← Back
CWE-601

1,689 CVEs • Abstraction: Base • Likelihood of Exploit: Low

URL Redirection to Untrusted Site ('Open Redirect')

A web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a Redirect. This simplifies phishing attacks.

JSON object

Loading...

CVEs (1,689)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Git Scm
1Git
May 13, 2026
Oct 5, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL can result in any program that exists on the victim's machine being executed. Such a URL could be plac...Show more
A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL can result in any program that exists on the victim's machine being executed. Such a URL could be placed in the .gitmodules file of a malicious project, and an unsuspecting victim could be tricked into running "git clone --recurse-submodules" to trigger the vulnerability.Show less
2Cloudfoundry
Pivotal
2Cf Release
Routing Release
May 13, 2026
Oct 4, 2017
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
In Cloud Foundry router routing-release all versions prior to v0.163.0 and cf-release all versions prior to v274, in some applications, it is possible to append a combination of characters to the URL that will allow for...Show more
In Cloud Foundry router routing-release all versions prior to v0.163.0 and cf-release all versions prior to v274, in some applications, it is possible to append a combination of characters to the URL that will allow for an open redirect. An attacker could exploit this as a phishing attack to gain access to user credentials or other sensitive data. NOTE: 274 resolves the vulnerability but has a serious bug that is fixed in 275.Show less
1Opentext
2Documentum Administrator
Documentum Webtop
May 13, 2026
Sep 28, 2017
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Multiple open redirect vulnerabilities in OpenText Documentum Webtop 6.8.0160.0073 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a (1) URL in the startat parameter to xd...Show more
Multiple open redirect vulnerabilities in OpenText Documentum Webtop 6.8.0160.0073 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a (1) URL in the startat parameter to xda/help/en/default.htm or (2) /%09/ (slash encoded horizontal tab slash) followed by a domain in the redirectUrl parameter to xda/component/virtuallinkconnect.Show less
1Opentext
2Documentum Administrator
Documentum Webtop
May 13, 2026
Sep 28, 2017
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Multiple open redirect vulnerabilities in OpenText Documentum Administrator 7.2.0180.0055 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a (1) URL in the startat paramete...Show more
Multiple open redirect vulnerabilities in OpenText Documentum Administrator 7.2.0180.0055 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a (1) URL in the startat parameter to xda/help/en/default.htm or (2) /%09/ (slash encoded horizontal tab slash) followed by a domain in the redirectUrl parameter to xda/component/virtuallinkconnect.Show less
1Xceedium
1Xsuite
May 13, 2026
Sep 25, 2017
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Open redirect vulnerability in Xsuite 2.4.4.5 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirurl parameter.
1Wordpress
1Wordpress
May 13, 2026
Sep 23, 2017
N/A· v4
5.4 MEDIUM· v3
4.9 MEDIUM· v2
Before version 4.8.2, WordPress was susceptible to an open redirect attack in wp-admin/edit-tag-form.php and wp-admin/user-edit.php.
1Joomla
1Joomla
May 13, 2026
Sep 20, 2017
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Open redirect vulnerability in Joomla! CMS 3.0.0 through 3.4.1.
1Phpbb
1Phpbb
May 13, 2026
Sep 19, 2017
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Open redirect vulnerability in phpBB before 3.0.14 and 3.1.x before 3.1.4 allows remote attackers to redirect users of Google Chrome to arbitrary web sites and conduct phishing attacks via unspecified vectors.
1Fedoraproject
1Python Fedora
May 13, 2026
Sep 14, 2017
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
python-fedora 0.8.0 and lower is vulnerable to an open redirect resulting in loss of CSRF protection
2Debian
Drupal
2Debian Linux
Drupal
May 13, 2026
Sep 13, 2017
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Open redirect vulnerability in URL-related API functions in Drupal 6.x before 6.35 and 7.x before 7.35 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving t...Show more
Open redirect vulnerability in URL-related API functions in Drupal 6.x before 6.35 and 7.x before 7.35 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving the "//" initial sequence.Show less
2Debian
Drupal
2Debian Linux
Drupal
May 13, 2026
Sep 13, 2017
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Open redirect vulnerability in Drupal 6.x before 6.35 and 7.x before 7.35 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the destination parameter.
1Ellucian
1Banner Student
May 13, 2026
Sep 11, 2017
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Open redirect vulnerability in Ellucian (formerly SunGard) Banner Student 8.5.1.2 through 8.7 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in an unspecified para...Show more
Open redirect vulnerability in Ellucian (formerly SunGard) Banner Student 8.5.1.2 through 8.7 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in an unspecified parameter.Show less
1Ibm
1Emptoris Sourcing
May 13, 2026
Aug 31, 2017
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
IBM Emptoris Sourcing 9.5 - 10.1.3 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit t...Show more
IBM Emptoris Sourcing 9.5 - 10.1.3 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 128177.Show less
1Ibm
1Emptoris Sourcing
May 13, 2026
Aug 31, 2017
N/A· v4
5.4 MEDIUM· v3
4.9 MEDIUM· v2
IBM Emptoris Sourcing 9.5 - 10.1.3 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit t...Show more
IBM Emptoris Sourcing 9.5 - 10.1.3 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 128174.Show less
1Crushftp
1Crushftp
May 13, 2026
Aug 30, 2017
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
CrushFTP before 7.8.0 and 8.x before 8.2.0 has a redirect vulnerability.
1Ibm
1Curam Social Program Management
May 13, 2026
Aug 29, 2017
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
IBM Curam Social Program Management 6.0, 6.1, 6.2, and 7.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote...Show more
IBM Curam Social Program Management 6.0, 6.1, 6.2, and 7.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 123670.Show less
1Ibm
6Security Access Manager
Security Access Manager For MobileSecurity Access Manager For Web+3 more
May 13, 2026
Aug 29, 2017
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
IBM Security Access Manager 6.1, 7.0, 8.0, and 9.0 e-community configurations may be affected by a redirect vulnerability. ECSSO Master Authentication can redirect to a server not participating in an e-community domain....Show more
IBM Security Access Manager 6.1, 7.0, 8.0, and 9.0 e-community configurations may be affected by a redirect vulnerability. ECSSO Master Authentication can redirect to a server not participating in an e-community domain. IBM X-Force ID: 128687.Show less
2Adobe
Redhat
5Enterprise Linux
Enterprise Linux DesktopEnterprise Linux Workstation+2 more
May 13, 2026
Aug 11, 2017
N/A· v4
7.4 HIGH· v3
4.3 MEDIUM· v2
Adobe Flash Player versions 26.0.0.137 and earlier have a security bypass vulnerability that leads to information disclosure when performing URL redirect.
1Ibm
2Emptoris Strategic Supply Management
Emptoris Supplier Lifecycle Management
May 13, 2026
Aug 9, 2017
N/A· v4
5.4 MEDIUM· v3
4.9 MEDIUM· v2
IBM Emptoris Supplier Lifecycle Management 10.0.x and 10.1.x could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remot...Show more
IBM Emptoris Supplier Lifecycle Management 10.0.x and 10.1.x could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 128173.Show less
1Ibm
2Emptoris Strategic Supply Management
Emptoris Supplier Lifecycle Management
May 13, 2026
Aug 9, 2017
N/A· v4
5.4 MEDIUM· v3
4.9 MEDIUM· v2
IBM Emptoris Supplier Lifecycle Management 10.0.x and 10.1.x could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remot...Show more
IBM Emptoris Supplier Lifecycle Management 10.0.x and 10.1.x could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 118836.Show less