CWE-601
1,578 CVEs • Abstraction: Base • Likelihood of Exploit: Low
URL Redirection to Untrusted Site ('Open Redirect')
A web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a Redirect. This simplifies phishing attacks.
CVEs (1,578)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Blogengine.net 3.3.8.0 and earlier is vulnerable to Open Redirect. |
When choosing a site-isolated process for a document loaded from a data: URL that was the result of a redirect, Firefox would load that document in the same process as the site that issued the redirect. This bypassed the...Show more |
An open redirect vulnerability exists in the /preauth Servlet in Zimbra Collaboration Suite through 9.0 and 8.8.15. To exploit the vulnerability, an attacker would need to have obtained a valid zimbra auth token or a val...Show more |
1Adobe 2Experience Manager Experience Manager Cloud ServiceJun 17, 2026 Jun 15, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Adobe Experience Manager versions 6.5.16.0 (and earlier) is affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to red...Show more |
Open redirect vulnerability in the Layout module's SEO configuration in Liferay Portal 7.4.3.70 through 7.4.3.76, and Liferay DXP 7.4 update 70 through 76 allows remote attackers to redirect users to arbitrary external U...Show more |
Keystone is a content management system for Node.JS. There is an open redirect in the `@keystone-6/auth` package versions 7.0.0 and prior, where the redirect leading `/` filter can be bypassed. Users may be redirected to...Show more |
1Createit 1Ultimate Gdpr & Ccpa Compliance Toolkit Jun 17, 2026 Jun 7, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 The Ultimate GDPR & CCPA plugin for WordPress is vulnerable to unauthenticated settings import and export via the export_settings & import_settings functions in versions up to, and including, 2.4. This makes it possible...Show more |
Landscape allowed URLs which caused open redirection. |
1Woocommerce 1Sidebar Manager To Woosidebars Converter Nov 21, 2024 Jun 5, 2023 N/A· v4 6.1 MEDIUM· v3 5.0 MEDIUM· v2 A vulnerability, which was classified as problematic, was found in WooSidebars Sidebar Manager Converter Plugin up to 1.1.1 on WordPress. This affects the function process_request of the file classes/class-woosidebars-sb...Show more |
A vulnerability, which was classified as problematic, has been found in WooSidebars Plugin up to 1.4.1 on WordPress. Affected by this issue is the function enable_custom_post_sidebars of the file classes/class-woo-sideba...Show more |
1Woocommerce 1Wooframework Tweaks Nov 21, 2024 Jun 5, 2023 N/A· v4 6.1 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability classified as problematic was found in WooFramework Tweaks Plugin up to 1.0.1 on WordPress. Affected by this vulnerability is the function admin_screen_logic of the file wooframework-tweaks.php. The manip...Show more |
1Accesspressthemes 1Frontend Post Wordpress Plugin Jun 17, 2026 Jun 5, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The Frontend Post WordPress Plugin WordPress plugin through 2.8.4 does not validate an attribute of one of its shortcode, which could allow users with a role as low as contributor to add a malicious shortcode to a page/p...Show more |
1Woocommerce 1Wooframework Branding Nov 21, 2024 Jun 5, 2023 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability classified as problematic has been found in WooFramework Branding Plugin up to 1.0.1 on WordPress. Affected is the function admin_screen_logic of the file wooframework-branding.php. The manipulation of th...Show more |
Using a redirect embedded into <code>sourceMappingUrls</code> could allow for navigation to external protocol links in sandboxed iframes without <code>allow-top-navigation-to-custom-protocols</code>. This vulnerability a...Show more |
1Mozilla 3Firefox Firefox EsrThunderbirdJun 17, 2026 Jun 2, 2023 N/A· v4 8.1 HIGH· v3 N/A· v2 After downloading a Windows <code>.url</code> shortcut from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from the operating system. This also had the potenti...Show more |
In JetBrains TeamCity before 2023.05 open redirect during oAuth configuration was possible |
Avaya IX Workforce Engagement v15.2.7.1195 - CWE-601: URL Redirection to Untrusted Site ('Open Redirect') |
An issue was discovered in Joomla! 4.2.0 through 4.3.1. Lack of input validation caused an open redirect and XSS issue within the new mfa selection screen. |
1Vmware 4Cloud Foundation Identity ManagerIdentity Manager Connector+1 moreJun 17, 2026 May 30, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 VMware Workspace ONE Access and VMware Identity Manager contain an insecure redirect vulnerability. An unauthenticated malicious actor may be able to redirect a victim to an attacker controlled domain due to improper pat...Show more |
Open redirect vulnerability in Tornado versions 6.3.1 and earlier allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having user access a specially craft...Show more |