CWE-601— URL Redirection to Untrusted Site (Open Redirect)
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.— MITRE CWE catalog
1,634 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-601page 19 of 33
- CVE-2023-4964HIGHCVSS 6.1EG 8.22023-10-30
Potential open redirect vulnerability in opentext Service Management Automation X (SMAX) versions 2020.05, 2020.08, 2020.11, 2021.02, 2021.05, 2021.08, 2021.11, 2022.05, 2022.11 and opentext Asset Management X (AMX) versions 2021.08, 2021…
- CVE-2023-4965MEDIUMCVSS 4.8EG 4.82023-09-14
A vulnerability was found in phpipam 1.5.1. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Header Handler. The manipulation of the argument X-Forwarded-Host leads to open redirect. T…
- CVE-2023-50297MEDIUMCVSS 6.1EG 6.12023-12-26
Open redirect vulnerability in PowerCMS (6 Series, 5 Series, and 4 Series) allows a remote unauthenticated attacker to redirect users to arbitrary web sites via a specially crafted URL. Note that all versions of PowerCMS 3 Series and earli…
- CVE-2023-50345MEDIUMCVSS 6.1EG 6.12024-01-03
HCL DRYiCE MyXalytics is impacted by an Open Redirect vulnerability which could allow an attacker to redirect users to malicious sites, potentially leading to phishing attacks or other security threats.
- CVE-2023-50456MEDIUMCVSS 5.3EG 5.32023-12-10
An issue was discovered in Zammad before 6.2.0. An attacker can trigger phishing links in generated notification emails via a crafted first or last name.
- CVE-2023-50704MEDIUMCVSS 6.1EG 6.12023-12-20
An attacker could construct a URL within the application that causes a redirection to an arbitrary external domain and could be leveraged to facilitate phishing attacks against application users.
- CVE-2023-50771MEDIUMCVSS 6.1EG 6.12023-12-13
Jenkins OpenId Connect Authentication Plugin 2.6 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins, allowing attackers to perform phishing attacks.
- CVE-2023-50963MEDIUMCVSS 6.5EG 6.52024-01-19
IBM Storage Defender - Data Protect 1.0.0 through 1.4.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable sys…
- CVE-2023-51517MEDIUMCVSS 5.4EG 5.42023-12-29
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CodePeople Calculated Fields Form.This issue affects Calculated Fields Form: from n/a through 1.2.28.
- CVE-2023-51675MEDIUMCVSS 5.4EG 5.42023-12-29
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in AAM Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More.This issue affects Advanced Access Manager – Restricted Content, Users & R…
- CVE-2023-5190MEDIUMCVSS 6.1EG 6.12024-02-20
Open redirect vulnerability in the Countries Management’s edit region page in Liferay Portal 7.4.3.45 through 7.4.3.101, and Liferay DXP 2023.Q3 before patch 6, and 7.4 update 45 through 92 allows remote attackers to redirect users to ar…
- CVE-2023-52263MEDIUMCVSS 6.1EG 6.12023-12-30
Brave Browser before 1.59.40 does not properly restrict the schema for WebUI factory and redirect. This is related to browser/brave_content_browser_client.cc and browser/ui/webui/brave_web_ui_controller_factory.cc.
- CVE-2023-5375MEDIUMCVSS 6.1EG 6.32023-10-04
Open Redirect in GitHub repository mosparo/mosparo prior to 1.0.2.
- CVE-2023-53901MEDIUMCVSS 5.4EG 5.42025-12-16
WBCE CMS 1.6.1 contains a cross-site scripting vulnerability that allows attackers to inject malicious HTML and CSS to capture user keystrokes. Attackers can upload a crafted HTML file with CSS-based keylogging techniques to intercept pass…
- CVE-2023-5445MEDIUMCVSS 5.4EG 5.42023-11-17
An open redirect vulnerability in ePolicy Orchestrator prior to 5.10.0 CP1 Update 2, allows a remote low privileged user to modify the URL parameter for the purpose of redirecting URL request(s) to a malicious site. This impacts the dashb…
- CVE-2023-5610MEDIUMCVSS 5.4EG 5.42023-11-20
The Seraphinite Accelerator WordPress plugin before 2.2.29 does not validate the URL to redirect any authenticated user to, leading to an arbitrary redirect
- CVE-2023-5629HIGHCVSS 6.1EG 8.22023-12-14
A CWE-601:URL Redirection to Untrusted Site (‘Open Redirect’) vulnerability exists that could cause disclosure of information through phishing attempts over HTTP.
- CVE-2023-5986HIGHCVSS 6.1EG 8.22023-11-15
A CWE-601 URL Redirection to Untrusted Site vulnerability exists that could cause an openredirect vulnerability leading to a cross site scripting attack. By providing a URL-encoded input attackers can cause the software’s web applicatio…
- CVE-2023-6291HIGHCVSS 7.1EG 7.12024-01-26
A flaw was found in the redirect_uri validation logic in Keycloak. This issue may allow a bypass of otherwise explicitly allowed hosts. A successful attack may lead to an access token being stolen, making it possible for the attacker to im…
- CVE-2023-6380MEDIUMCVSS 6.1EG 6.12023-12-13
Open redirect vulnerability has been found in the Open CMS product affecting versions 14 and 15 of the 'Mercury' template. An attacker could create a specially crafted URL and send it to a specific user to redirect them to a malicious site…
- CVE-2023-6389MEDIUMCVSS 6.1EG 6.12024-01-29
The WordPress Toolbar WordPress plugin through 2.2.6 redirects to any URL via the "wptbto" parameter. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them…
- CVE-2023-6545MEDIUMCVSS 4.7EG 4.72023-12-14
The package authelia-bhf included in Beckhoffs TwinCAT/BSD is prone to an open redirect that allows a remote unprivileged attacker to redirect a user to another site. This may have limited impact to integrity and does solely affect antheli…
- CVE-2023-6552MEDIUMCVSS 6.1EG 6.12024-01-08
Lack of "current" GET parameter validation during the action of changing a language leads to an open redirect vulnerability.
- CVE-2023-6786MEDIUMCVSS 6.1EG 6.12025-05-15
The Payment Gateway for Telcell WordPress plugin through 2.0.1 does not validate the api_url parameter before redirecting the user to its value, leading to an Open Redirect issue
- CVE-2023-6812MEDIUMCVSS 4.3EG 4.32024-05-14
The WP Compress – Image Optimizer [All-In-One plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 6.20.01. This is due to insufficient validation on the redirect url supplied via the 'css' parameter.…
- CVE-2023-6927MEDIUMCVSS 6.1EG 6.12023-12-18
A flaw was found in Keycloak. This issue may allow an attacker to steal authorization codes or tokens from clients using a wildcard in the JARM response mode "form_post.jwt" which could be used to bypass the security patch implemented to a…
- CVE-2024-0250MEDIUMCVSS 6.1EG 6.12024-02-12
The Analytics Insights for Google Analytics 4 (AIWP) WordPress plugin before 6.3 is vulnerable to Open Redirect due to insufficient validation on the redirect oauth2callback.php file. This makes it possible for unauthenticated attackers to…
- CVE-2024-0319MEDIUMCVSS 5.4EG 5.42024-01-15
Open Redirect vulnerability in FireEye HXTool affecting version 4.6, the exploitation of which could allow an attacker to redirect a legitimate user to a malicious page by changing the 'redirect_uri' parameter.
- CVE-2024-0337MEDIUMCVSS 6.1EG 6.12024-03-20
The Travelpayouts: All Travel Brands in One Place WordPress plugin through 1.1.15 is vulnerable to Open Redirect due to insufficient validation on the travelpayouts_redirect variable. This makes it possible for unauthenticated attackers to…
- CVE-2024-0545MEDIUMCVSS 5.3EG 5.32024-01-15
A vulnerability classified as problematic was found in CodeCanyon RISE Ultimate Project Manager 3.5.3. This vulnerability affects unknown code of the file /index.php/signin. The manipulation of the argument redirect with the input http://e…
- CVE-2024-0781LOWCVSS 3.5EG 3.52024-01-22
A vulnerability, which was classified as problematic, was found in CodeAstro Internet Banking System 1.0. This affects an unknown part of the file pages_client_signup.php. The manipulation of the argument Client Full Name with the input <m…
- CVE-2024-0854MEDIUMCVSS 5.4EG 5.42024-01-24
URL redirection to untrusted site ('Open Redirect') vulnerability in file access component in Synology DiskStation Manager (DSM) before 6.2.4-25556-8, 7.0.1-42218-7, 7.1.1-42962-7 and 7.2.1-69057-2 allows remote authenticated users to cond…
- CVE-2024-0953MEDIUMCVSS 6.1EG 6.12024-02-05
When a user scans a QR Code with the QR Code Scanner feature, the user is not prompted before being navigated to the page specified in the code. This may surprise the user and potentially direct them to unwanted content. This vulnerabilit…
- CVE-2024-10812MEDIUMCVSS 6.1EG 6.12025-03-20
