← Back
CWE-601

1,576 CVEs • Abstraction: Base • Likelihood of Exploit: Low

URL Redirection to Untrusted Site ('Open Redirect')

A web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a Redirect. This simplifies phishing attacks.

JSON object

Loading...

CVEs (1,576)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cisco
2Roomos
Telepresence Collaboration Endpoint
Jun 17, 2026
May 4, 2022
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
Multiple vulnerabilities in the web engine of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow a remote attacker to cause a denial of service (DoS) condition, view sensitive d...Show more
Multiple vulnerabilities in the web engine of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow a remote attacker to cause a denial of service (DoS) condition, view sensitive data on an affected device, or redirect users to an attacker-controlled destination. For more information about these vulnerabilities, see the Details section of this advisory.Show less
1Nopcommerce
1Nopcommerce
Jul 9, 2026
May 4, 2022
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
In nopCommerce 4.50.1, an open redirect vulnerability can be triggered by luring a user to authenticate to a nopCommerce page by clicking on a crafted link.
1Microfocus
1Netiq Access Manager
Jun 17, 2026
May 2, 2022
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Potential open redirection vulnerability when URL is crafted in specific format in NetIQ Access Manager prior to 5.0.2
1Nextcloud
1Talk
Jun 17, 2026
Apr 27, 2022
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Nextcloud Talk is a video and audio conferencing app for Nextcloud, a self-hosted productivity platform. Prior to versions 11.3.4, 12.2.2, and 13.0.0, when sharing a Deck card in conversation, the metaData can be manipul...Show more
Nextcloud Talk is a video and audio conferencing app for Nextcloud, a self-hosted productivity platform. Prior to versions 11.3.4, 12.2.2, and 13.0.0, when sharing a Deck card in conversation, the metaData can be manipulated so users can be tricked into opening arbitrary URLs. This issue is fixed in versions 11.3.4, 12.2.2, and 13.0.0. There are currently no known workarounds.Show less
1English Wordpress Admin Project
1English Wordpress Admin
Jun 17, 2026
Apr 25, 2022
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
The English WordPress Admin WordPress plugin before 1.5.2 does not validate the admin_custom_language_return_url before redirecting users o it, leading to an open redirect issue
1Mi
1Mi App Store
Jun 17, 2026
Apr 21, 2022
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
An intent redirection vulnerability in the Mi App Store product. This vulnerability is caused by the Mi App Store does not verify the validity of the incoming data, can cause the app store to automatically download and i...Show more
An intent redirection vulnerability in the Mi App Store product. This vulnerability is caused by the Mi App Store does not verify the validity of the incoming data, can cause the app store to automatically download and install apps.Show less
1Mcafee
1Web Gateway
Jun 17, 2026
Apr 20, 2022
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
A URL redirection vulnerability in Skyhigh SWG in main releases 10.x prior to 10.2.9, 9.x prior to 9.2.20, 8.x prior to 8.2.27, and 7.x prior to 7.8.2.31, and controlled release 11.x prior to 11.1.3 allows a remote attac...Show more
A URL redirection vulnerability in Skyhigh SWG in main releases 10.x prior to 10.2.9, 9.x prior to 9.2.20, 8.x prior to 8.2.27, and 7.x prior to 7.8.2.31, and controlled release 11.x prior to 11.1.3 allows a remote attacker to redirect a user to a malicious website controlled by the attacker. This is possible because SWG incorrectly creates a HTTP redirect response when a user clicks a carefully constructed URL. Following the redirect response, the new request is still filtered by the SWG policy.Show less
1Nextauth.js
1Next Auth
Jun 17, 2026
Apr 19, 2022
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
next-auth v3 users before version 3.29.2 are impacted. next-auth version 4 users before version 4.3.2 are also impacted. Upgrading to 3.29.2 or 4.3.2 will patch this vulnerability. If you are not able to upgrade for any...Show more
next-auth v3 users before version 3.29.2 are impacted. next-auth version 4 users before version 4.3.2 are also impacted. Upgrading to 3.29.2 or 4.3.2 will patch this vulnerability. If you are not able to upgrade for any reason, you can add a configuration to your callbacks option. If you already have a `redirect` callback, make sure that you match the incoming `url` origin against the `baseUrl`.Show less
1Automatedlogic
1Webctrl Server
Jun 17, 2026
Apr 19, 2022
