VYPR

CWE-601

URL Redirection to Untrusted Site ('Open Redirect')

BaseDraftLikelihood: Low

Description

The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-178

CVEs mapped to this weakness (1,692)

page 65 of 85
  • CVE-2025-65717MedFeb 16, 2026
    risk 0.28cvss 4.3epss 0.01

    An issue in Visual Studio Code Extensions Live Server v5.7.9 allows attackers to exfiltrate files via user interaction with a crafted HTML page.

  • CVE-2025-2418MedFeb 16, 2026
    risk 0.28cvss 4.3epss 0.00

    URL Redirection to Untrusted Site ('Open Redirect') vulnerability in TR7 Cyber ​​Defense Inc. Web Application Firewall allows Phishing. This issue affects Web Application Firewall: from 4.30 before v1.4.0.117.

  • CVE-2026-2153MedFeb 8, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was determined in mwielgoszewski doorman up to 0.6. This issue affects the function is_safe_url of the file doorman/users/views.py. Executing a manipulation of the argument Next can lead to open redirect. The attack may be launched remotely. The exploit has been…

  • CVE-2026-20123MedFeb 4, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper input…

  • CVE-2026-22912MedJan 15, 2026
    risk 0.28cvss 4.3epss 0.00

    Improper validation of a login parameter may allow attackers to redirect users to malicious websites after authentication. This can lead to various risk including stealing credentials from unsuspecting users.

  • CVE-2025-67502MedDec 10, 2025
    risk 0.28cvss 5.4epss 0.00

    Taguette is an open source qualitative research tool. In versions 1.5.1 and below, attackers can craft malicious URLs that redirect users to arbitrary external websites after authentication. The application accepts a user-controlled next parameter and uses it directly in HTTP…

  • CVE-2025-54196MedOct 14, 2025
    risk 0.28cvss 4.3epss 0.00

    Adobe Connect versions 12.9 and earlier are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. An attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue requires user interaction in that a…

  • CVE-2025-35059MedOct 9, 2025
    risk 0.28cvss 4.3epss 0.00

    Newforma Info Exchange (NIX) '/DownloadWeb/hyperlinkredirect.aspx' provides an unauthenticated URL redirect via the 'nhl' parameter.

  • CVE-2025-10229MedSep 10, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability has been found in Freshwork up to 1.2.3. This impacts an unknown function of the file /api/v2/logout. Such manipulation of the argument post_logout_redirect_uri leads to open redirect. The attack can be executed remotely. The exploit has been disclosed to the…

  • CVE-2025-20291MedSep 3, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability in Cisco Webex Meetings could have allowed an unauthenticated, remote attacker to redirect a targeted Webex Meetings user to an untrusted website. Cisco has addressed this vulnerability in the Cisco Webex Meetings service, and no customer action is needed. …

  • CVE-2025-55706MedAug 20, 2025
    risk 0.28cvss 4.3epss 0.00

    URL redirection to untrusted site ('Open Redirect') issue exists in Movable Type. If this vulnerability is exploited, an invalid parameter may be inserted into the password reset page, which may lead to redirection to an arbitrary URL.

  • CVE-2025-7785MedJul 18, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability classified as problematic was found in thinkgem JeeSite up to 5.12.0. This vulnerability affects the function sso of the file src/main/java/com/jeesite/modules/sys/web/SsoController.java. The manipulation of the argument redirect leads to open redirect. The…

  • CVE-2025-6197MedJul 18, 2025
    risk 0.28cvss 4.2epss 0.67

    An open redirect vulnerability has been identified in Grafana OSS organization switching functionality. Prerequisites for exploitation: - Multiple organizations must exist in the Grafana instance - Victim must be on a different organization than the one specified in the URL

  • CVE-2025-7763MedJul 17, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability, which was classified as problematic, was found in thinkgem JeeSite up to 5.12.0. Affected is the function select of the file src/main/java/com/jeesite/modules/cms/web/SiteController.java of the component Site Controller. The manipulation of the argument redirect…

  • CVE-2025-25012MedJun 25, 2025
    risk 0.28cvss 4.3epss 0.00

    URL redirection to an untrusted site ('Open Redirect') in Kibana can lead to sending a user to an arbitrary site and server-side request forgery via a specially crafted URL.

  • CVE-2025-6428MedJun 24, 2025
    risk 0.28cvss 4.3epss 0.00

    When a URL was provided in a link querystring parameter, Firefox for Android would follow that URL instead of the correct URL, potentially leading to phishing attacks. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.*. This vulnerability was…

  • CVE-2025-6552MedJun 24, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in java-aodeng Hope-Boot 1.0.0. It has been classified as problematic. Affected is the function doLogin of the file /src/main/java/com/hope/controller/WebController.java of the component Login. The manipulation of the argument redirect_url leads to open…

  • CVE-2025-6089MedJun 15, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability has been found in Astun Technology iShare Maps 5.4.0 and classified as problematic. This vulnerability affects unknown code of the file atCheckJS.aspx. The manipulation of the argument ref leads to open redirect. The attack can be initiated remotely. The exploit…

  • CVE-2024-1440MedJun 2, 2025
    risk 0.28cvss 5.4epss 0.00

    An open redirection vulnerability exists in multiple WSO2 products due to improper validation of the multi-option URL in the authentication endpoint when multi-option authentication is enabled. A malicious actor can craft a valid link that redirects users to an…

  • CVE-2025-47854MedMay 20, 2025
    risk 0.28cvss 4.3epss 0.00

    In JetBrains TeamCity before 2025.03.2 open redirect was possible on editing VCS Root page