An open redirect vulnerability exists in binary-husky/gpt_academic version 3.83. The vulnerability occurs when a user is redirected to a URL specified by user-controlled input in the 'file' parameter without proper validation or sanitizati…
- CVE-2024-10908MEDIUMCVSS 6.1EG 6.12025-03-20
An open redirect vulnerability in lm-sys/fastchat Release v0.2.36 allows a remote unauthenticated attacker to redirect users to arbitrary websites via a specially crafted URL. This can be exploited for phishing attacks, malware distributio…
- CVE-2024-11044MEDIUMCVSS 6.1EG 6.12025-03-20
An open redirect vulnerability in automatic1111/stable-diffusion-webui version 1.10.0 allows a remote unauthenticated attacker to redirect users to arbitrary websites via a specially crafted URL. This vulnerability can be exploited to cond…
- CVE-2024-11207MEDIUMCVSS 4.3EG 4.32024-11-14
A vulnerability has been found in Apereo CAS 6.6 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /login. The manipulation of the argument redirect_uri leads to open redirect. The attack…
- CVE-2024-11274HIGHCVSS 8.7EG 8.72024-12-12
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.1 prior to 17.4.6, starting from 17.5 prior to 17.5.4, and starting from 17.6 prior to 17.6.2, injection of NEL headers in k8s proxy response could lead to ses…
- CVE-2024-1183MEDIUMCVSS 6.5EG 6.52024-04-16
An SSRF (Server-Side Request Forgery) vulnerability exists in the gradio-app/gradio repository, allowing attackers to scan and identify open ports within an internal network. By manipulating the 'file' parameter in a GET request, an attack…
- CVE-2024-11955MEDIUMCVSS 4.3EG 4.32025-02-25
A vulnerability was found in GLPI up to 10.0.17. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /index.php. The manipulation of the argument redirect leads to open redirect. The …
- CVE-2024-1227MEDIUMCVSS 6.5EG 6.52024-03-12
An open redirect vulnerability, the exploitation of which could allow an attacker to create a custom URL and redirect a legitimate page to a malicious site.
- CVE-2024-1240MEDIUMCVSS 6.1EG 6.12024-11-15
An open redirection vulnerability exists in pyload/pyload version 0.5.0. The vulnerability is due to improper handling of the 'next' parameter in the login functionality. An attacker can exploit this vulnerability to redirect users to mali…
- CVE-2024-12561MEDIUMCVSS 6.1EG 6.12025-05-21
The Affiliate Sales in Google Analytics and other tools plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 2.0.0. This is due to insufficient validation on the redirect url supplied via the 'afflink' …
- CVE-2024-12924MEDIUMCVSS 6.3EG 6.32025-09-01
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Akınsoft QR Menü allows Forceful Browsing, Phishing. This issue affects QR Menü: from s1.05.05 before v1.05.12.
- CVE-2024-12990MEDIUMCVSS 4.3EG 4.32024-12-27
A vulnerability was found in ruifang-tech Rebuild 3.8.6. It has been classified as problematic. This affects an unknown part of the file /user/admin-verify of the component Admin Verification Page. The manipulation of the argument nexturl …
- CVE-2024-13888HIGHCVSS 7.2EG 7.22025-02-20
The WPMobile.App plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 11.56. This is due to insufficient validation on the redirect URL supplied via the 'redirect' parameter. This makes it possible for …
- CVE-2024-13983MEDIUMCVSS 6.3EG 6.32025-11-14
Inappropriate implementation in Lens in Google Chrome on iOS prior to 136.0.7103.59 allowed a remote attacker to perform UI spoofing via a crafted QR code. (Chromium security severity: Low)
- CVE-2024-1440MEDIUMCVSS 5.4EG 5.42025-06-02
An open redirection vulnerability exists in multiple WSO2 products due to improper validation of the multi-option URL in the authentication endpoint when multi-option authentication is enabled. A malicious actor can craft a valid link that…
- CVE-2024-20369MEDIUMCVSS 4.7EG 4.72024-05-15
A vulnerability in the web-based management interface of Cisco Crosswork Network Services Orchestrator (NSO) could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to impr…
- CVE-2024-20400MEDIUMCVSS 4.7EG 4.72024-07-17
A vulnerability in the web-based management interface of Cisco Expressway Series could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper input validation of HTTP …
Map vulnerabilities like CWE-601 to your infrastructure
EchelonGraph correlates every CVE — across CWE-601 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →