VYPR

CWE-601

URL Redirection to Untrusted Site ('Open Redirect')

BaseDraftLikelihood: Low

Description

The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-178

CVEs mapped to this weakness (1,767)

page 68 of 89
  • CVE-2026-48924MedMay 27, 2026
    risk 0.28cvss 4.3epss 0.00

    Jenkins Bitbucket OAuth Plugin 0.17 and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks.

  • CVE-2026-45448MedMay 14, 2026
    risk 0.28cvss 4.3epss 0.00

    CWE-601 URL redirection to untrusted site ('open redirect')

  • CVE-2026-42525MedApr 29, 2026
    risk 0.28cvss 4.3epss 0.00

    Jenkins Microsoft Entra ID (previously Azure AD) Plugin 666.v6060de32f87d and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks.

  • CVE-2026-30346MedApr 27, 2026
    risk 0.28cvss 4.3epss 0.00

    An open redirect in the /api/google/authorize endpoint of hunvreus DevPush v0.3.2 allows attackers to redirect users to malicious sites via supplying a crafted URL.

  • CVE-2026-40096MedApr 15, 2026
    risk 0.28cvss 5.4epss 0.00

    immich is a high performance self-hosted photo and video management solution. Versions prior to 2.7.3 contain an open redirect vulnerability in the shared album functionality, where the album name is inserted unsanitized into a tag in api.service.ts. A registered attacker…

  • CVE-2026-5467MedApr 3, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was identified in Casdoor 2.356.0. Affected by this issue is some unknown functionality of the component OAuth Authorization Request Handler. Such manipulation of the argument redirect_uri leads to open redirect. It is possible to launch the attack remotely. The…

  • CVE-2026-34442MedMar 31, 2026
    risk 0.28cvss 5.4epss 0.00

    FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.211, host header manipulation in FreeScout version (http://localhost:8080/system/status) allows an attacker to inject an arbitrary domain into generated absolute URLs. This…

  • CVE-2026-4799MedMar 31, 2026
    risk 0.28cvss 4.3epss 0.00

    In Search Guard FLX up to version 4.0.1, it is possible to use specially crafted requests to redirect the user to an untrusted URL.

  • CVE-2026-1166MedMar 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Open Redirect vulnerability in Hitachi Ops Center Administrator.This issue affects Hitachi Ops Center Administrator: from 10.2.0 before 11.0.8.

  • CVE-2026-29105MedMar 19, 2026
    risk 0.28cvss 5.4epss 0.00

    SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, SuiteCRM contains an unauthenticated open redirect vulnerability in the WebToLead capture functionality. A user-supplied POST parameter…

  • CVE-2026-28194MedFeb 25, 2026
    risk 0.28cvss 4.3epss 0.00

    In JetBrains TeamCity before 2025.11.3 open redirect was possible in the React project creation flow

  • CVE-2026-1369MedFeb 22, 2026
    risk 0.28cvss 4.3epss 0.00

    The Conditional CAPTCHA WordPress plugin through 4.0.0 does not validate a parameter before redirecting the user to its value, leading to an Open Redirect issue

  • CVE-2025-65717MedFeb 16, 2026
    risk 0.28cvss 4.3epss 0.01

    An issue in Visual Studio Code Extensions Live Server v5.7.9 allows attackers to exfiltrate files via user interaction with a crafted HTML page.

  • CVE-2025-2418MedFeb 16, 2026
    risk 0.28cvss 4.3epss 0.00

    URL Redirection to Untrusted Site ('Open Redirect') vulnerability in TR7 Cyber ​​Defense Inc. Web Application Firewall allows Phishing. This issue affects Web Application Firewall: from 4.30 before v1.4.0.117.

  • CVE-2026-2153MedFeb 8, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was determined in mwielgoszewski doorman up to 0.6. This issue affects the function is_safe_url of the file doorman/users/views.py. Executing a manipulation of the argument Next can lead to open redirect. The attack may be launched remotely. The exploit has been…

  • CVE-2026-20123MedFeb 4, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper input…

  • CVE-2026-22912MedJan 15, 2026
    risk 0.28cvss 4.3epss 0.00

    Improper validation of a login parameter may allow attackers to redirect users to malicious websites after authentication. This can lead to various risk including stealing credentials from unsuspecting users.

  • CVE-2025-14524MedJan 8, 2026
    risk 0.28cvss 5.3epss 0.01

    When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a cross-protocol redirect to a second URL that uses an IMAP, LDAP, POP3 or SMTP scheme, curl might wrongly pass on the bearer token to the new target host.

  • CVE-2025-67502MedDec 10, 2025
    risk 0.28cvss 5.4epss 0.00

    Taguette is an open source qualitative research tool. In versions 1.5.1 and below, attackers can craft malicious URLs that redirect users to arbitrary external websites after authentication. The application accepts a user-controlled next parameter and uses it directly in HTTP…

  • CVE-2025-54196MedOct 14, 2025
    risk 0.28cvss 4.3epss 0.00

    Adobe Connect versions 12.9 and earlier are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. An attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue requires user interaction in that a…