← Back
CWE-601

1,576 CVEs • Abstraction: Base • Likelihood of Exploit: Low

URL Redirection to Untrusted Site ('Open Redirect')

A web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a Redirect. This simplifies phishing attacks.

JSON object

Loading...

CVEs (1,576)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microweber
1Microweber
Jun 17, 2026
Jun 29, 2022
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Open Redirect in GitHub repository microweber/microweber prior to 1.2.19.
1Apifest
1Oauth 2.0 Server
Jun 17, 2026
Jun 29, 2022
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
ApiFest OAuth 2.0 Server 0.3.1 does not validate the redirect URI in accordance with RFC 6749 and is susceptible to an open redirector attack. Specifically, it directly sends an authorization code to the redirect URI sub...Show more
ApiFest OAuth 2.0 Server 0.3.1 does not validate the redirect URI in accordance with RFC 6749 and is susceptible to an open redirector attack. Specifically, it directly sends an authorization code to the redirect URI submitted with the authorization request, without checking whether the redirect URI is registered by the client who initiated the request. This allows an attacker to craft a request with a manipulated redirect URI (redirect_uri parameter), which is under the attacker's control, and consequently obtain the leaked authorization code when the server redirects the client to the manipulated redirect URI with an authorization code. NOTE: this is similar to CVE-2019-3778.Show less
1Nagios
1Nagios Xi
Jun 17, 2026
Jun 29, 2022
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
In Nagios XI through 5.8.5, an open redirect vulnerability exists in the login function that could lead to spoofing.
1Dahuasecurity
40Asi7213x T1 Firmware
Asi7213x FirmwareAsi7223x A T1 Firmware+37 more
Jun 17, 2026
Jun 28, 2022
N/A· v4
4.7 MEDIUM· v3
4.0 MEDIUM· v2
If the user enables the https function on the device, an attacker can modify the user’s request data packet through a man-in-the-middle attack ,Injection of a malicious URL in the Host: header of the HTTP Request results...Show more
If the user enables the https function on the device, an attacker can modify the user’s request data packet through a man-in-the-middle attack ,Injection of a malicious URL in the Host: header of the HTTP Request results in a 302 redirect to an attacker-controlled page.Show less
1Web2py
1Web2py
Jun 17, 2026
Jun 27, 2022
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Open redirect vulnerability in web2py versions prior to 2.22.5 allows a remote attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having a user to access a specially crafted URL.
1Habitica
1Habitica
Jun 17, 2026
Jun 22, 2022
N/A· v4
N/A· v3
5.8 MEDIUM· v2
In habitica versions v4.119.0 through v4.232.2 are vulnerable to open redirect via the login page.
1Yuba
1U5cms
Jun 17, 2026
Jun 17, 2022
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
An issue was discovered in u5cms verion 8.3.5 There is a URL redirection vulnerability that can cause a user's browser to be redirected to another site via /loginsave.php.
1Maykinmedia
1Open Forms
Jun 17, 2026
Jun 13, 2022
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Open Forms is an application for creating and publishing smart forms. Prior to versions 1.0.9 and 1.1.1, the cookie consent page in Open Forms contains an open redirect by injecting a `referer` querystring parameter and...Show more
Open Forms is an application for creating and publishing smart forms. Prior to versions 1.0.9 and 1.1.1, the cookie consent page in Open Forms contains an open redirect by injecting a `referer` querystring parameter and failing to validate the value. A malicious actor is able to redirect users to a website under their control, opening them up for phishing attacks. The redirect is initiated by the open forms backend which is a legimate page, making it less obvious to end users they are being redirected to a malicious website. Versions 1.0.9 and 1.1.1 contain patches for this issue. There are no known workarounds avaialble.Show less
1Apache
1Dubbo
Jun 17, 2026
Jun 9, 2022
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
bypass CVE-2021-25640 > In Apache Dubbo prior to 2.6.12 and 2.7.15, the usage of parseURL method will lead to the bypass of the white host check which can cause open redirect or SSRF vulnerability.
1Caddyserver
1Caddy
Jun 17, 2026
Jun 2, 2022
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Caddy v2.4 was discovered to contain an open redirect vulnerability. A remote unauthenticated attacker may exploit this vulnerability to redirect users to arbitrary web URLs by tricking the victim users to click on craft...Show more
Caddy v2.4 was discovered to contain an open redirect vulnerability. A remote unauthenticated attacker may exploit this vulnerability to redirect users to arbitrary web URLs by tricking the victim users to click on crafted links.Show less
1Netapp
1E Series Santricity Os Controller
Jun 17, 2026
Jun 2, 2022
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
E-Series SANtricity OS Controller Software 11.x versions through 11.70.2 are vulnerable to host header injection attacks that could allow an attacker to redirect users to malicious websites.
1Nextauth.js
1Next Auth
Jun 17, 2026
May 21, 2022
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
NextAuth.js (next-auth) is am open source authentication solution for Next.js applications. Prior to versions 3.29.3 and 4.3.3, an open redirect vulnerability is present when the developer is implementing an OAuth 1 prov...Show more
