CWE-601— URL Redirection to Untrusted Site (Open Redirect)
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.— MITRE CWE catalog
1,634 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-601page 18 of 33
- CVE-2023-35791MEDIUMCVSS 6.1EG 6.12023-07-31
Vound Intella Connect 2.6.0.3 has an Open Redirect vulnerability.
- CVE-2023-35883MEDIUMCVSS 4.7EG 4.72023-12-19
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Magazine3 Core Web Vitals & PageSpeed Booster.This issue affects Core Web Vitals & PageSpeed Booster: from n/a through 1.0.12.
- CVE-2023-35934MEDIUMCVSS 6.1EG 6.12023-07-06
yt-dlp is a command-line program to download videos from video sites. During file downloads, yt-dlp or the external downloaders that yt-dlp employs may leak cookies on HTTP redirects to a different host, or leak them when the host for down…
- CVE-2023-35948MEDIUMCVSS 5.4EG 5.42023-07-06
Novu provides an API for sending notifications through multiple channels. Versions prior to 0.16.0 contain an open redirect vulnerability in the "Sign In with GitHub" functionality of Novu's open-source repository. It could have allowed an…
- CVE-2023-36085MEDIUMCVSS 6.1EG 6.12023-10-25
The sisqualWFM 7.1.319.103 thru 7.1.319.111 for Android, has a host header injection vulnerability in its "/sisqualIdentityServer/core/" endpoint. By modifying the HTTP Host header, an attacker can change webpage links and even redirect us…
- CVE-2023-3684LOWCVSS 3.5EG 3.52023-07-16
A vulnerability was found in LivelyWorks Articart 2.0.1 and classified as problematic. Affected by this issue is some unknown functionality of the file /change-language/de_DE of the component Base64 Encoding Handler. The manipulation of th…
- CVE-2023-37561MEDIUMCVSS 6.1EG 6.12023-07-13
Open redirect vulnerability in ELECOM wireless LAN routers and ELECOM wireless LAN repeaters allows a remote unauthenticated attacker to redirect users to arbitrary web sites and conduct phishing attacks via a specially crafted URL. Affect…
- CVE-2023-37624MEDIUMCVSS 6.1EG 6.12023-07-26
Netdisco before v2.063000 was discovered to contain an open redirect vulnerability. An attacker may exploit this vulnerability to redirect users to arbitrary web URLs by tricking the victim users to click on crafted links.
- CVE-2023-3771MEDIUMCVSS 6.1EG 6.12024-01-16
The T1 WordPress theme through 19.0 is vulnerable to unauthenticated open redirect with which any attacker and redirect users to arbitrary websites.
- CVE-2023-37947MEDIUMCVSS 6.1EG 6.12023-07-12
Jenkins OpenShift Login Plugin 1.1.0.227.v27e08dfb_1a_20 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins, allowing attackers to perform phishing attacks.
- CVE-2023-37982MEDIUMCVSS 4.7EG 4.72023-12-19
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks Integration for Salesforce and Contact Form 7, WPForms, Elementor, Ninja Forms.This issue affects Integration for Salesforce and Contact Form 7, WPForms, Elemen…
- CVE-2023-38478MEDIUMCVSS 4.7EG 4.72023-12-19
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks Integration for WooCommerce and QuickBooks.This issue affects Integration for WooCommerce and QuickBooks: from n/a through 1.2.3.
- CVE-2023-38481MEDIUMCVSS 4.7EG 4.72023-12-19
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks Integration for WooCommerce and Zoho CRM, Books, Invoice, Inventory, Bigin.This issue affects Integration for WooCommerce and Zoho CRM, Books, Invoice, Inventor…
- CVE-2023-38574MEDIUMCVSS 6.1EG 6.12023-09-05
Open redirect vulnerability in VI Web Client prior to 7.9.6 allows a remote unauthenticated attacker to redirect users to arbitrary web sites and conduct phishing attacks via a specially crafted URL.
- CVE-2023-38998MEDIUMCVSS 6.1EG 6.12023-08-09
An open redirect in the Login page of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to redirect a victim user to an arbitrary web site via a crafted URL.
- CVE-2023-3922LOWCVSS 3.0EG 3.02023-09-29
An issue has been discovered in GitLab affecting all versions starting from 8.15 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible to hijack some links and buttons …
- CVE-2023-39364LOWCVSS 3.5EG 3.52023-09-05
Cacti is an open source operational monitoring and fault management framework. In Cacti 1.2.24, users with console access can be redirected to an arbitrary website after a change password performed via a specifically crafted URL. The `auth…
- CVE-2023-39371HIGHCVSS 8.8EG 8.82023-09-03
StarTrinity Softswitch version 2023-02-16 - Open Redirect (CWE-601)
- CVE-2023-39968MEDIUMCVSS 4.3EG 4.32023-08-28
jupyter-server is the backend for Jupyter web applications. Open Redirect Vulnerability. Maliciously crafted login links to known Jupyter Servers can cause successful login or an already logged-in session to be redirected to arbitrary site…
- CVE-2023-40306MEDIUMCVSS 6.1EG 6.12023-09-08
SAP S/4HANA Manage Catalog Items and Cross-Catalog searches Fiori apps allow an attacker to redirect users to a malicious site due to insufficient URL validation. As a result, it may have a slight impact on confidentiality and integrity.
- CVE-2023-40602MEDIUMCVSS 4.7EG 4.72023-12-19
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Doofinder Doofinder WP & WooCommerce Search.This issue affects Doofinder WP & WooCommerce Search: from n/a through 1.5.49.
- CVE-2023-40779MEDIUMCVSS 6.1EG 6.12023-09-14
An issue in IceWarp Mail Server Deep Castle 2 v.13.0.1.2 allows a remote attacker to execute arbitrary code via a crafted request to the URL.
- CVE-2023-41080MEDIUMCVSS 6.1EG 6.12023-08-25
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Tomcat.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.0.12, from 9.0.0-M1 through 9.0.7…
- CVE-2023-41609MEDIUMCVSS 6.1EG 6.12023-09-11
An open redirect vulnerability in the sanitize_url() parameter of CouchCMS v2.3 allows attackers to redirect a victim user to an arbitrary web site via a crafted URL.
- CVE-2023-41648MEDIUMCVSS 6.1EG 6.12023-12-19
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Swapnil V. Patil Login and Logout Redirect.This issue affects Login and Logout Redirect: from n/a through 2.0.3.
- CVE-2023-41699MEDIUMCVSS 6.1EG 6.12023-11-15
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Payara Platform Payara Server, Micro and Embedded (Servlet Implementation modules) allows Redirect Access to Libraries.This issue affects Payara Server, Micro and Embedde…
- CVE-2023-42502MEDIUMCVSS 5.4EG 5.42023-11-28
An authenticated attacker with update datasets permission could change a dataset link to an untrusted site by spoofing the HTTP Host header, users could be redirected to this site when clicking on that specific dataset. This issue affects …
- CVE-2023-44308MEDIUMCVSS 6.1EG 6.12024-02-20
Open redirect vulnerability in adaptive media administration page in Liferay DXP 2023.Q3 before patch 6, and 7.4 GA through update 92 allows remote attackers to redirect users to arbitrary external URLs via the _com_liferay_adaptive_media_…
- CVE-2023-45105MEDIUMCVSS 6.1EG 6.12023-12-19
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in SERVIT Software Solutions affiliate-toolkit – WordPress Affiliate Plugin.This issue affects affiliate-toolkit – WordPress Affiliate Plugin: from n/a through 3.3.9.
- CVE-2023-45201MEDIUMCVSS 6.1EG 6.12023-11-01
Online Examination System v1.0 is vulnerable to multiple Open Redirect vulnerabilities. The 'q' parameter of the admin.php resource allows an attacker to redirect a victim user to an arbitrary web site using a crafted URL.
- CVE-2023-45202MEDIUMCVSS 6.1EG 6.12023-11-01
Online Examination System v1.0 is vulnerable to multiple Open Redirect vulnerabilities. The 'q' parameter of the feed.php resource allows an attacker to redirect a victim user to an arbitrary web site using a crafted URL.
- CVE-2023-45203MEDIUMCVSS 6.1EG 6.12023-11-01
Online Examination System v1.0 is vulnerable to multiple Open Redirect vulnerabilities. The 'q' parameter of the login.php resource allows an attacker to redirect a victim user to an arbitrary web site using a crafted URL.
- CVE-2023-45762MEDIUMCVSS 6.1EG 6.12023-12-07
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Michael Uno (miunosoft) Responsive Column Widgets.This issue affects Responsive Column Widgets: from n/a through 1.2.7.
- CVE-2023-45909MEDIUMCVSS 6.1EG 6.12023-10-18
zzzcms v2.2.0 was discovered to contain an open redirect vulnerability.
- CVE-2023-46624MEDIUMCVSS 6.1EG 6.12023-12-19
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Parcel Pro.This issue affects Parcel Pro: from n/a through 1.6.11.
- CVE-2023-46688MEDIUMCVSS 6.1EG 6.12023-12-06
Open redirect vulnerability in Pleasanter 1.3.47.0 and earlier allows a remote unauthenticated attacker to redirect users to arbitrary web sites via a specially crafted URL.
- CVE-2023-46750MEDIUMCVSS 6.1EG 6.12023-12-14
URL Redirection to Untrusted Site ('Open Redirect') vulnerability when "form" authentication is used in Apache Shiro. Mitigation: Update to Apache Shiro 1.13.0+ or 2.0.0-alpha-4+.
- CVE-2023-47168MEDIUMCVSS 6.1EG 6.12023-11-27
Mattermost fails to properly check a redirect URL parameter allowing for an open redirect was possible when the user clicked "Back to Mattermost" after providing a invalid custom url scheme in /oauth/{service}/mobile_login?redirect_to=
- CVE-2023-47548MEDIUMCVSS 6.1EG 6.12023-12-07
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in SoftLab Integrate Google Drive – Browse, Upload, Download, Embed, Play, Share, Gallery, and Manage Your Google Drive Files Into Your WordPress Site.This issue affects I…
- CVE-2023-47779MEDIUMCVSS 6.1EG 6.12023-12-07
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks. Integration for Constant Contact and Contact Form 7, WPForms, Elementor, Ninja Forms.This issue affects Integration for Constant Contact and Contact Form 7, WP…
- CVE-2023-48003MEDIUMCVSS 6.1EG 6.12023-12-26
An open redirect through HTML injection in user messages in Asp.Net Zero before 12.3.0 allows remote attackers to redirect targeted victims to any URL via the '<meta http-equiv="refresh"' in the WebSocket messages.
- CVE-2023-48325MEDIUMCVSS 6.1EG 6.12023-12-07
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in PluginOps Landing Page Builder – Lead Page – Optin Page – Squeeze Page – WordPress Landing Pages.This issue affects Landing Page Builder – Lead Page – Optin P…
- CVE-2023-48815MEDIUMCVSS 6.1EG 6.12023-12-04
kkFileView v4.3.0 is vulnerable to Incorrect Access Control.
- CVE-2023-48928MEDIUMCVSS 6.1EG 6.12023-12-08
Franklin Fueling Systems System Sentinel AnyWare (SSA) version 1.6.24.492 is vulnerable to Open Redirect. The 'path' parameter of the prefs.asp resource allows an attacker to redirect a victim user to an arbitrary web site using a crafted …
- CVE-2023-49061MEDIUMCVSS 6.1EG 6.12023-11-21
An attacker could have performed HTML template injection via Reader Mode and exfiltrated user information. This vulnerability affects Firefox for iOS < 120.
- CVE-2023-49104HIGHCVSS 6.1EG 8.72023-11-21
An issue was discovered in ownCloud owncloud/oauth2 before 0.6.1, when Allow Subdomains is enabled. An attacker is able to pass in a crafted redirect-url that bypasses validation, and consequently allows an attacker to redirect callbacks t…
- CVE-2023-49240HIGHCVSS 7.5EG 7.52023-12-06
Unauthorized access vulnerability in the launcher module. Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2023-49281MEDIUMCVSS 6.1EG 6.12023-12-01
Calendarinho is an open source calendaring application to manage large teams of consultants. An Open Redirect issue occurs when a web application redirects users to external URLs without proper validation. This can lead to phishing attacks…
- CVE-2023-49394MEDIUMCVSS 6.1EG 6.12024-01-10
Zentao versions 4.1.3 and before has a URL redirect vulnerability, which prevents the system from functioning properly.
- CVE-2023-49438MEDIUMCVSS 6.1EG 6.12023-12-26
An open redirect vulnerability in the python package Flask-Security-Too <=5.3.2 allows attackers to redirect unsuspecting users to malicious sites via a crafted URL by abusing the ?next parameter on the /login and /register routes.
Map vulnerabilities like CWE-601 to your infrastructure
EchelonGraph correlates every CVE — across CWE-601 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →