CWE-601— URL Redirection to Untrusted Site (Open Redirect)
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.— MITRE CWE catalog
1,633 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-601page 13 of 33
- CVE-2021-4348HIGHCVSS 7.5EG 7.52023-06-07
The Ultimate GDPR & CCPA plugin for WordPress is vulnerable to unauthenticated settings import and export via the export_settings & import_settings functions in versions up to, and including, 2.4. This makes it possible for unauthenticated…
- CVE-2021-43532MEDIUMCVSS 6.1EG 6.12021-12-08
The 'Copy Image Link' context menu action would copy the final image URL after redirects. By embedding an image that triggered authentication flows - in conjunction with a Content Security Policy that stopped a redirection chain in the mid…
- CVE-2021-43777MEDIUMCVSS 6.8EG 6.82021-11-24
Redash is a package for data visualization and sharing. In Redash version 10.0 and prior, the implementation of Google Login (via OAuth) incorrectly uses the `state` parameter to pass the next URL to redirect the user to after login. The `…
- CVE-2021-43812MEDIUMCVSS 6.4EG 6.42021-12-16
The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. Versions before 1.6.2 do not filter out certain returnTo parameter values from the login url, which expose the application to an open redirect…
- CVE-2021-44054MEDIUMCVSS 4.3EG 6.12022-05-05
An open redirect vulnerability has been reported to affect QNAP device running QuTScloud, QuTS hero and QTS. If exploited, this vulnerability allows attackers to redirect users to an untrusted page that contains malware. We have already fi…
- CVE-2021-44528MEDIUMCVSS 6.1EG 6.12022-01-10
A open redirect vulnerability exists in Action Pack >= 6.0.0 that could allow an attacker to craft a "X-Forwarded-Host" headers in combination with certain "allowed host" formats can cause the Host Authorization middleware in Action Pack t…
- CVE-2021-45328MEDIUMCVSS 6.1EG 6.12022-02-08
Gitea before 1.4.3 is affected by URL Redirection to Untrusted Site ('Open Redirect') via internal URLs.
- CVE-2021-45408MEDIUMCVSS 6.1EG 6.12022-02-04
Open Redirect vulnerability exists in SeedDMS 6.0.15 in out.Login.php, which llows remote malicious users to redirect users to malicious sites using the "referuri" parameter.
- CVE-2021-46366HIGHCVSS 8.8EG 8.82022-02-11
An issue in the Login page of Magnolia CMS v6.2.3 and below allows attackers to exploit both an Open Redirect vulnerability and Cross-Site Request Forgery (CSRF) in order to brute force and exfiltrate users' credentials.
- CVE-2021-46379MEDIUMCVSS 6.1EG 6.12022-03-04
DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through URL redirection to untrusted site.
- CVE-2021-46898MEDIUMCVSS 6.1EG 6.12023-10-22
views/switch.py in django-grappelli (aka Django Grappelli) before 2.15.2 attempts to prevent external redirection with startswith("/") but this does not consider a protocol-relative URL (e.g., //example.com) attack.
- CVE-2022-0122MEDIUMCVSS 6.1EG 6.12022-01-06
forge is vulnerable to URL Redirection to Untrusted Site
- CVE-2022-0165HIGHCVSS 6.1EG 8.82022-03-14
The Page Builder KingComposer WordPress plugin through 2.9.6 does not validate the id parameter before redirecting the user to it via the kc_get_thumbn AJAX action available to both unauthenticated and authenticated users
- CVE-2022-0235MEDIUMCVSS 6.1EG 6.12022-01-16
node-fetch is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
- CVE-2022-0283MEDIUMCVSS 4.7EG 6.12022-03-28
An issue has been discovered affecting GitLab versions prior to 13.5. An open redirect vulnerability was fixed in GitLab integration with Jira that a could cause the web application to redirect the request to the attacker specified URL.
- CVE-2022-0560MEDIUMCVSS 6.1EG 6.12022-02-11
Open Redirect in Packagist microweber/microweber prior to 1.2.11.
