← Back
CWE-601

1,576 CVEs • Abstraction: Base • Likelihood of Exploit: Low

URL Redirection to Untrusted Site ('Open Redirect')

A web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a Redirect. This simplifies phishing attacks.

JSON object

Loading...

CVEs (1,576)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Broadcom
1Symantec Siteminder
Nov 20, 2024
Mar 28, 2022
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
A vulnerability was found in Netegrity SiteMinder up to 4.5.1 and classified as critical. Affected by this issue is the file /siteminderagent/pwcgi/smpwservicescgi.exe of the component Login. The manipulation of the argu...Show more
A vulnerability was found in Netegrity SiteMinder up to 4.5.1 and classified as critical. Affected by this issue is the file /siteminderagent/pwcgi/smpwservicescgi.exe of the component Login. The manipulation of the argument target leads to an open redirect. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainerShow less
1Gitlab
1Gitlab
Jun 17, 2026
Mar 28, 2022
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
An issue has been discovered affecting GitLab versions prior to 13.5. An open redirect vulnerability was fixed in GitLab integration with Jira that a could cause the web application to redirect the request to the attacke...Show more
An issue has been discovered affecting GitLab versions prior to 13.5. An open redirect vulnerability was fixed in GitLab integration with Jira that a could cause the web application to redirect the request to the attacker specified URL.Show less
1Dpgaspar
1Flask Appbuilder
Jun 17, 2026
Mar 24, 2022
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Flask-AppBuilder is an application development framework, built on top of the Flask web framework. Flask-AppBuilder contains an open redirect vulnerability when using database authentication login page on versions below...Show more
Flask-AppBuilder is an application development framework, built on top of the Flask web framework. Flask-AppBuilder contains an open redirect vulnerability when using database authentication login page on versions below 3.4.5. This issue is fixed in version 3.4.5. There are currently no known workarounds.Show less
1Gitea
1Gitea
Jun 17, 2026
Mar 24, 2022
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Open Redirect on login in GitHub repository go-gitea/gitea prior to 1.16.5.
1Chshcms
1Cscms
Jun 17, 2026
Mar 21, 2022
N/A· v4
5.4 MEDIUM· v3
4.9 MEDIUM· v2
Cscms Music Portal System v4.2 was discovered to contain a redirection vulnerability via the backurl parameter.
1King Theme
1Kingcomposer
Jun 17, 2026
Mar 14, 2022
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
The Page Builder KingComposer WordPress plugin through 2.9.6 does not validate the id parameter before redirecting the user to it via the kc_get_thumbn AJAX action available to both unauthenticated and authenticated user...Show more
The Page Builder KingComposer WordPress plugin through 2.9.6 does not validate the id parameter before redirecting the user to it via the kc_get_thumbn AJAX action available to both unauthenticated and authenticated usersShow less
1Moodle
1Moodle
Jun 17, 2026
Mar 11, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The redirect URI in the LTI authorization endpoint required extra sanitizing to prevent reflected XSS and open redirect risks. Moodle versions 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8 and earlier unsupported versions a...Show more
The redirect URI in the LTI authorization endpoint required extra sanitizing to prevent reflected XSS and open redirect risks. Moodle versions 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8 and earlier unsupported versions are affected.Show less
1Alltube Project
1Alltube
Jun 17, 2026
Mar 8, 2022
N/A· v4
6.1 MEDIUM· v3
4.0 MEDIUM· v2
alltube is an html front end for youtube-dl. On releases prior to 3.0.3, an attacker could craft a special HTML page to trigger either an open redirect attack or a Server-Side Request Forgery attack (depending on how All...Show more
alltube is an html front end for youtube-dl. On releases prior to 3.0.3, an attacker could craft a special HTML page to trigger either an open redirect attack or a Server-Side Request Forgery attack (depending on how AllTube is configured). The impact is mitigated by the fact the SSRF attack is only possible when the `stream` option is enabled in the configuration. (This option is disabled by default.) 3.0.3 contains a fix for this vulnerability.Show less
1Nextcloud
1Talk
Jun 17, 2026
Mar 8, 2022
N/A· v4
6.1 MEDIUM· v3
4.0 MEDIUM· v2
Nextcloud talk is a self hosting messaging service. In versions prior 12.1.2 an attacker is able to control the link of a geolocation preview in the Nextcloud Talk application due to a lack of validation on the link. Thi...Show more
Nextcloud talk is a self hosting messaging service. In versions prior 12.1.2 an attacker is able to control the link of a geolocation preview in the Nextcloud Talk application due to a lack of validation on the link. This could result in an open-redirect, but required user interaction. This only affected users of the Android Talk client. It is recommended that the Nextcloud Talk App is upgraded to 12.1.2. There are no known workarounds.Show less
1Archivy Project
1Archivy
Jun 17, 2026
Mar 6, 2022
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Open Redirect in GitHub repository archivy/archivy prior to 1.7.0.
1Uri.js Project
1Uri.js
Jun 17, 2026
Mar 6, 2022
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Open Redirect in GitHub repository medialize/uri.js prior to 1.19.10.
1Spirit Project
1Spirit
Jun 17, 2026
Mar 6, 2022
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Multiple Open Redirect in GitHub repository nitely/spirit prior to 0.12.3.
1Dlink
1Dir 850l Firmware
Jun 17, 2026
Mar 4, 2022
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through URL redirection to untrusted site.
2Openstack
Redhat
2Nova
Openstack Platform
Jun 17, 2026
Mar 2, 2022
N/A· v4
6.1 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability was found in openstack-nova's console proxy, noVNC. By crafting a malicious URL, noVNC could be made to redirect to any desired URL.
1Cherwell
1Cherwell Service Management
Jun 17, 2026
Feb 28, 2022
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
An issue was discovered in the web application in Cherwell Service Management (CSM) 10.2.3. It accepts and reflects arbitrary domains supplied via a client-controlled Host header. Injection of a malicious URL in the Host...Show more
An issue was discovered in the web application in Cherwell Service Management (CSM) 10.2.3. It accepts and reflects arbitrary domains supplied via a client-controlled Host header. Injection of a malicious URL in the Host: header of the HTTP Request results in a 302 redirect to an attacker-controlled page.Show less
1Cherwell
1Cherwell Service Management
Jun 17, 2026
Feb 28, 2022
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
An issue was discovered in the web application in Cherwell Service Management (CSM) 10.2.3. Injection of a malicious payload within the RelayState= parameter of the HTTP request body results in the hijacking of the form...Show more
An issue was discovered in the web application in Cherwell Service Management (CSM) 10.2.3. Injection of a malicious payload within the RelayState= parameter of the HTTP request body results in the hijacking of the form action. Form-action hijacking vulnerabilities arise when an application places user-supplied input into the action URL of an HTML form. An attacker can use this vulnerability to construct a URL that, if visited by another application user, will modify the action URL of a form to point to the attacker's server.Show less
1Karma Project
1Karma
Jun 17, 2026
Feb 25, 2022
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
The package karma before 6.3.16 are vulnerable to Open Redirect due to missing validation of the return_url query parameter.
1Jetbrains
1Teamcity
Jun 17, 2026
Feb 25, 2022
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
In JetBrains TeamCity before 2021.2.1, a redirection to an external site was possible.
1Hpe
1Oneview Global Dashboard
Jun 17, 2026
Feb 24, 2022
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
A remote URL redirection vulnerability was discovered in HPE OneView Global Dashboard version(s): Prior to 2.5. HPE has provided a software update to resolve this vulnerability in HPE OneView Global Dashboard.
1Alltube Project
1Alltube
Jun 17, 2026
Feb 21, 2022
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Open Redirect on Rudloff/alltube in Packagist rudloff/alltube prior to 3.0.1.