CWE-601: Open Redirect

A web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a Redirect.

263
Total CVEs
8
Critical
49
High
5.9
Avg CVSS

Yearly Trend

2026
35
2025
149
2024
56
2023
18
2022
2

Top Affected Vendors

1 Wegia 7
2 Adobe 7
3 Mozilla 7
4 Sap 6
5 Liferay 4
6 Microsoft 4
7 Redhat 4
8 Solarwinds 3
9 Esri 3
10 Sir 3

All Open Redirect CVEs (263)

CVE-2025-39599
4.7

This CVE describes an open redirect vulnerability in Webilia Inc.'s Listdom WordPress plugin that allows attackers to redirect users to malicious webs...

Apr 16, 2025
CVE-2025-32694
4.7

This vulnerability allows attackers to redirect users from legitimate WordPress sites to malicious websites through the Ultimate WP Mail plugin. Attac...

Apr 9, 2025
CVE-2025-31871
4.7

This vulnerability allows attackers to redirect users from legitimate WordPress sites to malicious websites through the WP Clone any post type plugin....

Apr 1, 2025
CVE-2025-31821
4.7

This vulnerability allows attackers to redirect users from legitimate WordPress sites to malicious websites through the Integration of Zoho CRM and Co...

Apr 1, 2025
CVE-2025-30884
4.7

This CVE describes an open redirect vulnerability in the Bit Integrations WordPress plugin that allows attackers to redirect users to malicious websit...

Mar 27, 2025
CVE-2025-30859
4.7

This CVE describes an open redirect vulnerability in the AliNext WordPress plugin that allows attackers to redirect users to malicious websites. Attac...

Mar 27, 2025
CVE-2025-30781
4.7

This vulnerability allows attackers to redirect users from legitimate WooCommerce order status pages to malicious websites through crafted URLs. It af...

Mar 27, 2025
CVE-2025-1488
4.7

The WPO365 Microsoft 365 Graph Mailer WordPress plugin has an open redirect vulnerability in all versions up to 3.2. Unauthenticated attackers can red...

Feb 24, 2025
CVE-2025-24740
4.7

This vulnerability allows attackers to redirect users from a legitimate LearnPress WordPress plugin page to malicious external websites. It affects al...

Jan 27, 2025
CVE-2024-54255
4.7

This CVE describes an open redirect vulnerability in the Login Widget With Shortcode WordPress plugin from aviplugins.com. Attackers can craft malicio...

Dec 9, 2024
CVE-2024-50463
4.7

This CVE describes an open redirect vulnerability in the Sunshine Photo Cart WordPress plugin. Attackers can craft malicious URLs that redirect users ...

Oct 28, 2024
CVE-2024-47354
4.7

This CVE describes an open redirect vulnerability in the WordPress Simple Membership After Login Redirection plugin. Attackers can craft malicious URL...

Oct 10, 2024
CVE-2024-46886
4.7

This vulnerability is an open redirect flaw in Siemens web servers where improper input validation allows attackers to redirect legitimate users to ma...

Oct 8, 2024
CVE-2024-9266
4.7

This CVE describes an open redirect vulnerability in Express.js versions 3.4.5 through 3.x that allows attackers to redirect users to malicious websit...

Oct 3, 2024
CVE-2024-39694
4.7

Duende IdentityServer contains an open redirect vulnerability where attackers can craft malicious URLs that are incorrectly treated as local and trust...

Jul 31, 2024
CVE-2024-41801
4.7

OpenProject versions before 14.3.0 are vulnerable to host header injection, allowing attackers to forge HOST headers to redirect users to malicious si...

Jul 25, 2024
CVE-2024-33930
4.7

This CVE describes an open redirect vulnerability in the WordPress Share This Image plugin. Attackers can craft malicious URLs that redirect users to ...

May 2, 2024
CVE-2024-25676
4.7

ViewerJS 0.5.8 contains an open redirection and out-of-band resource loading vulnerability due to improper URL sanitization in URL TAGs. This allows a...

May 1, 2024
CVE-2025-21401
4.5

This vulnerability allows attackers to bypass security features in Microsoft Edge, potentially enabling malicious websites to perform actions that sho...

