CWE-601: Open Redirect

A web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a Redirect.

263
Total CVEs
8
Critical
49
High
5.9
Avg CVSS

Yearly Trend

2026
35
2025
149
2024
56
2023
18
2022
2

Top Affected Vendors

1 Wegia 7
2 Adobe 7
3 Mozilla 7
4 Sap 6
5 Liferay 4
6 Microsoft 4
7 Redhat 4
8 Solarwinds 3
9 Esri 3
10 Sir 3

All Open Redirect CVEs (263)

CVE-2025-42893
6.1

An Open Redirect vulnerability in SAP Business Connector allows unauthenticated attackers to craft malicious URLs that redirect victims to attacker-co...

Nov 11, 2025
CVE-2025-12789
6.1

An open redirect vulnerability in Red Hat Single Sign-On allows attackers to redirect users to malicious websites during logout. This occurs when the ...

Nov 7, 2025
CVE-2025-62266
6.1

This CVE describes a DNS rebinding vulnerability in Liferay Portal and DXP that allows attackers to redirect users to malicious external URLs. Affecte...

Oct 30, 2025
CVE-2025-64116
6.1

This vulnerability allows attackers to redirect authenticated users to malicious external websites via an unvalidated redirect parameter on the login ...

Oct 30, 2025
CVE-2025-62253
6.1

This open redirect vulnerability in Liferay Portal and DXP allows attackers to redirect authenticated users to malicious external websites by manipula...

Oct 27, 2025
CVE-2025-62407
6.1

This CVE describes an open redirect vulnerability in Frappe web framework's login page. Attackers can craft malicious URLs that redirect users to arbi...

Oct 16, 2025
CVE-2025-54088
6.1

CVE-2025-54088 is an open-redirect vulnerability in Secure Access software that allows attackers with console access to redirect victims to malicious ...

Oct 2, 2025
CVE-2025-61587
6.1

This CVE describes an open redirect vulnerability in Weblate versions 5.13.2 and below when configured with Anubis and REDIRECT_DOMAINS is not set. At...

Oct 1, 2025
CVE-2025-57878
6.1

An unvalidated redirect vulnerability in Esri Portal for ArcGIS allows attackers to craft malicious URLs that redirect users to arbitrary websites. Th...

Sep 29, 2025
CVE-2025-57879
6.1

This vulnerability allows remote attackers to create malicious URLs that redirect users to arbitrary websites without validation. It affects unauthent...

Sep 29, 2025
CVE-2025-57872
6.1

This CVE describes an unvalidated redirect vulnerability in Esri Portal for ArcGIS that allows attackers to craft malicious URLs. When clicked, these ...

Sep 29, 2025
CVE-2025-43795
6.1

This CVE describes an open redirect vulnerability in Liferay Portal and DXP that allows attackers to redirect users to malicious external websites. Th...

Sep 12, 2025
CVE-2025-59013
6.1

An open-redirect vulnerability in TYPO3 CMS's GeneralUtility::sanitizeLocalUrl function allows attackers to redirect users to malicious external websi...

Sep 9, 2025
CVE-2025-43767
6.1

An open redirect vulnerability in Liferay Portal and DXP allows attackers to manipulate the /c/portal/edit_info_item parameter to redirect users to ma...

Aug 23, 2025
CVE-2025-54793
6.1

Astro web framework versions 5.2.0 through 5.12.7 contain an open redirect vulnerability in trailing slash redirection logic when handling paths with ...

Aug 8, 2025
CVE-2025-42985
6.1

This CVE describes a URL redirection vulnerability in SAP BusinessObjects Content Administrator Workbench where insufficient URL sanitization allows a...

Jul 8, 2025
CVE-2024-37656
6.1

An open redirect vulnerability in gnuboard5 v5.5.16 allows attackers to redirect users to malicious websites by exploiting insufficient URL parameter ...

Jul 7, 2025
CVE-2024-37658
6.1

An open redirect vulnerability in gnuboard5 v5.5.16 allows attackers to redirect users to malicious websites via the bbs/member_confirm.php endpoint. ...

Jul 7, 2025
CVE-2024-12561
6.1

This vulnerability allows unauthenticated attackers to redirect WordPress users to malicious websites by exploiting insufficient URL validation in the...

May 21, 2025
CVE-2025-47789
6.1

This is an open redirect vulnerability in Horilla HRMS that allows attackers to craft URLs that redirect users to external malicious domains after log...

May 15, 2025
CVE-2024-6690
6.1

The wccp-pro WordPress plugin before version 15.3 contains an open redirect vulnerability via the referrer parameter. This allows attackers to redirec...

May 15, 2025
CVE-2023-6786
6.1

The Payment Gateway for Telcell WordPress plugin through version 2.0.1 contains an open redirect vulnerability. Attackers can craft malicious URLs tha...

May 15, 2025
CVE-2025-4143
6.1

This CVE describes an OAuth redirect URI validation vulnerability in the workers-oauth-provider library used in Cloudflare's MCP framework. Attackers ...

May 1, 2025
CVE-2024-49706
6.1

This CVE describes an open redirect vulnerability in Internet Starter, a module of the SoftCOM iKSORIS system. Attackers can manipulate the 'target' p...

Apr 14, 2025
CVE-2025-3433
6.1

The Advanced Advertising System WordPress plugin has an open redirect vulnerability that allows unauthenticated attackers to redirect users to malicio...

Apr 8, 2025
CVE-2024-9308
6.1

An open redirect vulnerability in haotian-liu/llava v1.2.0 allows attackers to redirect users to malicious websites via crafted URLs. This affects all...

Mar 20, 2025
CVE-2024-8021
6.1

An open redirect vulnerability in gradio-app/gradio allows attackers to redirect users to malicious websites using URL encoding. This affects all user...

Mar 20, 2025
CVE-2024-11044
6.1

An open redirect vulnerability in automatic1111/stable-diffusion-webui version 1.10.0 allows attackers to redirect users to malicious websites via cra...

Mar 20, 2025
CVE-2024-10908
6.1

An open redirect vulnerability in lm-sys/fastchat v0.2.36 allows attackers to redirect users to malicious websites via crafted URLs. This affects all ...

Mar 20, 2025
CVE-2024-10812
6.1

An open redirect vulnerability in binary-husky/gpt_academic version 3.83 allows attackers to redirect users to malicious websites via the 'file' param...

Mar 20, 2025
CVE-2025-1300
6.1

CodeChecker web server versions through 6.24.5 contain an open redirect vulnerability that allows attackers to redirect users to malicious websites. T...

Feb 28, 2025
CVE-2025-21512
6.1

This vulnerability in Oracle JD Edwards EnterpriseOne Tools allows unauthenticated attackers to manipulate or view data by tricking users into interac...

Jan 21, 2025
CVE-2025-24020
6.1

This CVE describes an Open Redirect vulnerability in WeGIA web management software for charitable institutions. Authenticated users can be tricked int...

Jan 21, 2025
CVE-2025-23086
6.1

This vulnerability in Brave Browser allows malicious websites to spoof trusted site origins in file upload/download dialogs when combined with open re...

Jan 21, 2025
CVE-2024-54050
6.1

Adobe Connect versions 12.6, 11.4.7 and earlier contain an open redirect vulnerability (CWE-601) that allows attackers to redirect users to malicious ...

Dec 10, 2024
CVE-2024-52003
6.1

This vulnerability in Traefik allows attackers to manipulate the X-Forwarded-Prefix header from untrusted sources, potentially enabling URL redirectio...

Nov 29, 2024
CVE-2024-1240
6.1

An open redirection vulnerability in pyload/pyload version 0.5.0 allows attackers to redirect users to malicious websites by manipulating the 'next' p...

Nov 15, 2024
CVE-2024-25566
6.1

CVE-2024-25566 is an open-redirect vulnerability in PingAM where attackers can craft requests that bypass URL validation. This allows redirecting user...

Oct 29, 2024
CVE-2024-46326
6.1

This vulnerability in Public Knowledge Project pkp-lib allows attackers to redirect users to malicious websites after logout due to insufficient input...

Oct 21, 2024
CVE-2024-8897
6.1

This vulnerability allows attackers to spoof the address bar in Firefox for Android by exploiting an open redirect on a trusted site. When users are r...

Sep 17, 2024
CVE-2024-7260
6.1

CVE-2024-7260 is an open redirect vulnerability in Keycloak that allows attackers to craft malicious URLs that appear to be legitimate Keycloak pages ...

Sep 9, 2024
CVE-2024-8586
6.1

WebITR from Uniong has an Open Redirect vulnerability that allows attackers to create malicious URLs that appear legitimate. When users click these li...

Sep 9, 2024
CVE-2024-42341
6.1

This CVE describes an open redirect vulnerability in Loway software where attackers can redirect users to malicious websites. It affects systems runni...

Sep 8, 2024
CVE-2024-8386
6.1

This vulnerability allows malicious websites with popup permissions to overlay select elements on top of legitimate sites, enabling UI spoofing attack...

Sep 3, 2024
CVE-2024-44776
6.1

An open redirect vulnerability in vTiger CRM v7.4.0 allows attackers to craft malicious URLs that redirect users to untrusted external sites. This aff...

Aug 29, 2024
CVE-2024-39097
6.1

This CVE describes an Open Redirect vulnerability in Gnuboard v6.0.4 and earlier versions. Attackers can manipulate the 'url' parameter in the login p...

Aug 26, 2024
CVE-2024-43794
6.1

OpenSearch Dashboards Security Plugin versions before 1.3.19 and 2.16.0 have an open redirect vulnerability in the login flow. Attackers can craft mal...

Aug 23, 2024
CVE-2024-42353
6.1

This vulnerability in WebOb allows attackers to manipulate HTTP redirects by injecting malicious URLs into Location headers, potentially redirecting u...

Aug 14, 2024
CVE-2024-6289
6.1

The WPS Hide Login WordPress plugin before version 1.9.16.4 fails to properly restrict access to hidden login pages, allowing unauthenticated visitors...

Jul 15, 2024
CVE-2024-5936
6.1

An open redirect vulnerability in imartinez/privategpt version 0.5.0 allows attackers to redirect users to malicious websites by manipulating the 'fil...

Jun 27, 2024

About Open Redirect (CWE-601)

A web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a Redirect.

Our database tracks 263 CVEs classified as CWE-601, with 8 rated critical and 49 rated high severity. The average CVSS score for Open Redirect vulnerabilities is 5.9.

External reference: View CWE-601 on MITRE CWE →

Monitor Open Redirect Vulnerabilities

Get alerted when new Open Redirect CVEs affect your infrastructure.

Start Monitoring Free