CWE-601: Open Redirect

A web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a Redirect.

263
Total CVEs
8
Critical
49
High
5.9
Avg CVSS

Yearly Trend

2026
35
2025
149
2024
56
2023
18
2022
2

Top Affected Vendors

1 Wegia 7
2 Adobe 7
3 Mozilla 7
4 Sap 6
5 Liferay 4
6 Microsoft 4
7 Redhat 4
8 Solarwinds 3
9 Esri 3
10 Sir 3

All Open Redirect CVEs (263)

CVE-2024-23442
6.1

This CVE describes an open redirect vulnerability in Kibana where attackers can craft malicious URLs that redirect users to arbitrary external website...

Jun 14, 2024
CVE-2024-23664
6.1

This CVE describes an open redirect vulnerability in Fortinet FortiAuthenticator that allows attackers to craft malicious URLs that redirect users to ...

Jun 3, 2024
CVE-2022-2237
6.1

CVE-2022-2237 is an open redirect vulnerability in Keycloak's Node.js adapter checkSso function. This allows attackers to redirect users to malicious ...

Mar 27, 2023
CVE-2025-0608
5.5

This CVE describes an open redirect vulnerability in Logo Software Inc.'s Logo Cloud platform that allows attackers to redirect users to malicious web...

Oct 6, 2025
CVE-2025-61782
5.4

OpenCTI versions before 6.8.3 contain an open redirect vulnerability in the SAML authentication callback endpoint. Attackers can manipulate the RelayS...

Jan 7, 2026
CVE-2025-1885
5.4

This CVE describes an open redirect vulnerability in Restajet Information Technologies' Online Food Delivery System that allows attackers to redirect ...

Dec 19, 2025
CVE-2025-67502
5.4

This vulnerability allows attackers to craft malicious URLs that redirect authenticated Taguette users to arbitrary external websites. It affects all ...

Dec 10, 2025
CVE-2025-44109
5.4

CVE-2025-44109 is an open redirect vulnerability in Pinokio v3.6.23 that allows attackers to redirect users to malicious websites. This affects all us...

Jul 23, 2025
CVE-2025-2091
5.4

An open redirection vulnerability in M-Files mobile applications allows attackers to craft malicious PDF files that trick users into visiting untruste...

Jun 16, 2025
CVE-2024-1440
5.4

An open redirection vulnerability in WSO2 products allows attackers to craft malicious authentication links that redirect users to attacker-controlled...

Jun 2, 2025
CVE-2024-55452
5.4

This vulnerability allows authenticated attackers in UJCMS 9.6.3 to create malicious block/carousel items that redirect users to attacker-controlled w...

Dec 16, 2024
CVE-2024-36406
5.4

SuiteCRM versions before 7.14.4 and 8.6.1 contain an open redirect vulnerability due to unchecked input. This allows attackers to redirect users to ma...

Jun 10, 2024
CVE-2023-22260
5.4

This vulnerability allows a low-privilege authenticated attacker to redirect users to malicious websites via an open redirect flaw in Adobe Experience...

Mar 22, 2023
CVE-2023-22262
5.4

This vulnerability allows low-privilege authenticated attackers in Adobe Experience Manager 6.5.15.0 and earlier to redirect users to malicious websit...

Mar 22, 2023
CVE-2023-22264
5.4

This vulnerability allows low-privilege authenticated attackers to create malicious links that redirect users to untrusted websites when clicked. It a...

Mar 22, 2023
CVE-2023-22266
5.4

This vulnerability allows low-privilege authenticated attackers to create malicious links that redirect Adobe Experience Manager users to untrusted we...

Mar 22, 2023
CVE-2023-22256
5.4

This vulnerability allows low-privilege authenticated attackers to create malicious links that redirect users to untrusted websites when clicked. It a...

Mar 22, 2023
CVE-2023-22258
5.4

This vulnerability allows low-privilege authenticated attackers to create malicious links that redirect Adobe Experience Manager users to untrusted we...

Mar 22, 2023
CVE-2026-28413
5.3

This vulnerability in Products.isurlinportal allows attackers to redirect users to external malicious websites after login by manipulating the 'came_f...

Mar 5, 2026
CVE-2025-14524
5.3

This vulnerability in curl allows OAuth2 bearer tokens to be incorrectly passed during cross-protocol redirects from HTTP(S) to IMAP, LDAP, POP3, or S...

Jan 8, 2026
CVE-2025-65581
5.3

An open redirect vulnerability in Volosoft ABP Framework's Account module allows attackers to redirect users to malicious external websites by manipul...

Dec 16, 2025
CVE-2025-55624
5.3

This CVE describes an intent redirection vulnerability in Reolink mobile app version 4.54.0.4.20250526 that allows attackers to bypass intended restri...

Aug 22, 2025
CVE-2025-50181
5.3

This CVE describes a vulnerability in urllib3 where disabling redirects at the PoolManager level fails to properly mitigate SSRF or open redirect atta...

Jun 19, 2025
CVE-2025-0244
5.3

This vulnerability in Firefox for Android allows attackers to spoof the address bar when redirecting to invalid protocol schemes, potentially tricking...

Jan 7, 2025
CVE-2025-40545
4.8

SolarWinds Observability Self-Hosted has an open redirection vulnerability where authenticated attackers can manipulate URLs to redirect users to mali...

