CWE-601— URL Redirection to Untrusted Site (Open Redirect)
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.— MITRE CWE catalog
1,741 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-601page 29 of 35
- CVE-2026-18266MEDIUMCVSS 5.4EG 5.42026-07-29
Dify AI Workflow oauth_redirect_url Open Redirect Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Dify. User interaction is required to exploit this vulnerability in …
- CVE-2026-18721MEDIUMCVSS 4.3EG 4.32026-08-04
A vulnerability has been found in kalcaddle kodbox 1.67 Build 02. This issue affects some unknown processing of the file /user/sso/apiLogin of the component SSO API Login. The manipulation of the argument callbackUrl leads to open redirect…
- CVE-2026-19078MEDIUMCVSS 4.3EG 4.32026-08-11
A flaw was found in the oauth-server component. This open redirect vulnerability occurs when the 'then' parameter in the grant approval handler is not properly validated. A remote attacker can craft a malicious URL that, when approved or d…
- CVE-2026-1970MEDIUMCVSS 6.1EG 6.12026-02-05
A flaw has been found in Edimax BR-6258n up to 1.18. This issue affects the function formStaDrvSetup of the file /goform/formStaDrvSetup. This manipulation of the argument submit-url causes open redirect. The attack can be initiated remote…
- CVE-2026-20060MEDIUMCVSS 4.7EG 4.72026-04-15
A vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper input validation of HTTP r…
- CVE-2026-20123MEDIUMCVSS 6.1EG 6.12026-02-04
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This v…
- CVE-2026-20178MEDIUMCVSS 4.3EG 4.32026-06-17
A vulnerability in the browser-based version of Cisco Webex App could have allowed an unauthenticated, remote attacker to redirect users to a malicious webpage. Cisco has addressed this vulnerability in the Cisco Webex App, and no customer…
- CVE-2026-20994MEDIUMCVSS 6.1EG 6.12026-03-16
URL redirection in Samsung Account prior to version 15.5.01.1 allows local attackers to potentially get access token.
- CVE-2026-21295LOWCVSS 3.1EG 3.12026-03-11
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. An attacker could leverage this vulnerability to red…
- CVE-2026-2153MEDIUMCVSS 6.1EG 6.12026-02-08
A vulnerability was determined in mwielgoszewski doorman up to 0.6. This issue affects the function is_safe_url of the file doorman/users/views.py. Executing a manipulation of the argument Next can lead to open redirect. The attack may be …
- CVE-2026-21741LOWCVSS 2.4EG 2.42026-04-14
An URL Redirection to Untrusted Site ('Open Redirect') vulnerability [CWE-601] vulnerability in Fortinet FortiNAC-F 7.6.0 through 7.6.5, FortiNAC-F 7.4 all versions, FortiNAC-F 7.2 all versions may allow a remote privileged attacker with s…
- CVE-2026-21826MEDIUMCVSS 6.1EG 6.12026-06-05
HCL Digital Experience and HCL Digital Experience Compose could be susceptible to Host header injection. An attacker can manipulate the Host header and cause the application to behave in unexpected ways.
- CVE-2026-21879MEDIUMCVSS 6.1EG 6.12026-01-08
Kanboard is project management software focused on Kanban methodology. Versions 1.2.48 and below are vulnerable to an Open Redirect attack that allows malicious actors to redirect authenticated users to attacker-controlled websites. By cra…
- CVE-2026-22032MEDIUMCVSS 6.1EG 6.12026-01-08
Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 11.14.0, an open redirect vulnerability exists in the Directus SAML authentication callback endpoint. During SAML authentication, the `RelayS…
- CVE-2026-22560MEDIUMCVSS 5.3EG 5.32026-04-10
An open redirect vulnerability in Rocket.Chat versions prior to 8.4.0 allows users to be redirected to arbitrary URLs by manipulating parameters within a SAML endpoint.
- CVE-2026-22912MEDIUMCVSS 6.1EG 6.12026-01-15
Improper validation of a login parameter may allow attackers to redirect users to malicious websites after authentication. This can lead to various risk including stealing credentials from unsuspecting users.
- CVE-2026-23726MEDIUMCVSS 6.1EG 6.12026-01-16
WeGIA is a web manager for charitable institutions. Prior to 3.6.2, An Open Redirect vulnerability was identified in the /WeGIA/controle/control.php endpoint of the WeGIA application, specifically through the nextPage parameter when combin…
- CVE-2026-23727MEDIUMCVSS 6.1EG 6.12026-01-16
WeGIA is a web manager for charitable institutions. Prior to 3.6.2, an Open Redirect vulnerability was identified in the /WeGIA/controle/control.php endpoint of the WeGIA application, specifically through the nextPage parameter when combin…
- CVE-2026-23728MEDIUMCVSS 6.1EG 6.12026-01-16
WeGIA is a web manager for charitable institutions. Prior to 3.6.2, an Open Redirect vulnerability was identified in the /WeGIA/controle/control.php endpoint of the WeGIA application, specifically through the nextPage parameter when combin…
- CVE-2026-23729MEDIUMCVSS 6.1EG 6.12026-01-16
WeGIA is a web manager for charitable institutions. Prior to 3.6.2, an Open Redirect vulnerability was identified in the /WeGIA/controle/control.php endpoint of the WeGIA application, specifically through the nextPage parameter when combin…
- CVE-2026-23730MEDIUMCVSS 6.1EG 6.12026-01-16
WeGIA is a web manager for charitable institutions. Prior to 3.6.2, an Open Redirect vulnerability was identified in the /WeGIA/controle/control.php endpoint of the WeGIA application, specifically through the nextPage parameter when combin…
- CVE-2026-2376MEDIUMCVSS 5.4EG 5.42026-03-12
A flaw was found in mirror-registry where an authenticated user can trick the system into accessing unintended internal or restricted systems by providing malicious web addresses. When the application processes these addresses, it automa…
- CVE-2026-23817MEDIUMCVSS 6.1EG 6.52026-03-11
A vulnerability in the web-based management interface of AOS-CX Switches could allow an unauthenticated remote attacker to redirect users to an arbitrary URL.
- CVE-2026-23818HIGHCVSS 8.8EG 8.82026-04-07
A vulnerability has been identified in the graphical user interface (GUI) of HPE Aruba Networking Private 5G Core On-Prem that could allow an attacker to abuse an open redirect vulnerability in the login flow using a crafted URL. Successfu…
- CVE-2026-24052HIGHCVSS 7.4EG 7.42026-02-03
Claude Code is an agentic coding tool. Prior to version 1.0.111, Claude Code contained insufficient URL validation in its trusted domain verification mechanism for WebFetch requests. The application used a startsWith() function to validate…
- CVE-2026-24323MEDIUMCVSS 6.1EG 6.12026-02-10
The BSP applications allow an unauthenticated user to inject malicious script content via user-controlled URL parameters that are not sufficiently sanitized. When a victim accesses a crafted URL, the injected script is executed in the vict…
- CVE-2026-24328MEDIUMCVSS 6.1EG 6.12026-02-10
SAP TAF_APPLAUNCHER within Business Server Pages allows unauthenticated attacker to craft malicious links that, when clicked by a victim, redirect them to attacker?controlled sites, potentially exposing or altering sensitive information in…
- CVE-2026-2475LOWCVSS 3.1EG 3.12026-04-01
IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 could allow a r…
- CVE-2026-24768MEDIUMCVSS 6.1EG 6.12026-01-28
NocoDB is software for building databases as spreadsheets. Prior to version 0.301.0, an unvalidated redirect (open redirect) vulnerability exists in NocoDB’s login flow due to missing validation of the `continueAfterSignIn` parameter. Du…
- CVE-2026-24847MEDIUMCVSS 6.1EG 6.12026-02-25
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the Eye Exam form module allows any authenticated user to be redirected to an arbitrary external URL. This can…
- CVE-2026-25149MEDIUMCVSS 6.1EG 6.12026-02-03
Qwik is a performance focused javascript framework. Prior to version 1.19.0, an Open Redirect vulnerability in Qwik City's default request handler middleware allows a remote attacker to redirect users to arbitrary protocol-relative URLs. S…
- CVE-2026-25198MEDIUMCVSS 4.7EG 4.72026-02-05
web2py versions 2.27.1-stable+timestamp.2023.11.16.08.03.57 and prior contain an open redirect vulnerability. If this vulnerability is exploited, the user may be redirected to an arbitrary website when accessing a specially crafted URL. As…
- CVE-2026-25392MEDIUMCVSS 4.7EG 4.72026-02-19
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in KaizenCoders Update URLs – Quick and Easy way to search old links and replace them with new links in WordPress update-urls allows Phishing.This issue affects Update URL…
- CVE-2026-25477MEDIUMCVSS 6.1EG 6.12026-03-02
AFFiNE is an open-source, all-in-one workspace and an operating system. Prior to version 0.26.0, there is an Open Redirect vulnerability located at the /redirect-proxy endpoint. The flaw exists in the domain validation logic, where an impr…
- CVE-2026-25649HIGHCVSS 8.7EG 8.72026-02-23
Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain an issue in which authenticated users can steal OAuth 2.0 authorization codes by exploiting an open redirect vulnerability in two OIDC-related endpo…
- CVE-2026-25651MEDIUMCVSS 6.1EG 6.12026-02-06
client-certificate-auth is middleware for Node.js implementing client SSL certificate authentication/authorization. Versions 0.2.1 and 0.3.0 of client-certificate-auth contain an open redirect vulnerability. The middleware unconditionally …
- CVE-2026-25779MEDIUMCVSS 6.1EG 6.12026-06-17
Gitea versions up to and including 1.25.4 allow redirect bypasses through raw or percent-encoded backslashes in redirect_to values.
- CVE-2026-25854MEDIUMCVSS 6.1EG 6.12026-04-09
Occasional URL redirection to untrusted Site ('Open Redirect') vulnerability in Apache Tomcat via the LoadBalancerDrainingValve. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M1 through 10.1.52, from 9.0.0.…
- CVE-2026-25956MEDIUMCVSS 6.1EG 6.12026-02-10
Frappe is a full-stack web application framework. Prior to 14.99.14 and 15.94.0, an attacker could craft a malicious signup URL for a frappe site which could lead to an open redirect (or reflected XSS, depending on the crafted payload) whe…
- CVE-2026-26003MEDIUMCVSS 5.4EG 5.42026-02-10
FastGPT is an AI Agent building platform. From 4.14.0 to 4.14.5, attackers can directly access the plugin system through FastGPT/api/plugin/xxx without authentication, thereby threatening the plugin system. This may cause the plugin system…
- CVE-2026-2709LOWCVSS 3.5EG 3.52026-02-19
A flaw has been found in busy up to 2.5.5. The affected element is an unknown function of the file source-code/busy-master/src/server/app.js of the component Callback Handler. Executing a manipulation of the argument state can lead to open…
- CVE-2026-27191MEDIUMCVSS 6.1EG 6.12026-02-21
Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. Versions 5.0.39 and below the redirect query parameter is appended to the base origin without validation, allowing attackers to steal…
- CVE-2026-27736MEDIUMCVSS 6.1EG 6.12026-02-25
BigBlueButton is an open-source virtual classroom. In versions on the 3.x branch prior to 3.0.20, the string received with errorRedirectUrl lacks validation, using it directly in the respondWithRedirect function leads to an Open Redirect v…
- CVE-2026-27738MEDIUMCVSS 6.9EG 6.92026-02-25
The Angular SSR is a server-rise rendering tool for Angular applications. An Open Redirect vulnerability exists in the internal URL processing logic in versions on the 19.x branch prior to 19.2.21, the 20.x branch prior to 20.3.17, and the…
- CVE-2026-27982MEDIUMCVSS 6.1EG 6.12026-03-05
An open redirect vulnerability exists in django-allauth versions prior to 65.14.1 when SAML IdP initiated SSO is enabled (it is disabled by default), which may allow an attacker to redirect users to an arbitrary external website via a craf…
- CVE-2026-28106MEDIUMCVSS 4.7EG 4.72026-03-06
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Kings Plugins B2BKing Premium allows Phishing.This issue affects B2BKing Premium: from n/a before 5.4.20.
- CVE-2026-2813MEDIUMCVSS 4.1EG 4.72026-05-20
ArcGIS Server contains an input validation weakness in the login redirection workflow. An Authenticated attacker could exploit this issue by sending a specially crafted request, Successful exploitation may result in the application redirec…
- CVE-2026-28194MEDIUMCVSS 6.1EG 6.12026-02-25
In JetBrains TeamCity before 2025.11.3 open redirect was possible in the React project creation flow
- CVE-2026-28301MEDIUMCVSS 4.8EG 4.82026-06-09
A vulnerability in which an attacker can provide a crafted external URL that may redirect a user to an unintended website.
- CVE-2026-28413MEDIUMCVSS 6.1EG 6.12026-03-02
Products.isurlinportal is a replacement for isURLInPortal method in Plone. Prior to versions 2.1.0, 3.1.0, and 4.0.0, a url /login?came_from=////evil.example may redirect to an external website after login. This issue has been patched in v…
Map vulnerabilities like CWE-601 to your infrastructure
EchelonGraph correlates every CVE — across CWE-601 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →