CWE-601: Open Redirect

A web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a Redirect.

263
Total CVEs
8
Critical
49
High
5.9
Avg CVSS

Yearly Trend

2026
35
2025
149
2024
56
2023
18
2022
2

Top Affected Vendors

1 Wegia 7
2 Adobe 7
3 Mozilla 7
4 Sap 6
5 Liferay 4
6 Microsoft 4
7 Redhat 4
8 Solarwinds 3
9 Esri 3
10 Sir 3

All Open Redirect CVEs (263)

CVE-2025-24868
7.1

This vulnerability allows unauthenticated attackers to craft malicious links that redirect victims to attacker-controlled websites when clicked. It af...

Feb 11, 2025
CVE-2024-3597
7.1

The Export WP Page to Static HTML/CSS WordPress plugin contains an open redirect vulnerability that allows unauthenticated attackers to redirect users...

Jun 20, 2024
CVE-2024-2419
7.1

CVE-2024-2419 is a redirect_uri validation bypass vulnerability in Keycloak that allows attackers to steal access tokens by circumventing host validat...

Apr 17, 2024
CVE-2024-22248
7.1

VMware SD-WAN Orchestrator has an open redirect vulnerability that allows attackers to redirect users to malicious websites. This could lead to sensit...

Apr 2, 2024
CVE-2024-2465
7.1

CVE-2024-2465 is an open redirection vulnerability in the CDeX application that allows attackers to redirect users to malicious websites via crafted U...

Mar 21, 2024
CVE-2023-6291
7.1

This vulnerability in Keycloak's redirect_uri validation logic allows attackers to bypass host restrictions and steal access tokens. Attackers can the...

Jan 26, 2024
CVE-2024-28076
7.0

This CVE describes an open redirect vulnerability in SolarWinds Platform where attackers can manipulate URL parameters to redirect users to malicious ...

Apr 18, 2024
CVE-2024-43543
6.8

This vulnerability in the Windows Mobile Broadband Driver allows remote attackers to execute arbitrary code on affected systems. Attackers could explo...

Oct 8, 2024
CVE-2026-0484
6.5

This vulnerability in SAP NetWeaver ABAP and SAP S/4HANA allows authenticated attackers to modify text data through unauthorized access to a specific ...

Feb 10, 2026
CVE-2025-7777
6.5

CVE-2025-7777 is an open redirect vulnerability in mirror-registry where improper host header sanitization allows attackers to redirect users to malic...

Aug 20, 2025
CVE-2024-56968
6.5

This vulnerability in the Govee Home iOS app allows attackers to access sensitive user information by sending a specially crafted payload. It affects ...

Jan 27, 2025
CVE-2024-56971
6.5

This vulnerability in Shuqi Novel iOS app allows attackers to access sensitive user information by tricking users into clicking a specially crafted li...

Jan 27, 2025
CVE-2024-56955
6.5

This vulnerability in QQMail iOS app allows attackers to access sensitive user information by tricking users into clicking a specially crafted link. I...

Jan 27, 2025
CVE-2024-56959
6.5

This vulnerability in Mashang Consumer Finance Co., Ltd's Anyihua iOS app allows attackers to access sensitive user information by tricking users into...

Jan 27, 2025
CVE-2024-56962
6.5

This vulnerability in WeSing iOS app allows attackers to access sensitive user information by tricking users into clicking a malicious link. It affect...

Jan 27, 2025
CVE-2024-56964
6.5

This vulnerability in Guazi Used Car iOS app allows attackers to access sensitive user information by tricking users into clicking a crafted malicious...

Jan 27, 2025
CVE-2024-56966
6.5

This vulnerability in Qidian Reader iOS app allows attackers to access sensitive user information by tricking users into clicking a specially crafted ...

Jan 27, 2025
CVE-2024-56947
6.5

This vulnerability in BeautyCam iOS app allows attackers to access sensitive user information by tricking users into clicking a crafted malicious link...

Jan 27, 2025
CVE-2024-56949
6.5

This vulnerability in University Search iOS app allows attackers to access sensitive user information by tricking users into clicking a maliciously cr...

Jan 27, 2025
CVE-2024-56951
6.5

This vulnerability in UU Game Booster iOS app allows attackers to access sensitive user information by tricking users into clicking a specially crafte...

Jan 27, 2025
CVE-2024-56953
6.5

This vulnerability in Baidu Input Method for iOS allows attackers to access user information by tricking users into clicking a specially crafted link....

Jan 27, 2025
CVE-2024-4612
6.4

This CVE describes an open redirect vulnerability in GitLab EE that could allow attackers to hijack OAuth flows and potentially take over user account...

Sep 12, 2024
CVE-2024-13983
6.3

This vulnerability allows attackers to create QR codes that spoof Chrome's Lens UI on iOS, potentially tricking users into interacting with malicious ...

Nov 14, 2025
CVE-2024-12924
6.3

This CVE describes an open redirect vulnerability in Akınsoft QR Menü software that allows attackers to redirect users to malicious websites. The vu...

Sep 1, 2025
CVE-2025-55625
6.3

An open redirect vulnerability in Reolink firmware allows attackers to craft URLs that redirect users to malicious websites. This affects users of Reo...

Aug 22, 2025
CVE-2024-34328
6.3

This vulnerability in Sielox AnyWare v2.1.2 allows attackers to redirect users to malicious websites through crafted URLs, enabling man-in-the-middle ...

Jul 31, 2025
CVE-2026-24847
6.1

OpenEMR versions before 8.0.0 contain an open redirect vulnerability in the Eye Exam form module that allows authenticated users to be redirected to a...

Feb 25, 2026
CVE-2026-24328
6.1

CVE-2026-24328 is an open redirect vulnerability in SAP TAF_APPLAUNCHER within Business Server Pages that allows unauthenticated attackers to craft ma...

Feb 10, 2026
CVE-2026-24323
6.1

This CVE describes a reflected cross-site scripting (XSS) vulnerability in BSP applications where unauthenticated attackers can inject malicious scrip...

Feb 10, 2026
CVE-2025-66596
6.1

A host header injection vulnerability in Yokogawa FAST/TOOLS allows attackers to redirect users to malicious websites by manipulating request headers....

Feb 9, 2026
CVE-2026-25651
6.1

The client-certificate-auth middleware for Node.js contains an open redirect vulnerability in versions 0.2.1 and 0.3.0. It unconditionally redirects H...

Feb 6, 2026
CVE-2026-24768
6.1

NocoDB versions before 0.301.0 contain an open redirect vulnerability in the login flow. Attackers can redirect authenticated users to malicious websi...

Jan 28, 2026
CVE-2026-23729
6.1

WeGIA versions before 3.6.2 contain an open redirect vulnerability in the control.php endpoint. Attackers can manipulate the nextPage parameter to red...

Jan 16, 2026
CVE-2026-23730
6.1

This CVE describes an Open Redirect vulnerability in WeGIA web manager for charitable institutions. Attackers can redirect users to malicious external...

Jan 16, 2026
CVE-2026-23726
6.1

This CVE describes an open redirect vulnerability in WeGIA web management software for charitable institutions. Attackers can redirect users to malici...

Jan 16, 2026
CVE-2026-23727
6.1

This open redirect vulnerability in WeGIA allows attackers to redirect users to malicious external websites by manipulating the nextPage parameter. It...

Jan 16, 2026
CVE-2026-23728
6.1

WeGIA versions before 3.6.2 contain an open redirect vulnerability in the control.php endpoint. Attackers can manipulate the nextPage parameter to red...

Jan 16, 2026
CVE-2025-55060
6.1

This CVE describes an open redirect vulnerability (CWE-601) that allows attackers to redirect users to malicious websites. It affects web applications...

Dec 29, 2025
CVE-2025-60935
6.1

An open redirect vulnerability in Blitz Panel v1.17.0 allows attackers to redirect authenticated users to malicious domains via crafted URLs. This aff...

Dec 24, 2025
CVE-2025-68602
6.1

This CVE describes an open redirect vulnerability in the WordPress 'Accept Donations with PayPal' plugin. Attackers can craft malicious URLs that redi...

Dec 24, 2025
CVE-2025-68509
6.1

This CVE describes an open redirect vulnerability in the WordPress User Submitted Posts plugin that allows attackers to redirect users to malicious we...

Dec 24, 2025
CVE-2025-34439
6.1

AVideo versions before 20.1 contain an open redirect vulnerability in the login functionality. Attackers can craft malicious links that redirect users...

Dec 17, 2025
CVE-2025-34440
6.1

AVideo versions before 20.1 contain an open redirect vulnerability in the user registration process. Attackers can manipulate the siteRedirectUri para...

Dec 17, 2025
CVE-2025-64250
6.1

This CVE describes an open redirect vulnerability in the Directorist WordPress plugin that allows attackers to redirect users to malicious websites. A...

Dec 16, 2025
CVE-2025-34504
6.1

KodExplorer 4.52 contains an open redirect vulnerability in the user login page. Attackers can manipulate the 'link' parameter to redirect authenticat...

Dec 11, 2025
CVE-2025-67713
6.1

Miniflux 2 versions 2.2.14 and below contain an open redirect vulnerability that allows attackers to redirect users to malicious websites after login....

Dec 11, 2025
CVE-2025-11222
6.1

Central Dogma versions before 0.78.0 contain an open redirect vulnerability that allows attackers to craft malicious URLs that redirect users to untru...

Dec 4, 2025
CVE-2025-58044
6.1

This CVE describes an open redirect vulnerability in JumpServer's internationalization endpoint. Attackers can craft malicious URLs that redirect user...

Dec 1, 2025
CVE-2025-63828
6.1

A Host Header Injection vulnerability in Backdrop CMS 1.32.1 allows attackers to manipulate the Host header in password reset requests. This can redir...

Nov 18, 2025
CVE-2025-42924
6.1

CVE-2025-42924 is an open redirect vulnerability in SAP S/4HANA's E-Recruiting BSP component that allows unauthenticated attackers to craft malicious ...

Nov 11, 2025

About Open Redirect (CWE-601)

A web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a Redirect.

Our database tracks 263 CVEs classified as CWE-601, with 8 rated critical and 49 rated high severity. The average CVSS score for Open Redirect vulnerabilities is 5.9.

External reference: View CWE-601 on MITRE CWE →

Monitor Open Redirect Vulnerabilities

Get alerted when new Open Redirect CVEs affect your infrastructure.

Start Monitoring Free