing.Show less
1Microsoft
1Asp.net Core
Jun 17, 2026
Jul 15, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
A spoofing vulnerability exists in ASP.NET Core that could lead to an open redirect, aka 'ASP.NET Core Spoofing Vulnerability'.
1Eventum Project
1Eventum
Nov 21, 2024
Jul 5, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
An issue was discovered in Eventum 3.5.0. /htdocs/switch.php has an Open Redirect via the current_page parameter.
1Weseek
1Growi
Jun 17, 2026
Jul 5, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Open redirect vulnerability in GROWI v3.4.6 and earlier allows remote attackersto redirect users to arbitrary web sites and conduct phishing attacks via the process of login.
1Joruri
1Joruri Mail
Jun 17, 2026
Jul 5, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Open redirect vulnerability in Joruri Mail 2.1.4 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
1Dotnetblogengine
1Blogengine.net
Jun 17, 2026
Jul 3, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
BlogEngine.NET 3.3.7.0 allows a Client Side URL Redirect via the ReturnUrl parameter, related to BlogEngine/BlogEngine.Core/Services/Security/Security.cs, login.aspx, and register.aspx.
1Readthedocs
1Read The Docs
Jun 17, 2026
Jul 2, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Read the Docs before 3.5.1 has an Open Redirect if certain user-defined redirects are used. This affects private instances of Read the Docs (in addition to the public readthedocs.org web sites).