VYPR

CWE-601

URL Redirection to Untrusted Site ('Open Redirect')

BaseDraftLikelihood: Low

Description

The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-178

CVEs mapped to this weakness (1,692)

page 77 of 85
  • CVE-2008-1547Oct 21, 2008
    risk 0.07cvss epss 0.48

    Open redirect vulnerability in exchweb/bin/redir.asp in Microsoft Outlook Web Access (OWA) for Exchange Server 2003 SP2 (aka build 6.5.7638) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the URL parameter.

  • CVE-2024-53995LowJan 8, 2025
    risk 0.05cvss epss 0.01

    SickChill is an automatic video library manager for TV shows. A user-controlled `login` endpoint's `next_` parameter takes arbitrary content. Prior to commit c7128a8946c3701df95c285810eb75b2de18bf82, an authenticated attacker may use this to redirect the user to arbitrary…

  • CVE-2005-0420Apr 27, 2005
    risk 0.05cvss epss 0.26

    Microsoft Outlook Web Access (OWA), when used with Exchange, allows remote attackers to redirect users to arbitrary URLs for login via a link to the owalogon.asp application.

  • CVE-2015-5354Jul 1, 2015
    risk 0.04cvss epss 0.13

    Open redirect vulnerability in Novius OS 5.0.1 (Elche) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirect parameter to admin/nos/login.

  • CVE-2023-5375MedOct 4, 2023
    risk 0.03cvss 6.1epss 0.35

    Open Redirect in GitHub repository mosparo/mosparo prior to 1.0.2.

  • CVE-2013-4200Jan 21, 2014
    risk 0.03cvss epss 0.02

    The isURLInPortal method in the URLTool class in in_portal.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 treats URLs starting with a space as a relative URL, which allows remote attackers to bypass the allow_external_login_sites filtering property, …

  • CVE-2025-46826LowMay 7, 2025
    risk 0.01cvss epss 0.00

    insa-auth is an authentication server for INSA Rouen. A minor issue allowed third-party websites to access the server's secondary authentication bridge, potentially revealing basic student information (name and number). However, the issue posed minimal risk, was never exploited,…

  • CVE-2025-25300LowFeb 18, 2025
    risk 0.01cvss epss 0.00

    smartbanner.js is a customizable smart app banner for iOS and Android. Prior to version 1.14.1, clicking on smartbanner `View` link and navigating to 3rd party page leaves `window.opener` exposed. It may allow hostile third parties to abuse `window.opener`, e.g. by redirection…

  • CVE-2026-49826NonAug 14, 2026
    risk 0.00cvss epss 0.00

    Concourse is a container-based automation system written in Go. Prior to version 8.2.3, an attacker is able to craft and send a user a URL that will redirect the user from the Concourse web server to any other site. This could be used in a phishing attack to steal user's…

  • CVE-2026-55087Aug 13, 2026
    risk 0.00cvss epss

    # GHSA-03 — `x-proxy-path` header reflected into admin HTML/JS/CSS (cache-poisoning XSS) and concatenated into redirect (open-redirect) **Severity:** Medium **CVSS v3.1 vector:** `CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N` **CVSS suggested base score:** ~6.1 — Medium …

  • CVE-2026-14219MedAug 4, 2026
    risk 0.00cvss 5.4epss 0.00

    URL redirection to untrusted site ('open redirect') vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Phishing. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.

  • CVE-2026-16296MedAug 4, 2026
    risk 0.00cvss 4.7epss 0.00

    The Clearfy Cache WordPress plugin before 2.4.3 does not validate the redirect target in its Cyrlitera old-URL redirect handler, passing a decoded request URI to an unsafe redirect function, which allows unauthenticated attackers to redirect visitors to an arbitrary external…

  • CVE-2026-69087MedAug 3, 2026
    risk 0.00cvss 6.5epss 0.00

    The Grav form plugin (getgrav/grav-plugin-form) before 9.1.13 contains an open redirect vulnerability. Since v9.1.11, the redirect process action evaluates user-supplied form data inside Twig expressions, and Grav::redirect() accepts external URLs without origin validation. When…

  • CVE-2026-66414MedJul 30, 2026
    risk 0.00cvss 6.1epss 0.00

    Leantime 3.6.2 contains an open redirect vulnerability in the Login controller that allows unauthenticated attackers to redirect authenticated users to arbitrary external sites by manipulating the redirectUrl POST parameter. Attackers can craft a malicious login URL with a…

  • CVE-2026-18266MedJul 29, 2026
    risk 0.00cvss 5.4epss 0.00

    Dify AI Workflow oauth_redirect_url Open Redirect Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Dify. User interaction is required to exploit this vulnerability in that the target must visit a malicious…

  • CVE-2026-67178HigJul 28, 2026
    risk 0.00cvss epss 0.00

    MISP installation scripts generated an Apache HTTP virtual-host configuration containing an incorrectly formatted HTTP-to-HTTPS redirect: Redirect permanent / https://misp.example Apache’s Redirect directive appends any portion of the requested path that follows the matched…

  • CVE-2026-14171MedJul 28, 2026
    risk 0.00cvss 6.1epss 0.00

    An unauthenticated remote attacker can abuse the improper validation of the post-login redirect of the web-UI to trick users to a malicious website. This can result in a loss of confidentiality and availability.

  • CVE-2026-51564MedJul 27, 2026
    risk 0.00cvss 4.9epss 0.01

    An issue in the redirect parameter in Milk admin <=0.9.8 allows remote attackers to redirect users to arbitrary external URLs via a crafted request.

  • CVE-2026-14236MedJul 27, 2026
    risk 0.00cvss 4.7epss 0.00

    The Contact Form 7 WordPress plugin before 2.5 does not validate the host of a user-supplied return URL before using it as the success and cancel redirect targets of a Stripe checkout, allowing an unauthenticated attacker to redirect a victim, via a crafted link, to an…

  • CVE-2026-8152CriJul 22, 2026
    risk 0.00cvss epss 0.00

    Unblu Spark contains an open redirect vulnerability that can be escalated to a DOM-based cross-site scripting (XSS) attack. When Unblu Spark is deployed with com.unblu.identifier.siteEmbeddedSetup=true, it runs in the same origin as the host application. Any JavaScript…