CWE-601

Low likelihood

URL Redirection to Untrusted Site ('Open Redirect')

Parent: CWE-610 - Externally Controlled Reference to a Resource in Another Sphere

The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

1,380 vulnerabilities with CWE-601
CVE-2026-29067 HIGH
ZITADEL 4.0.0-rc.1-4.7.0 - Open Redirect
CVSS 8.1
CVE-2026-28106 MEDIUM
B2BKing Premium <=5.3.80 - Open Redirect
CVSS 4.7
CVE-2026-28681 HIGH
IRRd 4.4.0-4.4.4/4.5.0 - Open Redirect
CVSS 8.1
CVE-2026-28413 MEDIUM
Products.isurlinportal <4.0.0 - Open Redirect
CVSS 5.3
CVE-2026-27982 MEDIUM
django-allauth <65.14.1 - Open Redirect
CVSS 4.3
CVE-2026-25477
AFFiNE <0.26.0 - Open Redirect
CVE-2026-28415 MEDIUM
Gradio <6.6.0 - Open Redirect
CVSS 4.3
CVE-2026-27738
Angular SSR <19.2.21/20.3.17/21.1.5 - Open Redirect
CVE-2026-27736 MEDIUM
BigBlueButton 3.x <3.0.20 - Open Redirect
CVSS 6.1
CVE-2026-28194 MEDIUM
JetBrains TeamCity <2025.11.3 - Open Redirect
CVSS 4.3
CVE-2026-24847 MEDIUM
OpenEMR <8.0.0 - Open Redirect
CVSS 6.1
CVE-2026-3049 MEDIUM
horilla-opensource horilla <=1.0.2 - Open Redirect
CVSS 4.3
CVE-2026-25649 HIGH
Traccar <=6.11.1 - Open Redirect
CVSS 7.3
CVE-2026-1369 MEDIUM
Conditional CAPTCHA WordPress Plugin <4.0.0 - Open Redirect
CVSS 4.3
CVE-2026-27191 MEDIUM
Feathersjs <=5.0.39 - Open Redirect
CVSS 6.1
CVE-2025-69725 MEDIUM
go-chi/chi >=5.2.2 - Open Redirect
CVSS 4.7
CVE-2025-71244 MEDIUM
SPIP <4.4.5/4.3.9 - Open Redirect
CVSS 6.1
CVE-2026-25392 MEDIUM
Update URLs WordPress <=1.4.0 - Open Redirect
CVSS 4.7
CVE-2026-2709 LOW
Busy up to 2.5.5 - Open Redirect
CVSS 3.5
CVE-2026-0573 CRITICAL
GitHub Enterprise Server - Open Redirect
CVSS 9.0
CVE-2026-1296 MEDIUM
Frontend Post Submission Manager Lite <=1.2.7 - Open Redirect
CVSS 6.1
CVE-2026-1277 MEDIUM
WordPress URL Shortify <1.12.1 - Open Redirect
CVSS 4.7
CVE-2025-27900 MEDIUM
IBM DB2 Recovery Expert 5.5 IF002 - Open Redirect
CVSS 6.8
CVE-2025-65717 MEDIUM
Visual Studio Code Extensions Live Server <5.7.9 - Info Disclosure
CVSS 4.3
CVE-2025-2418 MEDIUM
TR7 Web Application Firewall 4.30-16022026 - Open Redirect
CVSS 4.3
Details
Vulnerabilities 1,380
Exploit Likelihood Low