VYPR

CWE-601

URL Redirection to Untrusted Site ('Open Redirect')

BaseDraftLikelihood: Low

Description

The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-178

CVEs mapped to this weakness (1,767)

page 16 of 89
  • CVE-2026-3824MedMar 11, 2026
    risk 0.40cvss 6.1epss 0.00

    IFTOP developed by WellChoose has an Open redirect vulnerability, allowing authenticated remote attackers to craft a URL that tricks users into visiting malicious website.

  • CVE-2025-70032MedMar 9, 2026
    risk 0.40cvss 6.1epss 0.00

    An issue pertaining to CWE-601: URL Redirection to Untrusted Site was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4.

  • CVE-2025-70037MedMar 9, 2026
    risk 0.40cvss 6.1epss 0.00

    An issue pertaining to CWE-601: URL Redirection to Untrusted Site was discovered in linagora Twake v2023.Q1.1223. This allows attackers to obtain sensitive information and execute arbitrary code.

  • CVE-2026-25477MedMar 2, 2026
    risk 0.40cvss 6.1epss 0.00

    AFFiNE is an open-source, all-in-one workspace and an operating system. Prior to version 0.26.0, there is an Open Redirect vulnerability located at the /redirect-proxy endpoint. The flaw exists in the domain validation logic, where an improperly anchored Regular Expression…

  • CVE-2025-71244MedFeb 19, 2026
    risk 0.40cvss 6.1epss 0.00

    SPIP before 4.4.5 and 4.3.9 allows an Open Redirect via the login form when used in AJAX mode. An attacker can craft a malicious URL that, when visited by a victim, redirects them to an arbitrary external site after login. This vulnerability only affects sites where the login…

  • CVE-2026-1296MedFeb 18, 2026
    risk 0.40cvss 6.1epss 0.00

    The Frontend Post Submission Manager Lite plugin for WordPress is vulnerable to Open Redirection in all versions up to, and including, 1.2.7 due to insufficient validation on the 'requested_page' POST parameter in the verify_username_password function. This makes it possible for…

  • CVE-2026-24328MedFeb 10, 2026
    risk 0.40cvss 6.1epss 0.00

    SAP TAF_APPLAUNCHER within Business Server Pages allows unauthenticated attacker to craft malicious links that, when clicked by a victim, redirect them to attacker?controlled sites, potentially exposing or altering sensitive information in the victim�s browser. This results in…

  • CVE-2026-24323MedFeb 10, 2026
    risk 0.40cvss 6.1epss 0.00

    The BSP applications allow an unauthenticated user to inject malicious script content via user-controlled URL parameters that are not sufficiently sanitized. When a victim accesses a crafted URL, the injected script is executed in the victim�s browser, leading to a low impact…

  • CVE-2025-66596MedFeb 9, 2026
    risk 0.40cvss 6.1epss 0.00

    A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product does not properly validate request headers. When an attacker inserts an invalid host header, users could be redirected to malicious sites. The affected products and…

  • CVE-2025-55060MedDec 29, 2025
    risk 0.40cvss 6.1epss 0.00

    CWE-601 URL Redirection to Untrusted Site ('Open Redirect')

  • CVE-2025-60935MedDec 24, 2025
    risk 0.40cvss 6.1epss 0.00

    An open redirect vulnerability in the login endpoint of Blitz Panel v1.17.0 allows attackers to redirect users to malicious domains via a crafted URL. This issue affects the next_url parameter in the login endpoint and could lead to phishing or token theft after successful…

  • CVE-2025-34504MedDec 11, 2025
    risk 0.40cvss 6.1epss 0.00

    KodExplorer 4.52 contains an open redirect vulnerability in the user login page that allows attackers to manipulate the 'link' parameter. Attackers can craft malicious URLs in the link parameter to redirect users to arbitrary external websites after authentication.

  • CVE-2025-13819MedDec 1, 2025
    risk 0.40cvss 6.1epss 0.00

    Open redirect in the web server component of MiR Robot and Fleet software allows a remote attacker to redirect users to arbitrary external websites via a crafted parameter, facilitating phishing or social engineering attacks.

  • CVE-2025-63828MedNov 18, 2025
    risk 0.40cvss 6.1epss 0.00

    Host Header Injection vulnerability in Backdrop CMS 1.32.1 allows attackers to manipulate the Host header in password reset requests, leading to redirects to malicious domains and potential session hijacking via cookie injection.

  • CVE-2025-42924MedNov 11, 2025
    risk 0.40cvss 6.1epss 0.00

    SAP S/4HANA landscape SAP E-Recruiting BSP allows an unauthenticated attacker to craft malicious links, when clicked the victim could be redirected to the page controlled by the attacker. This has low impact on confidentiality and integrity of the application with no impact on…

  • CVE-2025-42893MedNov 11, 2025
    risk 0.40cvss 6.1epss 0.00

    Due to an Open Redirect vulnerability in SAP Business Connector, an unauthenticated attacker could craft a malicious URL that, if accessed by a victim, redirects them to an attacker-controlled site displayed within an embedded frame. Successful exploitation could allow the…

  • CVE-2025-12789MedNov 7, 2025
    risk 0.40cvss 6.1epss 0.00

    A flaw was found in Red Hat Single Sign-On. This issue is an Open Redirect vulnerability that occurs during the logout process. The redirect_uri parameter associated with the openid-connect logout protocol does not properly validate the provided URL.

  • CVE-2025-62266MedOct 30, 2025
    risk 0.40cvss 6.1epss 0.00

    By default, Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP 2024.Q1.1 through 2024.Q1.5, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions is vulnerable to DNS rebinding…

  • CVE-2025-50736MedOct 30, 2025
    risk 0.40cvss 6.1epss 0.00

    An open redirect vulnerability exists in Byaidu PDFMathTranslate v1.9.9 that allows attackers to craft URLs that cause the application to redirect users to arbitrary external websites via the file parameter to the /gradio_api endpoint. This vulnerability could be exploited for…

  • CVE-2025-61753MedOct 21, 2025
    risk 0.40cvss 6.1epss 0.00

    Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Miscellaneous). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle…