VYPR

CWE-601

URL Redirection to Untrusted Site ('Open Redirect')

BaseDraftLikelihood: Low

Description

The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-178

CVEs mapped to this weakness (1,693)

page 47 of 85
  • CVE-2026-3318MedMay 8, 2026
    risk 0.34cvss epss 0.00

    Open redirection vulnerability in the latest demo version of the Cradle eCommerce platform. The vulnerability occurs in the login form endpoint, where the ‘returnUrl’ parameter allows redirection because the web application accepts a URL as a parameter without properly…

  • CVE-2025-55624MedAug 22, 2025
    risk 0.34cvss 5.3epss 0.00

    An intent redirection vulnerability in Reolink v4.54.0.4.20250526 allows unauthorized attackers to access internal functions or access non-public components.

  • CVE-2020-36845MedApr 20, 2025
    risk 0.34cvss 5.3epss 0.00

    The KnowBe4 Security Awareness Training application before 2020-01-10 contains a redirect function that does not validate the destination URL before redirecting. The response has a SCRIPT element that sets window.location.href to an arbitrary https URL.

  • CVE-2024-4882MedJul 8, 2024
    risk 0.34cvss epss 0.00

    The user may be redirected to an arbitrary site in Sitefinity 15.1.8321.0 and previous versions.

  • CVE-2024-0545MedJan 15, 2024
    risk 0.34cvss 5.3epss 0.00

    A vulnerability classified as problematic was found in CodeCanyon RISE Ultimate Project Manager 3.5.3. This vulnerability affects unknown code of the file /index.php/signin. The manipulation of the argument redirect with the input http://evil.com leads to open redirect. The…

  • CVE-2023-50456MedDec 10, 2023
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered in Zammad before 6.2.0. An attacker can trigger phishing links in generated notification emails via a crafted first or last name.

  • CVE-2015-10102MedApr 17, 2023
    risk 0.34cvss 6.3epss 0.00

    A vulnerability, which was classified as critical, has been found in Freshdesk Plugin 1.7 on WordPress. Affected by this issue is some unknown functionality. The manipulation leads to open redirect. The attack may be launched remotely. Upgrading to version 1.8 is able to address…

  • CVE-2022-37940MedMar 22, 2023
    risk 0.34cvss 5.3epss 0.00

    Potential security vulnerabilities have been identified in the HPE FlexFabric 5700 Switch Series. These vulnerabilities could be remotely exploited to allow host header injection and URL redirection. HPE has made the following software to resolve the vulnerability in HPE…

  • CVE-2017-20164MedJan 7, 2023
    risk 0.34cvss 6.3epss 0.01

    A vulnerability was found in Symbiote Seed up to 6.0.2. It has been classified as critical. Affected is the function onBeforeSecurityLogin of the file code/extensions/SecurityLoginExtension.php of the component Login. The manipulation of the argument URL leads to open redirect.…

  • CVE-2021-4260MedDec 19, 2022
    risk 0.34cvss 6.3epss 0.00

    A vulnerability was found in oils-js. It has been declared as critical. This vulnerability affects unknown code of the file core/Web.js. The manipulation leads to open redirect. The attack can be initiated remotely. The name of the patch is fad8fbae824a7d367dacb90d56cb02c5cb999d4…

  • CVE-2022-44560MedNov 9, 2022
    risk 0.34cvss 5.3epss 0.00

    The launcher module has an Intent redirection vulnerability. Successful exploitation of this vulnerability may cause launcher module data to be modified.

  • CVE-2022-33712MedJul 12, 2022
    risk 0.34cvss 5.3epss 0.01

    Intent redirection vulnerability using implict intent in Camera prior to versions 12.0.01.64 ,12.0.3.23, 12.0.0.98, 12.0.6.11, 12.0.3.19 in Android S(12) allows attacker to get sensitive information.

  • CVE-2022-1019MedApr 19, 2022
    risk 0.34cvss 5.2epss 0.01

    Automated Logic's WebCtrl Server Version 6.1 'Help' index pages are vulnerable to open redirection. The vulnerability allows an attacker to send a maliciously crafted URL which could result in redirecting the user to a malicious webpage or downloading a malicious file.

  • CVE-2021-21392MedApr 12, 2021
    risk 0.34cvss 6.3epss 0.01

    Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.28.0 requests to user provided domains were not restricted to external IP addresses when…

  • CVE-2021-21337MedMar 8, 2021
    risk 0.34cvss 5.7epss 0.08

    Products.PluggableAuthService is a pluggable Zope authentication and authorization framework. In Products.PluggableAuthService before version 2.6.0 there is an open redirect vulnerability. A maliciously crafted link to the login form and login functionality could redirect the…

  • CVE-2020-11529MedApr 4, 2020
    risk 0.34cvss 6.1epss 0.11

    Common/Grav.php in Grav before 1.7 has an Open Redirect. This is partially fixed in 1.6.23 and still present in 1.6.x.

  • CVE-2019-19613MedMar 16, 2020
    risk 0.34cvss 5.2epss 0.01

    An issue was discovered in Halvotec RaQuest 10.23.10801.0. The login page of the admin application is vulnerable to an Open Redirect attack allowing an attacker to redirect a user to a malicious site after authentication. The attacker needs to be on the same network to modify…

  • CVE-2019-1943MedJul 17, 2019
    risk 0.34cvss 4.7epss 0.11

    A vulnerability in the web interface of Cisco Small Business 200, 300, and 500 Series Switches software could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. The vulnerability is due to improper input validation of the parameters of an HTTP…

  • CVE-2018-8813MedApr 4, 2018
    risk 0.34cvss 4.8epss 0.03

    Open redirect vulnerability in the login[redirect] parameter login functionality in WolfCMS 0.8.3.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a malformed URL.

  • CVE-2026-66829MedAug 6, 2026
    risk 0.33cvss 6.1epss 0.01

    URL Redirection to Untrusted Site ('Open Redirect') vulnerability in the HTML5 scrubber in rrrene html_sanitize_ex allows a remote attacker to force visitors of a page to navigate to a site of the attacker's choosing via a element in sanitized HTML.…