VYPR

CWE-601

URL Redirection to Untrusted Site ('Open Redirect')

BaseDraftLikelihood: Low

Description

The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-178

CVEs mapped to this weakness (1,692)

page 64 of 85
  • CVE-2026-48012MedJul 23, 2026
    risk 0.28cvss 4.3epss 0.00

    Shopware is an open commerce platform. Versions 6.7.3.0 through 6.7.10.0 have an open redirect in Shopware's public SSO entry point at `GET /api/oauth/sso/auth`. When the endpoint is reached without the expected SSO session state, the application falls back to the request's…

  • CVE-2026-52802MedJun 24, 2026
    risk 0.28cvss 5.4epss 0.00

    Gogs is an open source self-hosted Git service. Prior to 0.14.3, an open redirect vulnerability exists in Gogs where attacker-controlled redirect_to parameters can bypass validation, allowing redirection to arbitrary external sites. All redirects in Gogs that are validated via…

  • CVE-2026-41479MedJun 22, 2026
    risk 0.28cvss 5.4epss 0.00

    Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.10 and 1.7.1, Authlib's OAuth 2.0 authorization endpoint can be turned into an unauthenticated open redirect when a request uses an unsupported response_type and supplies an…

  • CVE-2026-12804MedJun 21, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was detected in lemonldap-ng up to 2.23.0. Impacted is an unknown function in the library lemonldap-ng-portal/lib/Lemonldap/NG/Portal/CDC.pm of the component SAML Common Domain Cookie Endpoint. Performing a manipulation of the argument url results in open…

  • CVE-2026-20178MedJun 17, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability in the browser-based version of Cisco Webex App could have allowed an unauthenticated, remote attacker to redirect users to a malicious webpage. Cisco has addressed this vulnerability in the Cisco Webex App, and no customer action is needed. This vulnerability…

  • CVE-2025-32748MedJun 17, 2026
    risk 0.28cvss 4.3epss 0.00

    Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) a Host Header Injection vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability to trigger redirections.

  • CVE-2026-46616MedJun 10, 2026
    risk 0.28cvss 5.4epss 0.00

    Umbraco is an ASP.NET CMS. Prior to versions 13.14.0 and 17.4.0, some of the Surface Controllers in the CMS provide to support member related operations fail to validate redirect URLs, making Razor templates that derive 'RedirectUrl' from user-controlled query parameters…

  • CVE-2026-45335MedMay 27, 2026
    risk 0.28cvss 5.4epss 0.00

    WeGIA is a web manager for charitable institutions. Prior to 3.7.3, an Open Redirect vulnerability was identified in the /WeGIA/controle/control.php endpoint of the WeGIA application, specifically through the nextPage parameter when combined with metodo=listarTodos and…

  • CVE-2026-48924MedMay 27, 2026
    risk 0.28cvss 4.3epss 0.00

    Jenkins Bitbucket OAuth Plugin 0.17 and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks.

  • CVE-2026-45448MedMay 14, 2026
    risk 0.28cvss 4.3epss 0.00

    CWE-601 URL redirection to untrusted site ('open redirect')

  • CVE-2026-42525MedApr 29, 2026
    risk 0.28cvss 4.3epss 0.00

    Jenkins Microsoft Entra ID (previously Azure AD) Plugin 666.v6060de32f87d and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks.

  • CVE-2026-30346MedApr 27, 2026
    risk 0.28cvss 4.3epss 0.00

    An open redirect in the /api/google/authorize endpoint of hunvreus DevPush v0.3.2 allows attackers to redirect users to malicious sites via supplying a crafted URL.

  • CVE-2026-40096MedApr 15, 2026
    risk 0.28cvss 5.4epss 0.00

    immich is a high performance self-hosted photo and video management solution. Versions prior to 2.7.3 contain an open redirect vulnerability in the shared album functionality, where the album name is inserted unsanitized into a tag in api.service.ts. A registered attacker…

  • CVE-2026-5467MedApr 3, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was identified in Casdoor 2.356.0. Affected by this issue is some unknown functionality of the component OAuth Authorization Request Handler. Such manipulation of the argument redirect_uri leads to open redirect. It is possible to launch the attack remotely. The…

  • CVE-2026-34442MedMar 31, 2026
    risk 0.28cvss 5.4epss 0.00

    FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.211, host header manipulation in FreeScout version (http://localhost:8080/system/status) allows an attacker to inject an arbitrary domain into generated absolute URLs. This…

  • CVE-2026-4799MedMar 31, 2026
    risk 0.28cvss 4.3epss 0.00

    In Search Guard FLX up to version 4.0.1, it is possible to use specially crafted requests to redirect the user to an untrusted URL.

  • CVE-2026-1166MedMar 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Open Redirect vulnerability in Hitachi Ops Center Administrator.This issue affects Hitachi Ops Center Administrator: from 10.2.0 before 11.0.8.

  • CVE-2026-29105MedMar 19, 2026
    risk 0.28cvss 5.4epss 0.00

    SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, SuiteCRM contains an unauthenticated open redirect vulnerability in the WebToLead capture functionality. A user-supplied POST parameter…

  • CVE-2026-28194MedFeb 25, 2026
    risk 0.28cvss 4.3epss 0.00

    In JetBrains TeamCity before 2025.11.3 open redirect was possible in the React project creation flow

  • CVE-2026-1369MedFeb 22, 2026
    risk 0.28cvss 4.3epss 0.00

    The Conditional CAPTCHA WordPress plugin through 4.0.0 does not validate a parameter before redirecting the user to its value, leading to an Open Redirect issue