VYPR

CWE-601

URL Redirection to Untrusted Site ('Open Redirect')

BaseDraftLikelihood: Low

Description

The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-178

CVEs mapped to this weakness (1,692)

page 14 of 85
  • CVE-2026-42230MedMay 4, 2026
    risk 0.40cvss 6.1epss 0.00

    n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the /mcp-oauth/register endpoint accepted OAuth client registrations without authentication, allowing arbitrary redirect_uri values to be registered. When a user denies the MCP…

  • CVE-2026-34284MedApr 21, 2026
    risk 0.40cvss 6.1epss 0.00

    Vulnerability in the Oracle Business Process Management Suite product of Oracle Fusion Middleware (component: Human workflow 11g+). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network…

  • CVE-2026-34283MedApr 21, 2026
    risk 0.40cvss 6.1epss 0.00

    Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Identity Console). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to…

  • CVE-2026-34257MedApr 14, 2026
    risk 0.40cvss 6.1epss 0.00

    Due to an Open Redirect vulnerability in SAP NetWeaver Application Server ABAP, an unauthenticated attacker could craft malicious URL that, if accessed by a victim, they could be redirected to the page controlled by the attacker. This causes low impact on confidentiality and…

  • CVE-2026-6203MedApr 13, 2026
    risk 0.40cvss 6.1epss 0.01

    The User Registration & Membership plugin for WordPress is vulnerable to Open Redirect in versions up to and including 5.1.4. This is due to insufficient validation of user-supplied URLs passed via the 'redirect_to_on_logout' GET parameter before redirecting users. The…

  • CVE-2025-61166MedApr 6, 2026
    risk 0.40cvss 6.1epss 0.00

    An open redirect in Ascertia SigningHub User v10.0 allows attackers to redirect users to a malicious site via a crafted URL.

  • CVE-2026-3872HigApr 2, 2026
    risk 0.40cvss 7.3epss 0.00

    A flaw was found in Keycloak. This issue allows an attacker, who controls another path on the same web server, to bypass the allowed path in redirect Uniform Resource Identifiers (URIs) that use a wildcard. A successful attack may lead to the theft of an access token, resulting…

  • CVE-2026-20994MedMar 16, 2026
    risk 0.40cvss 6.1epss 0.00

    URL redirection in Samsung Account prior to version 15.5.01.1 allows local attackers to potentially get access token.

  • CVE-2026-3824MedMar 11, 2026
    risk 0.40cvss 6.1epss 0.00

    IFTOP developed by WellChoose has an Open redirect vulnerability, allowing authenticated remote attackers to craft a URL that tricks users into visiting malicious website.

  • CVE-2025-70032MedMar 9, 2026
    risk 0.40cvss 6.1epss 0.00

    An issue pertaining to CWE-601: URL Redirection to Untrusted Site was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4.

  • CVE-2025-70037MedMar 9, 2026
    risk 0.40cvss 6.1epss 0.00

    An issue pertaining to CWE-601: URL Redirection to Untrusted Site was discovered in linagora Twake v2023.Q1.1223. This allows attackers to obtain sensitive information and execute arbitrary code.

  • CVE-2026-25477MedMar 2, 2026
    risk 0.40cvss 6.1epss 0.00

    AFFiNE is an open-source, all-in-one workspace and an operating system. Prior to version 0.26.0, there is an Open Redirect vulnerability located at the /redirect-proxy endpoint. The flaw exists in the domain validation logic, where an improperly anchored Regular Expression…

  • CVE-2025-71244MedFeb 19, 2026
    risk 0.40cvss 6.1epss 0.00

    SPIP before 4.4.5 and 4.3.9 allows an Open Redirect via the login form when used in AJAX mode. An attacker can craft a malicious URL that, when visited by a victim, redirects them to an arbitrary external site after login. This vulnerability only affects sites where the login…

  • CVE-2026-1296MedFeb 18, 2026
    risk 0.40cvss 6.1epss 0.00

    The Frontend Post Submission Manager Lite plugin for WordPress is vulnerable to Open Redirection in all versions up to, and including, 1.2.7 due to insufficient validation on the 'requested_page' POST parameter in the verify_username_password function. This makes it possible for…

  • CVE-2026-24328MedFeb 10, 2026
    risk 0.40cvss 6.1epss 0.00

    SAP TAF_APPLAUNCHER within Business Server Pages allows unauthenticated attacker to craft malicious links that, when clicked by a victim, redirect them to attacker?controlled sites, potentially exposing or altering sensitive information in the victim�s browser. This results in…

  • CVE-2026-24323MedFeb 10, 2026
    risk 0.40cvss 6.1epss 0.00

    The BSP applications allow an unauthenticated user to inject malicious script content via user-controlled URL parameters that are not sufficiently sanitized. When a victim accesses a crafted URL, the injected script is executed in the victim�s browser, leading to a low impact…

  • CVE-2025-66596MedFeb 9, 2026
    risk 0.40cvss 6.1epss 0.00

    A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product does not properly validate request headers. When an attacker inserts an invalid host header, users could be redirected to malicious sites. The affected products and…

  • CVE-2025-55060MedDec 29, 2025
    risk 0.40cvss 6.1epss 0.00

    CWE-601 URL Redirection to Untrusted Site ('Open Redirect')

  • CVE-2025-60935MedDec 24, 2025
    risk 0.40cvss 6.1epss 0.00

    An open redirect vulnerability in the login endpoint of Blitz Panel v1.17.0 allows attackers to redirect users to malicious domains via a crafted URL. This issue affects the next_url parameter in the login endpoint and could lead to phishing or token theft after successful…

  • CVE-2025-34504MedDec 11, 2025
    risk 0.40cvss 6.1epss 0.00

    KodExplorer 4.52 contains an open redirect vulnerability in the user login page that allows attackers to manipulate the 'link' parameter. Attackers can craft malicious URLs in the link parameter to redirect users to arbitrary external websites after authentication.