- CVE-2022-0597MEDIUMCVSS 6.1EG 6.12022-02-15
Open Redirect in Packagist microweber/microweber prior to 1.2.11.
- CVE-2022-0637MEDIUMCVSS 6.1EG 6.12023-02-16
open redirect in pollbot (pollbot.services.mozilla.com) in versions before 1.4.6
- CVE-2022-0645MEDIUMCVSS 6.1EG 6.12022-04-19
Open redirect vulnerability via endpoint authorize_and_redirect/?redirect= in GitHub repository posthog/posthog prior to 1.34.1.
- CVE-2022-0692MEDIUMCVSS 6.1EG 6.12022-02-21
Open Redirect on Rudloff/alltube in Packagist rudloff/alltube prior to 3.0.1.
- CVE-2022-0697MEDIUMCVSS 6.1EG 6.12022-03-06
Open Redirect in GitHub repository archivy/archivy prior to 1.7.0.
- CVE-2022-0868MEDIUMCVSS 6.1EG 6.12022-03-06
Open Redirect in GitHub repository medialize/uri.js prior to 1.19.10.
- CVE-2022-0869MEDIUMCVSS 6.1EG 6.12022-03-06
Multiple Open Redirect in GitHub repository nitely/spirit prior to 0.12.3.
- CVE-2022-1019MEDIUMCVSS 5.2EG 6.12022-04-19
Automated Logic's WebCtrl Server Version 6.1 'Help' index pages are vulnerable to open redirection. The vulnerability allows an attacker to send a maliciously crafted URL which could result in redirecting the user to a malicious webpage or…
- CVE-2022-1058HIGHCVSS 6.1EG 7.22022-03-24
Open Redirect on login in GitHub repository go-gitea/gitea prior to 1.16.5.
- CVE-2022-1209MEDIUMCVSS 4.3EG 5.42022-05-10
The Ultimate Member plugin for WordPress is vulnerable to arbitrary redirects due to insufficient validation on supplied URLs in the social fields of the Profile Page, which makes it possible for attackers to redirect unsuspecting victims …
- CVE-2022-1230LOWCVSS 3.9EG 3.92023-03-28
This vulnerability allows local attackers to execute arbitrary code on affected installations of Samsung Galaxy S21 prior to 4.5.40.5 phones. An attacker must first obtain the ability to execute low-privileged code on the target system in …
- CVE-2022-1233MEDIUMCVSS 6.1EG 6.12022-04-04
URL Confusion When Scheme Not Supplied in GitHub repository medialize/uri.js prior to 1.19.11.
- CVE-2022-1254MEDIUMCVSS 6.1EG 6.12022-04-20
A URL redirection vulnerability in Skyhigh SWG in main releases 10.x prior to 10.2.9, 9.x prior to 9.2.20, 8.x prior to 8.2.27, and 7.x prior to 7.8.2.31, and controlled release 11.x prior to 11.1.3 allows a remote attacker to redirect a u…
- CVE-2022-1702MEDIUMCVSS 6.1EG 6.12022-05-13
SonicWall SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier versions accept a user-controlled input that specifies a link to an external site and uses that link in a redirect which leads to Open redirection vulnerability.
- CVE-2022-1774MEDIUMCVSS 6.1EG 6.12022-05-18
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository jgraph/drawio prior to 18.0.7.
- CVE-2022-20634MEDIUMCVSS 4.7EG 4.72024-11-15
A vulnerability in the web-based management interface of Cisco ECE could allow an unauthenticated, remote attacker to redirect a user to an undesired web page. This vulnerability is due to improper input validation of the URL paramet…
- CVE-2022-20764HIGHCVSS 6.5EG 8.12022-05-04
Multiple vulnerabilities in the web engine of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow a remote attacker to cause a denial of service (DoS) condition, view sensitive data on an affected …
- CVE-2022-20794MEDIUMCVSS 6.5EG 6.52022-05-04
Multiple vulnerabilities in the web engine of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow a remote attacker to cause a denial of service (DoS) condition, view sensitive data on an affected …
- CVE-2022-21651MEDIUMCVSS 6.8EG 6.82022-01-05
Shopware is an open source e-commerce software platform. An open redirect vulnerability has been discovered. Users may be arbitrary redirected due to incomplete URL handling in the shopware router. This issue has been resolved in version 5…
- CVE-2022-2237MEDIUMCVSS 6.1EG 6.12023-03-27
A flaw was found in the Keycloak Node.js Adapter. This flaw allows an attacker to benefit from an Open Redirect vulnerability in the checkSso function.