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Automated Logic's WebCtrl Server Version 6.1 'Help' index pages are vulnerable to open redirection. The vulnerability allows an attacker to send a maliciously crafted URL which could result in redirecting the user to a m...Show more
Automated Logic's WebCtrl Server Version 6.1 'Help' index pages are vulnerable to open redirection. The vulnerability allows an attacker to send a maliciously crafted URL which could result in redirecting the user to a malicious webpage or downloading a malicious file.Show less
1Posthog
1Posthog
Jun 17, 2026
Apr 19, 2022
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Open redirect vulnerability via endpoint authorize_and_redirect/?redirect= in GitHub repository posthog/posthog prior to 1.34.1.
1Bbraun
2Datamodule Compactplus
Spacecom
Jun 17, 2026
Apr 14, 2022
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
An open redirect vulnerability in the administrative interface of the B. Braun Melsungen AG SpaceCom device Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows attackers to redirect u...Show more
An open redirect vulnerability in the administrative interface of the B. Braun Melsungen AG SpaceCom device Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows attackers to redirect users to malicious websites.Show less
1Hubzilla
1Hubzilla
Jun 17, 2026
Apr 13, 2022
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
A PHP Local File inclusion vulnerability in the Redbasic theme for Hubzilla before version 7.2 allows remote attackers to include arbitrary php files via the schema parameter.
1Sap
1Netweaver Abap
Jun 17, 2026
Apr 12, 2022
N/A· v4
4.7 MEDIUM· v3
4.3 MEDIUM· v2
SAP NetWeaver ABAP Server and ABAP Platform - versions 740, 750, 787, allows an unauthenticated attacker to redirect users to a malicious site due to insufficient URL validation. This could lead to the user being tricked...Show more
SAP NetWeaver ABAP Server and ABAP Platform - versions 740, 750, 787, allows an unauthenticated attacker to redirect users to a malicious site due to insufficient URL validation. This could lead to the user being tricked to disclose personal information.Show less
1Orangehrm
1Orangehrm
Jun 17, 2026
Apr 6, 2022
N/A· v4
5.4 MEDIUM· v3
4.9 MEDIUM· v2
OrangeHRM 4.10 is vulnerable to a Host header injection redirect via viewPersonalDetails endpoint.
1Orangehrm
1Orangehrm
Jun 17, 2026
Apr 6, 2022
N/A· v4
5.4 MEDIUM· v3
4.9 MEDIUM· v2
OrangeHRM 4.10 suffers from a Referer header injection redirect vulnerability.
1Wwbn
1Avideo
Jun 17, 2026
Apr 5, 2022
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Open redirect vulnerability in objects/login.json.php in WWBN AVideo through 11.6, allows attackers to arbitrarily redirect users from a crafted url to the login page.
1Uri.js Project
1Uri.js
Jun 17, 2026
Apr 4, 2022
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
URL Confusion When Scheme Not Supplied in GitHub repository medialize/uri.js prior to 1.19.11.
1Auth0
1Express Openid Connect
Jun 17, 2026
Mar 31, 2022
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Express OpenID Connect is an Express JS middleware implementing sign on for Express web apps using OpenID Connect. Users of the `requiresAuth` middleware, either directly or through the default `authRequired` option, are...Show more
Express OpenID Connect is an Express JS middleware implementing sign on for Express web apps using OpenID Connect. Users of the `requiresAuth` middleware, either directly or through the default `authRequired` option, are vulnerable to an Open Redirect when the middleware is applied to a catch all route. If all routes under `example.com` are protected with the `requiresAuth` middleware, a visit to `http://example.com//google.com` will be redirected to `google.com` after login because the original url reported by the Express framework is not properly sanitized. This vulnerability affects versions prior to 2.7.2. Users are advised to upgrade. There are no known workarounds.Show less
1Joomla
1Joomla
Jun 17, 2026
Mar 30, 2022
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
An issue was discovered in Joomla! 2.5.0 through 3.10.6 & 4.0.0 through 4.1.0. Inadequate validation of URLs could result into an invalid check whether an redirect URL is internal or not.
1Rsa
1Archer
Jun 17, 2026
Mar 30, 2022
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Archer 6.x through 6.9 P2 (6.9.0.2) is affected by an open redirect vulnerability. A remote unprivileged attacker may potentially redirect legitimate users to arbitrary web sites and conduct phishing attacks. The attacke...Show more
Archer 6.x through 6.9 P2 (6.9.0.2) is affected by an open redirect vulnerability. A remote unprivileged attacker may potentially redirect legitimate users to arbitrary web sites and conduct phishing attacks. The attacker could then steal the victims' credentials and silently authenticate them to the Archer application without the victims realizing an attack occurred.Show less