NextAuth.js (next-auth) is am open source authentication solution for Next.js applications. Prior to versions 3.29.3 and 4.3.3, an open redirect vulnerability is present when the developer is implementing an OAuth 1 provider. Versions 3.29.3 and 4.3.3 contain a patch for this issue. The maintainers recommend adding a certain configuration to one's `callbacks` option as a workaround for those unable to upgrade.Show less
1Grafana
1Grafana
Jun 17, 2026
May 20, 2022
N/A· v4
8.5 HIGH· v3
4.9 MEDIUM· v2
Grafana is an open-source platform for monitoring and observability. In Grafana Enterprise, the Request security feature allows list allows to configure Grafana in a way so that the instance doesn’t call or only calls sp...Show more
Grafana is an open-source platform for monitoring and observability. In Grafana Enterprise, the Request security feature allows list allows to configure Grafana in a way so that the instance doesn’t call or only calls specific hosts. The vulnerability present starting with version 7.4.0-beta1 and prior to versions 7.5.16 and 8.5.3 allows someone to bypass these security configurations if a malicious datasource (running on an allowed host) returns an HTTP redirect to a forbidden host. The vulnerability only impacts Grafana Enterprise when the Request security allow list is used and there is a possibility to add a custom datasource to Grafana which returns HTTP redirects. In this scenario, Grafana would blindly follow the redirects and potentially give secure information to the clients. Grafana Cloud is not impacted by this vulnerability. Versions 7.5.16 and 8.5.3 contain a patch for this issue. There are currently no known workarounds.Show less
1Diagrams
1Drawio
Jun 17, 2026
May 18, 2022
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository jgraph/drawio prior to 18.0.7.
1Acronis
1Cyber Protect
Jun 17, 2026
May 18, 2022
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Open redirect via user-controlled query parameter. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 29240
1Sonicwall
5Sma 6200 Firmware
Sma 6210 FirmwareSma 7200 Firmware+2 more
Jun 17, 2026
May 13, 2022
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
SonicWall SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier versions accept a user-controlled input that specifies a link to an external site and uses that link in a redirect which leads to Open redirection vulner...Show more
SonicWall SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier versions accept a user-controlled input that specifies a link to an external site and uses that link in a redirect which leads to Open redirection vulnerability.Show less
1Sysaid
1Sysaid
Jun 17, 2026
May 12, 2022
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Sysaid – sysaid Open Redirect - An Attacker can change the redirect link at the parameter "redirectURL" from"GET" request from the url location: /CommunitySSORedirect.jsp?redirectURL=https://google.com. Unvalidated redir...Show more
Sysaid – sysaid Open Redirect - An Attacker can change the redirect link at the parameter "redirectURL" from"GET" request from the url location: /CommunitySSORedirect.jsp?redirectURL=https://google.com. Unvalidated redirects and forwards are possible when a web application accepts untrusted input that could cause the web application to redirect the request to a URL contained within untrusted input. By modifying untrusted URL input to a malicious site, an attacker may successfully launch a phishing scam and steal user credentials.Show less
1Ultimatemember
1Ultimate Member
Jun 17, 2026
May 10, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Ultimate Member plugin for WordPress is vulnerable to arbitrary redirects due to insufficient validation on supplied URLs in the social fields of the Profile Page, which makes it possible for attackers to redirect un...Show more
The Ultimate Member plugin for WordPress is vulnerable to arbitrary redirects due to insufficient validation on supplied URLs in the social fields of the Profile Page, which makes it possible for attackers to redirect unsuspecting victims in versions up to, and including, 2.3.1.Show less
1Qnap
3Qts
Quts HeroQutscloud
Jun 17, 2026
May 5, 2022
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
An open redirect vulnerability has been reported to affect QNAP device running QuTScloud, QuTS hero and QTS. If exploited, this vulnerability allows attackers to redirect users to an untrusted page that contains malware....Show more
An open redirect vulnerability has been reported to affect QNAP device running QuTScloud, QuTS hero and QTS. If exploited, this vulnerability allows attackers to redirect users to an untrusted page that contains malware. We have already fixed this vulnerability in the following versions of QuTScloud, QuTS hero and QTS: QuTScloud c5.0.1.1949 and later QuTS hero h5.0.0.1949 build 20220215 and later QuTS hero h4.5.4.1951 build 20220218 and later QTS 5.0.0.1986 build 20220324 and later QTS 4.5.4.1991 build 20220329 and laterShow less
1Cisco
2Roomos
Telepresence Collaboration Endpoint
Jun 17, 2026
May 4, 2022
N/A· v4
4.7 MEDIUM· v3
4.3 MEDIUM· v2
Multiple vulnerabilities in the web engine of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow a remote attacker to cause a denial of service (DoS) condition, view sensitive d...Show more
Multiple vulnerabilities in the web engine of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow a remote attacker to cause a denial of service (DoS) condition, view sensitive data on an affected device, or redirect users to an attacker-controlled destination. For more information about these vulnerabilities, see the Details section of this advisory.Show less