- CVE-2022-2250MEDIUMCVSS 4.7EG 6.12022-07-01
An open redirect vulnerability in GitLab EE/CE affecting all versions from 11.1 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows an attacker to redirect users to an arbitrary location if they trust the URL.
- CVE-2022-2252MEDIUMCVSS 6.1EG 6.12022-06-29
Open Redirect in GitHub repository microweber/microweber prior to 1.2.19.
- CVE-2022-22797MEDIUMCVSS 4.6EG 6.12022-05-12
Sysaid – sysaid Open Redirect - An Attacker can change the redirect link at the parameter "redirectURL" from"GET" request from the url location: /CommunitySSORedirect.jsp?redirectURL=https://google.com. Unvalidated redirects and forwards…
- CVE-2022-22919MEDIUMCVSS 6.1EG 6.12022-01-30
Adenza AxiomSL ControllerView through 10.8.1 allows redirection for SSO login URLs.
- CVE-2022-23078MEDIUMEG 6.12022-06-22
In habitica versions v4.119.0 through v4.232.2 are vulnerable to open redirect via the login page.
- CVE-2022-23102MEDIUMCVSS 6.1EG 6.12022-02-09
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0). Affected products contain an open redirect vulnerability. An attacker could trick a valid authenticated user to the device into clicking a malicious…
- CVE-2022-23184MEDIUMCVSS 6.1EG 6.12022-02-07
In affected Octopus Server versions when the server HTTP and HTTPS bindings are configured to localhost, Octopus Server will allow open redirects.
- CVE-2022-23237MEDIUMCVSS 6.1EG 6.12022-06-02
E-Series SANtricity OS Controller Software 11.x versions through 11.70.2 are vulnerable to host header injection attacks that could allow an attacker to redirect users to malicious websites.
- CVE-2022-23527MEDIUMCVSS 4.7EG 4.72022-12-14
mod_auth_openidc is an OpenID Certified™ authentication and authorization module for the Apache 2.x HTTP server. Versions prior to 2.4.12.2 are vulnerable to Open Redirect. When providing a logout parameter to the redirect URI, the exist…
- CVE-2022-23599MEDIUMCVSS 4.3EG 4.32022-01-28
Products.ATContentTypes are the core content types for Plone 2.1 - 4.3. Versions of Plone that are dependent on Products.ATContentTypes prior to version 3.0.6 are vulnerable to reflected cross site scripting and open redirect when an attac…
- CVE-2022-23618MEDIUMCVSS 4.7EG 4.72022-02-09
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions there is no protection against URL redirection to untrusted sites, in particular some well known parameters (xred…
- CVE-2022-23798MEDIUMCVSS 6.1EG 6.12022-03-30
An issue was discovered in Joomla! 2.5.0 through 3.10.6 & 4.0.0 through 4.1.0. Inadequate validation of URLs could result into an invalid check whether an redirect URL is internal or not.
- CVE-2022-24330MEDIUMCVSS 6.1EG 6.12022-02-25
In JetBrains TeamCity before 2021.2.1, a redirection to an external site was possible.
- CVE-2022-24739HIGHCVSS 7.3EG 7.32022-03-08
alltube is an html front end for youtube-dl. On releases prior to 3.0.3, an attacker could craft a special HTML page to trigger either an open redirect attack or a Server-Side Request Forgery attack (depending on how AllTube is configured)…
Map vulnerabilities like CWE-601 to your infrastructure
EchelonGraph correlates every CVE — across CWE-601 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →