CWE-601

Low likelihood

URL Redirection to Untrusted Site ('Open Redirect')

Parent: CWE-610 - Externally Controlled Reference to a Resource in Another Sphere

The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

1,628 vulnerabilities with CWE-601
CVE-2026-10545 HIGH
IBM Planning Analytics Local is affected by Open Redirect
CVSS 7.5
CVE-2026-66414 MEDIUM
Leantime Open Redirect in Login Controller via redirectUrl Parameter
CVSS 6.1
CVE-2026-18266 MEDIUM
Dify AI Workflow oauth_redirect_url Open Redirect Vulnerability
CVSS 5.4
CVE-2026-55403 LOW
datamodel-code-generator: Authorization / request headers leaked to cross-origin redirect target when fetching remote schemas
CVSS 3.7
CVE-2026-54603 HIGH
OAuth2::Client#request: Protocol-relative redirect Location overrides authority, leaking bearer Authorization to attacker host
CVSS 8.6
CVE-2026-67178 HIGH
Open Redirect in MISP Installer-Generated Apache Configuration
CVE-2026-14171 MEDIUM
ads-tec Industrial IT: Post-login open redirect in the web interface
CVSS 6.1
CVE-2026-53669 MEDIUM
React Router: Open redirect via backslash in <Link> and useNavigate (CVE-2025-68470 bypass)
CVE-2026-53668 MEDIUM
React Router - Open Redirect to Cross-Site Scripting
CVSS 6.9
CVE-2026-51564 MEDIUM
Milk admin <= 0.9.8 - Unauthenticated Open Redirect via Redirect Parameter
CVSS 4.9
CVE-2026-59730 LOW
@astrojs/node: Backslash-prefixed paths not recognized as internal by trailing-slash redirect
CVE-2026-64645 MEDIUM
Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname
CVSS 6.1
CVE-2026-14236 MEDIUM
Contact Form 7 – PayPal & Stripe Add-on < 2.5 - Open Redirect
CVSS 4.7
CVE-2026-48012 MEDIUM
Shopware SSO referer trust leading to an arbitrary redirect target
CVSS 4.3
CVE-2026-8152 CRITICAL
Unblu Spark Open Redirect leading to DOM-Based XSS
CVE-2026-62563 MEDIUM
Oracle Work IN Process < 12.2.15 - Improper Authorization
CVSS 5.4
CVE-2026-62517 MEDIUM
Oracle Production Scheduling < 12.2.15 - Insufficient Verification of Data Authenticity
CVSS 5.3
CVE-2026-62444 MEDIUM
Oracle Contracts Integration < 12.2.15 - Improper Authorization
CVSS 6.1
CVE-2026-61254 MEDIUM
Oracle Hrms (Republic OF Korea) < 12.2.15 - URL Redirection to Untrusted Site ('Open Redirect')
CVSS 5.4
CVE-2026-61181 HIGH
Oracle Agile PLM for Process 6.2.4: Authenticated Data Access/Modification via Product Quality Mgmt
CVSS 7.6
CVE-2026-61143 MEDIUM
Oracle Communications Convergent Charging Controller 15.0.0.0.0/15.2.0.0.0 Auth Bypass RCE via Prov IF
CVSS 6.4
CVE-2026-61097 CRITICAL
Oracle Banking Trade Finance Process Management < 14.8.0 - Denial of Service
CVSS 9.6
CVE-2026-61082 MEDIUM
MySQL Connectors 9.7.0-9.7.1 - Unauthenticated Unauthorized Data Access via Connector/J
CVSS 6.5
CVE-2026-61078 HIGH
PeopleSoft Enterprise CC Common App Objects 9.2 - Authenticated Data Manipulation & Unauthorized Access via HTTP
CVSS 8.7
CVE-2026-60957 MEDIUM
Oracle Transportation Execution 12.2.3-12.2.15 - Cross-Site Request Forgery via HTTP with Scope Change Impact
CVSS 5.4
Details
Vulnerabilities 1,628
Exploit Likelihood Low