CWE-601

Low likelihood

URL Redirection to Untrusted Site ('Open Redirect')

Parent: CWE-610 - Externally Controlled Reference to a Resource in Another Sphere

The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

1,628 vulnerabilities with CWE-601
CVE-2026-60945 HIGH
Oracle Learning Management 12.2.3-12.2.15 - Authenticated Data Creation, Deletion, and Unauthorized Access via HTTP
CVSS 7.3
CVE-2026-60911 MEDIUM
Oracle Property Manager 12.2.3-12.2.15 - Authenticated Data Modification and Information Disclosure via HTTP
CVSS 5.4
CVE-2026-60842 MEDIUM
Oracle Knowledge Mgmt 12.2.5-12.2.15: Unauth CSRF & Data Disclosure via HTTP Search
CVSS 6.1
CVE-2026-60685 MEDIUM
Oracle iSupport 12.2.3-12.2.15 - Unauthenticated Cross-Site Request Forgery via HTTP with Impact to Additional Products
CVSS 6.1
CVE-2026-60664 HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP with User Interaction
CVSS 8.8
CVE-2026-60658 HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP with User Interaction
CVSS 7.5
CVE-2026-60650 HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via Web Content Management
CVSS 8.0
CVE-2026-60648 HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via Web Content Management
CVSS 8.0
CVE-2026-60646 HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via Web Content Management
CVSS 8.0
CVE-2026-60642 HIGH
Oracle WebCenter Content - Denial of Service
CVSS 7.6
CVE-2026-60641 HIGH
Oracle WebCenter Content - Denial of Service
CVSS 7.6
CVE-2026-60640 HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP with User Interaction
CVSS 8.3
CVE-2026-60639 HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 8.8
CVE-2026-60638 HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP with User Interaction
CVSS 8.8
CVE-2026-60637 HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via Content Server
CVSS 8.8
CVE-2026-60636 HIGH
Oracle WebCenter Content 12.2.1.4.0 and 14.1.2.0.0 - Unauthenticated Remote Code Execution via Content Server
CVSS 8.8
CVE-2026-60635 HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP with User Interaction
CVSS 8.8
CVE-2026-60634 HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP with User Interaction
CVSS 8.8
CVE-2026-60633 HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 8.8
CVE-2026-60632 CRITICAL
Oracle WebCenter Content 12.2.1.4.0/14.1.2.0.0: Unauth HTTP Arbitrary Data Creation, Modification, Access
CVSS 9.3
CVE-2026-60467 HIGH
Oracle WebCenter Content: Imaging 12.2.1.4.0/14.1.2.0.0 - Unauth RCE via HTTP w/ User Interaction
CVSS 7.5
CVE-2026-47051 MEDIUM
PeopleSoft PeopleTools 8.61-8.62: Authenticated CSRF with Scope Change via HTTP Request
CVSS 5.4
CVE-2026-47048 MEDIUM
PeopleSoft PeopleTools 8.61/8.62 CSRF with Data Modification & Info Disclosure via HTTP
CVSS 5.4
CVE-2026-47045 MEDIUM
Oracle DB 19.3-19.31/21.3-21.22/23.4-23.26.2 Auth RCE via JDBC Oracle Net
CVSS 6.8
CVE-2026-47026 HIGH
PeopleSoft Enterprise PeopleTools 8.61 and 8.62 - Unauthenticated Unauthorized Data Access via OpenSearch Dashboards
CVSS 7.4
Details
Vulnerabilities 1,628
Exploit Likelihood Low