CWE-601

Low likelihood

URL Redirection to Untrusted Site ('Open Redirect')

Parent: CWE-610 - Externally Controlled Reference to a Resource in Another Sphere

The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

1,448 vulnerabilities with CWE-601
CVE-2025-1885 MEDIUM
Restajet Online Food Delivery System - Open Redirect
CVSS 5.4
CVE-2025-55254 LOW
HCL BigFix Remote Control Lite Web Portal <10.1.0.0326 - RCE
CVSS 3.7
CVE-2025-43526 CRITICAL
macOS Tahoe <26.2 - Info Disclosure
CVSS 9.8
CVE-2025-34440 MEDIUM
Wwbn Avideo < 20.0 - Open Redirect
CVSS 6.1
CVE-2025-34439 MEDIUM
Wwbn Avideo < 20.0 - Open Redirect
CVSS 6.1
CVE-2025-62690 LOW
Mattermost Server < 10.11.5 - Open Redirect
CVSS 3.1
CVE-2025-65581 MEDIUM
Volosoft Abp < 10.0.0 - Open Redirect
CVSS 5.3
CVE-2025-64250 MEDIUM
wpWax Directorist <8.5.6 - Open Redirect
CVSS 4.7
CVE-2025-14692 MEDIUM
Pypi Mayan-edms < 4.10.2 - Open Redirect
CVSS 4.3
CVE-2025-14451 MEDIUM
Solutions Ad Manager <1.0.0 - Open Redirect
CVSS 4.7
CVE-2025-34504 MEDIUM
Kodcloud Kodexplorer - Open Redirect
CVSS 6.1
CVE-2025-67713 MEDIUM
Miniflux < 2.2.15 - Open Redirect
CVSS 6.1
CVE-2025-67502 MEDIUM
Taguette < 1.5.2 - Open Redirect
CVSS 5.4
CVE-2025-67587 MEDIUM
WP Gravity Forms FreshDesk Plugin <1.3.5 - Open Redirect
CVSS 4.7
CVE-2025-67585 MEDIUM
Flexmls IDX <3.15.7 - Open Redirect
CVSS 4.7
CVE-2025-11222 MEDIUM
Central Dogma <0.78.0 - Open Redirect
CVSS 6.1
CVE-2025-20382 LOW
Splunk <10.0.2,9.4.6,9.3.8,9.2.10 - CSRF
CVSS 3.5
CVE-2025-58044 MEDIUM
Fit2cloud Jumpserver < 3.10.19 - Open Redirect
CVSS 6.1
CVE-2025-13819 MEDIUM
MiR Robot and Fleet - Open Redirect
CVSS 6.1
CVE-2025-66062 LOW
WP YouTube Lyte <1.7.28 - Open Redirect
CVSS 3.4
CVE-2025-63828 MEDIUM
Backdrop CMS 1.32.1 - Host Header Injection
CVSS 6.1
CVE-2025-40545 MEDIUM
Solarwinds Observability Self-hosted < 2025.4.1 - Open Redirect
CVSS 4.8
CVE-2025-64754 LOW
Jitsi Meet <2.0.10532 - Open Redirect
CVE-2025-20355 MEDIUM
Cisco Catalyst Center Virtual Appliance - Open Redirect
CVSS 4.7
CVE-2025-64716 MEDIUM
Techarohq Anubis < 1.23.0 - XSS
Details
Vulnerabilities 1,448
Exploit Likelihood Low