CWE-601: Open Redirect
A web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a Redirect.
Yearly Trend
Top Affected Vendors
All Open Redirect CVEs (263)
An Open Redirect vulnerability in SAP Business Connector allows unauthenticated attackers to craft malicious URLs that redirect victims to attacker-co...
Nov 11, 2025An open redirect vulnerability in Red Hat Single Sign-On allows attackers to redirect users to malicious websites during logout. This occurs when the ...
Nov 7, 2025This CVE describes a DNS rebinding vulnerability in Liferay Portal and DXP that allows attackers to redirect users to malicious external URLs. Affecte...
Oct 30, 2025This vulnerability allows attackers to redirect authenticated users to malicious external websites via an unvalidated redirect parameter on the login ...
Oct 30, 2025This open redirect vulnerability in Liferay Portal and DXP allows attackers to redirect authenticated users to malicious external websites by manipula...
Oct 27, 2025This CVE describes an open redirect vulnerability in Frappe web framework's login page. Attackers can craft malicious URLs that redirect users to arbi...
Oct 16, 2025CVE-2025-54088 is an open-redirect vulnerability in Secure Access software that allows attackers with console access to redirect victims to malicious ...
Oct 2, 2025This CVE describes an open redirect vulnerability in Weblate versions 5.13.2 and below when configured with Anubis and REDIRECT_DOMAINS is not set. At...
Oct 1, 2025An unvalidated redirect vulnerability in Esri Portal for ArcGIS allows attackers to craft malicious URLs that redirect users to arbitrary websites. Th...
Sep 29, 2025This vulnerability allows remote attackers to create malicious URLs that redirect users to arbitrary websites without validation. It affects unauthent...
Sep 29, 2025This CVE describes an unvalidated redirect vulnerability in Esri Portal for ArcGIS that allows attackers to craft malicious URLs. When clicked, these ...
Sep 29, 2025This CVE describes an open redirect vulnerability in Liferay Portal and DXP that allows attackers to redirect users to malicious external websites. Th...
Sep 12, 2025An open-redirect vulnerability in TYPO3 CMS's GeneralUtility::sanitizeLocalUrl function allows attackers to redirect users to malicious external websi...
Sep 9, 2025An open redirect vulnerability in Liferay Portal and DXP allows attackers to manipulate the /c/portal/edit_info_item parameter to redirect users to ma...
Aug 23, 2025Astro web framework versions 5.2.0 through 5.12.7 contain an open redirect vulnerability in trailing slash redirection logic when handling paths with ...
Aug 8, 2025This CVE describes a URL redirection vulnerability in SAP BusinessObjects Content Administrator Workbench where insufficient URL sanitization allows a...
Jul 8, 2025An open redirect vulnerability in gnuboard5 v5.5.16 allows attackers to redirect users to malicious websites by exploiting insufficient URL parameter ...
Jul 7, 2025An open redirect vulnerability in gnuboard5 v5.5.16 allows attackers to redirect users to malicious websites via the bbs/member_confirm.php endpoint. ...
Jul 7, 2025This vulnerability allows unauthenticated attackers to redirect WordPress users to malicious websites by exploiting insufficient URL validation in the...
May 21, 2025This is an open redirect vulnerability in Horilla HRMS that allows attackers to craft URLs that redirect users to external malicious domains after log...
May 15, 2025The wccp-pro WordPress plugin before version 15.3 contains an open redirect vulnerability via the referrer parameter. This allows attackers to redirec...
May 15, 2025The Payment Gateway for Telcell WordPress plugin through version 2.0.1 contains an open redirect vulnerability. Attackers can craft malicious URLs tha...
May 15, 2025This CVE describes an OAuth redirect URI validation vulnerability in the workers-oauth-provider library used in Cloudflare's MCP framework. Attackers ...
May 1, 2025This CVE describes an open redirect vulnerability in Internet Starter, a module of the SoftCOM iKSORIS system. Attackers can manipulate the 'target' p...
Apr 14, 2025The Advanced Advertising System WordPress plugin has an open redirect vulnerability that allows unauthenticated attackers to redirect users to malicio...
Apr 8, 2025An open redirect vulnerability in haotian-liu/llava v1.2.0 allows attackers to redirect users to malicious websites via crafted URLs. This affects all...
