VYPR

CWE-601

URL Redirection to Untrusted Site ('Open Redirect')

BaseDraftLikelihood: Low

Description

The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-178

CVEs mapped to this weakness (1,692)

page 10 of 85
  • CVE-2026-55660HigJul 1, 2026
    risk 0.42cvss epss 0.00

    Tina is a headless content management system. In versions prior to @tinacms/app 2.5.6 and tinacms 3.9.3, cross-origin postMessage handlers and a rich-text URL-sanitization bypass enable stored XSS and session takeover. The library registers window message listeners — the…

  • CVE-2026-34315MedApr 21, 2026
    risk 0.42cvss 6.5epss 0.00

    Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network…

  • CVE-2026-23817MedMar 11, 2026
    risk 0.42cvss 6.5epss 0.00

    A vulnerability in the web-based management interface of AOS-CX Switches could allow an unauthenticated remote attacker to redirect users to an arbitrary URL.

  • CVE-2026-0484MedFeb 10, 2026
    risk 0.42cvss 6.5epss 0.00

    Due to missing authorization check in SAP NetWeaver Application Server ABAP and SAP S/4HANA, an authenticated attacker could access a specific transaction code and modify the text data in the system. This vulnerability has a high impact on integrity of the application with no…

  • CVE-2025-68616HigJan 19, 2026
    risk 0.42cvss 7.5epss 0.01

    WeasyPrint helps web developers to create PDF documents. Prior to version 68.0, a server-side request forgery (SSRF) protection bypass exists in WeasyPrint's `default_url_fetcher`. The vulnerability allows attackers to access internal network resources (such as `localhost`…

  • CVE-2025-63784MedNov 7, 2025
    risk 0.42cvss 6.5epss 0.00

    An Open Redirect vulnerability exists in the OAuth callback handler in file onlook/apps/web/client/src/app/auth/callback/route.ts in Onlook web application 0.2.32. The vulnerability occurs because the application trusts the X-Forwarded-Host header value without proper validation…

  • CVE-2025-9072HigSep 15, 2025
    risk 0.42cvss 7.6epss 0.00

    Mattermost versions 10.10.x <= 10.10.1, 10.5.x <= 10.5.9, 10.9.x <= 10.9.4 fail to validate the redirect_to parameter, allowing an attacker to craft a malicious link that, once a user authenticates with their SAML provider, could post the user’s cookies to an…

  • CVE-2025-52219MedAug 26, 2025
    risk 0.42cvss 6.5epss 0.00

    SelectZero SelectZero Data Observability Platform before 2025.5.2 contains an Open Redirect vulnerability. Legacy UI fields can be used to create arbitrary external links via HTML Injection.

  • CVE-2025-7777MedAug 20, 2025
    risk 0.42cvss 6.5epss 0.00

    The mirror-registry doesn't properly sanitize the host header HTTP header in HTTP request received, allowing an attacker to perform malicious redirects to attacker-controlled domains or phishing campaigns.

  • CVE-2025-52897MedJul 30, 2025
    risk 0.42cvss 6.5epss 0.00

    GLPI is a Free Asset and IT Management Software package. In versions 9.1.0 through 10.0.18, an unauthenticated user can send a malicious link to attempt a phishing attack from the planning feature. This is fixed in version 10.0.19.

  • CVE-2024-57241MedFeb 11, 2025
    risk 0.42cvss 6.5epss 0.01

    Dedecms 5.71sp1 and earlier is vulnerable to URL redirect. In the web application, a logic error does not judge the input GET request resulting in URL redirection.

  • CVE-2024-54728MedJan 27, 2025
    risk 0.42cvss 6.5epss 0.00

    Incorrect access control in BYD QIN PLUS DM-i Dilink OS 3.0_13.1.7.2204050.1 allows unauthorized attackers to access system logcat logs.

  • CVE-2024-56972MedJan 27, 2025
    risk 0.42cvss 6.5epss 0.00

    An issue in Midea Group Co., Ltd Midea Home iOS 9.3.12 allows attackers to access sensitive user information via supplying a crafted link.

  • CVE-2024-56971MedJan 27, 2025
    risk 0.42cvss 6.5epss 0.00

    An issue in Zhiyuan Yuedu (Guangzhou) Literature Information Technology Co., Ltd Shuqi Novel iOS 5.3.8 allows attackers to access sensitive user information via supplying a crafted link.

  • CVE-2024-56969MedJan 27, 2025
    risk 0.42cvss 6.5epss 0.00

    An issue in Pixocial Technology (Singapore) Pte. Ltd BeautyPlus iOS 7.8.010 allows attackers to access sensitive user information via supplying a crafted link.

  • CVE-2024-56968MedJan 27, 2025
    risk 0.42cvss 6.5epss 0.00

    An issue in Shenzhen Intellirocks Tech Co. Ltd Govee Home iOS 6.5.01 allows attackers to access sensitive user information via supplying a crafted payload.

  • CVE-2024-56967MedJan 27, 2025
    risk 0.42cvss 6.5epss 0.00

    An issue in Cloud Whale Interactive Technology LLC. PolyBuzz iOS 2.0.20 allows attackers to access sensitive user information via supplying a crafted link.

  • CVE-2024-56966MedJan 27, 2025
    risk 0.42cvss 6.5epss 0.00

    An issue in Shanghai Xuan Ting Entertainment Information & Technology Co., Ltd Qidian Reader iOS 5.9.384 allows attackers to access sensitive user information via supplying a crafted link.

  • CVE-2024-56965MedJan 27, 2025
    risk 0.42cvss 6.5epss 0.00

    An issue in Shanghai Shizhi Information Technology Co., Ltd Shihuo iOS 8.16.0 allows attackers to access sensitive user information via supplying a crafted link.

  • CVE-2024-56964MedJan 27, 2025
    risk 0.42cvss 6.5epss 0.00

    An issue in Che Hao Duo Used Automobile Agency (Beijing) Co., Ltd Guazi Used Car iOS 10.15.1 allows attackers to access sensitive user information via supplying a crafted link.