Nov 18, 2025
CVE-2025-26394
4.8

SolarWinds Observability Self-Hosted has an open redirection vulnerability where attackers can manipulate URLs to redirect authenticated users to mali...

Jun 10, 2025
CVE-2024-55892
4.8

This vulnerability in TYPO3's URI parsing component allows attackers to bypass host validation checks when processing externally provided URLs. This c...

Jan 14, 2025
CVE-2026-28106
4.7

This CVE describes an open redirect vulnerability in the B2BKing Premium WordPress plugin that allows attackers to redirect users to malicious website...

Mar 6, 2026
CVE-2025-69725
4.7

An open redirect vulnerability in go-chi/chi's RedirectSlashes function allows attackers to craft URLs that appear legitimate but redirect users to ma...

Feb 19, 2026
CVE-2026-1277
4.7

The URL Shortify WordPress plugin contains an open redirect vulnerability that allows unauthenticated attackers to craft malicious links that redirect...

Feb 18, 2026
CVE-2026-25198
4.7

This CVE describes an open redirect vulnerability in web2py web framework. Attackers can craft malicious URLs that redirect users to arbitrary externa...

Feb 5, 2026
CVE-2026-0513
4.7

An open redirect vulnerability in SAP Supplier Relationship Management allows unauthenticated attackers to craft malicious URLs that redirect victims ...

Jan 13, 2026
CVE-2026-21879
4.7

This CVE describes an Open Redirect vulnerability in Kanboard versions 1.2.48 and below that allows attackers to redirect authenticated users to malic...

Jan 8, 2026
CVE-2025-14451
4.7

The Solutions Ad Manager WordPress plugin has an open redirect vulnerability that allows unauthenticated attackers to redirect users to malicious webs...

Dec 13, 2025
CVE-2025-67585
4.7

This CVE describes an open redirect vulnerability in the flexmls IDX WordPress plugin that allows attackers to redirect users to malicious websites. T...

Dec 9, 2025
CVE-2025-20355
4.7

An open redirect vulnerability in Cisco Catalyst Center Virtual Appliance's web management interface allows unauthenticated remote attackers to redire...

Nov 13, 2025
CVE-2025-60151
4.7

This CVE describes an open redirect vulnerability in the WP Gravity Forms HubSpot plugin for WordPress. Attackers can craft malicious URLs that redire...

Oct 22, 2025
CVE-2025-11167
4.7

This vulnerability allows unauthenticated attackers to redirect WordPress users to malicious websites by exploiting insufficient validation of the 're...

Oct 11, 2025
CVE-2025-58006
4.7

This CVE describes an open redirect vulnerability in the WP Gravity Forms Keap/Infusionsoft WordPress plugin that allows attackers to redirect users t...

Sep 22, 2025
CVE-2025-7702
4.7

This CVE describes an open redirect vulnerability in Pusula Communication's Manageable Email Sending System that allows attackers to redirect users to...

Sep 19, 2025
CVE-2025-54681
4.7

This CVE describes an open redirect vulnerability in the CRM Perks Connector for Gravity Forms and Google Sheets WordPress plugin. Attackers can craft...

Aug 14, 2025
CVE-2025-4296
4.7

An open redirect vulnerability in HotelRunner B2B allows attackers to redirect users to malicious websites by manipulating URLs. This affects HotelRun...

Jul 23, 2025
CVE-2025-54066
4.7

This vulnerability in DiracX-Web allows attackers to redirect authenticated users to malicious websites through an unvalidated redirect parameter. Att...

Jul 17, 2025
CVE-2025-53821
4.7

This CVE describes an Open Redirect vulnerability in WeGIA web management software where attackers can manipulate the 'nextPage' parameter in control....

Jul 14, 2025
CVE-2025-49325
4.7

This CVE describes an open redirect vulnerability in the Newspack Newsletters WordPress plugin that allows attackers to redirect users to malicious we...

Jun 6, 2025
CVE-2025-30953
4.7

This CVE describes an open redirect vulnerability in the WP Gravity Forms Salesforce plugin for WordPress. Attackers can craft malicious URLs that red...

Jun 6, 2025
CVE-2025-47644
4.7

This CVE describes an open redirect vulnerability in the 'Integrations of Zoho CRM with Elementor form' WordPress plugin. Attackers can craft maliciou...

May 7, 2025
CVE-2025-47455
4.7

This vulnerability allows attackers to redirect users from legitimate WooCommerce/Salesforce integration pages to malicious websites through crafted U...

May 7, 2025
CVE-2025-39404
4.7

This CVE describes an open redirect vulnerability in the Heateor Support Sassy Social Share WordPress plugin. Attackers can craft malicious URLs that ...

Apr 24, 2025
CVE-2025-39597
4.7

This CVE describes an open redirect vulnerability in the Fast eBay Listings WordPress plugin that allows attackers to redirect users to malicious webs...

Apr 16, 2025

About Open Redirect (CWE-601)

A web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a Redirect.

Our database tracks 263 CVEs classified as CWE-601, with 8 rated critical and 49 rated high severity. The average CVSS score for Open Redirect vulnerabilities is 5.9.

External reference: View CWE-601 on MITRE CWE →

Monitor Open Redirect Vulnerabilities

Get alerted when new Open Redirect CVEs affect your infrastructure.

Start Monitoring Free