Mar 20, 2025An open redirect vulnerability in gradio-app/gradio allows attackers to redirect users to malicious websites using URL encoding. This affects all user...
Mar 20, 2025An open redirect vulnerability in automatic1111/stable-diffusion-webui version 1.10.0 allows attackers to redirect users to malicious websites via cra...
Mar 20, 2025An open redirect vulnerability in lm-sys/fastchat v0.2.36 allows attackers to redirect users to malicious websites via crafted URLs. This affects all ...
Mar 20, 2025An open redirect vulnerability in binary-husky/gpt_academic version 3.83 allows attackers to redirect users to malicious websites via the 'file' param...
Mar 20, 2025CodeChecker web server versions through 6.24.5 contain an open redirect vulnerability that allows attackers to redirect users to malicious websites. T...
Feb 28, 2025This vulnerability in Oracle JD Edwards EnterpriseOne Tools allows unauthenticated attackers to manipulate or view data by tricking users into interac...
Jan 21, 2025This CVE describes an Open Redirect vulnerability in WeGIA web management software for charitable institutions. Authenticated users can be tricked int...
Jan 21, 2025This vulnerability in Brave Browser allows malicious websites to spoof trusted site origins in file upload/download dialogs when combined with open re...
Jan 21, 2025Adobe Connect versions 12.6, 11.4.7 and earlier contain an open redirect vulnerability (CWE-601) that allows attackers to redirect users to malicious ...
Dec 10, 2024This vulnerability in Traefik allows attackers to manipulate the X-Forwarded-Prefix header from untrusted sources, potentially enabling URL redirectio...
Nov 29, 2024An open redirection vulnerability in pyload/pyload version 0.5.0 allows attackers to redirect users to malicious websites by manipulating the 'next' p...
Nov 15, 2024CVE-2024-25566 is an open-redirect vulnerability in PingAM where attackers can craft requests that bypass URL validation. This allows redirecting user...
Oct 29, 2024This vulnerability in Public Knowledge Project pkp-lib allows attackers to redirect users to malicious websites after logout due to insufficient input...
Oct 21, 2024This vulnerability allows attackers to spoof the address bar in Firefox for Android by exploiting an open redirect on a trusted site. When users are r...
Sep 17, 2024CVE-2024-7260 is an open redirect vulnerability in Keycloak that allows attackers to craft malicious URLs that appear to be legitimate Keycloak pages ...
Sep 9, 2024WebITR from Uniong has an Open Redirect vulnerability that allows attackers to create malicious URLs that appear legitimate. When users click these li...
Sep 9, 2024This CVE describes an open redirect vulnerability in Loway software where attackers can redirect users to malicious websites. It affects systems runni...
Sep 8, 2024This vulnerability allows malicious websites with popup permissions to overlay select elements on top of legitimate sites, enabling UI spoofing attack...
Sep 3, 2024An open redirect vulnerability in vTiger CRM v7.4.0 allows attackers to craft malicious URLs that redirect users to untrusted external sites. This aff...
Aug 29, 2024This CVE describes an Open Redirect vulnerability in Gnuboard v6.0.4 and earlier versions. Attackers can manipulate the 'url' parameter in the login p...
Aug 26, 2024OpenSearch Dashboards Security Plugin versions before 1.3.19 and 2.16.0 have an open redirect vulnerability in the login flow. Attackers can craft mal...
Aug 23, 2024This vulnerability in WebOb allows attackers to manipulate HTTP redirects by injecting malicious URLs into Location headers, potentially redirecting u...
Aug 14, 2024The WPS Hide Login WordPress plugin before version 1.9.16.4 fails to properly restrict access to hidden login pages, allowing unauthenticated visitors...
Jul 15, 2024An open redirect vulnerability in imartinez/privategpt version 0.5.0 allows attackers to redirect users to malicious websites by manipulating the 'fil...
Jun 27, 2024About Open Redirect (CWE-601)
A web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a Redirect.
Our database tracks 263 CVEs classified as CWE-601, with 8 rated critical and 49 rated high severity. The average CVSS score for Open Redirect vulnerabilities is 5.9.
External reference: View CWE-601 on MITRE CWE →
Monitor Open Redirect Vulnerabilities
Get alerted when new Open Redirect CVEs affect your infrastructure.
Start Monitoring Free