Feb 15, 2025
CVE-2026-27982
4.3

An open redirect vulnerability in django-allauth allows attackers to redirect users to malicious external websites via crafted URLs when SAML IdP init...

Mar 5, 2026
CVE-2026-1369
4.3

The Conditional CAPTCHA WordPress plugin through version 4.0.0 contains an open redirect vulnerability that allows attackers to redirect users to mali...

Feb 22, 2026
CVE-2026-2153
4.3

This CVE describes an open redirect vulnerability in mwielgoszewski's doorman application up to version 0.6. Attackers can manipulate the 'Next' param...

Feb 8, 2026
CVE-2026-20123
4.3

An open redirect vulnerability in Cisco EPNM and Prime Infrastructure web interfaces allows attackers to redirect users to malicious websites by manip...

Feb 4, 2026
CVE-2026-22912
4.3

This vulnerability allows attackers to redirect authenticated users to malicious websites through improper validation of a login parameter. It affects...

Jan 15, 2026
CVE-2026-22032
4.3

An open redirect vulnerability in Directus SAML authentication allows attackers to redirect users to malicious external websites after authentication....

Jan 8, 2026
CVE-2025-14692
4.3

This CVE describes an open redirect vulnerability in Mayan EDMS up to version 4.10.1. Attackers can manipulate the authentication component to redirec...

Dec 15, 2025
CVE-2025-67587
4.3

This vulnerability allows attackers to redirect users from legitimate WordPress sites to malicious websites through the WP Gravity Forms FreshDesk Plu...

Dec 9, 2025
CVE-2025-62595
4.3

This CVE describes a URL redirect bypass vulnerability in Koa.js middleware for Node.js. Attackers can manipulate the Referer header to force user bro...

Oct 21, 2025
CVE-2025-35059
4.3

This vulnerability in Newforma Info Exchange (NIX) allows unauthenticated attackers to redirect users to arbitrary external websites via the 'nhl' par...

Oct 9, 2025
CVE-2025-59426
4.3

This CVE describes an open redirect vulnerability in Lobe Chat's OIDC implementation. Attackers can manipulate X-Forwarded-* headers to redirect users...

Sep 25, 2025
CVE-2025-10229
4.3

This CVE describes an open redirect vulnerability in Freshwork's logout endpoint. Attackers can manipulate the post_logout_redirect_uri parameter to r...

Sep 10, 2025
CVE-2025-20291
4.3

This vulnerability allowed unauthenticated remote attackers to redirect Cisco Webex Meetings users to malicious websites through specially crafted mee...

Sep 3, 2025
CVE-2025-55706
4.3

This CVE describes an open redirect vulnerability in Movable Type's password reset functionality. Attackers can manipulate parameters to redirect user...

Aug 20, 2025
CVE-2025-7785
4.3

This CVE describes an open redirect vulnerability in JeeSite's SSO controller that allows attackers to redirect users to malicious websites. The vulne...

Jul 18, 2025
CVE-2025-6552
4.3

This vulnerability in Hope-Boot 1.0.0 allows attackers to redirect users to malicious websites through manipulation of the redirect_url parameter in t...

Jun 24, 2025
CVE-2025-6089
4.3

This vulnerability in Astun Technology iShare Maps allows attackers to redirect users to malicious websites by manipulating the 'ref' parameter in atC...

Jun 15, 2025
CVE-2025-21104
4.3

Dell NetWorker Management Console versions prior to 19.11.0.4 and version 19.12 contain an open redirect vulnerability that allows unauthenticated att...

Mar 13, 2025
CVE-2024-11955
4.3

This CVE describes an open redirect vulnerability in GLPI versions up to 10.0.17. Attackers can manipulate the 'redirect' parameter in /index.php to r...

Feb 25, 2025
CVE-2025-0970
4.3

This vulnerability in Zenvia Movidesk allows attackers to redirect users to malicious websites by manipulating the ReturnUrl parameter in the login pa...

Feb 2, 2025
CVE-2025-0705
4.3

This CVE describes an open redirect vulnerability in JoeyBling bootplus software. Attackers can manipulate the 'text' parameter in the qrCode function...

Jan 24, 2025
CVE-2024-12990
4.3

This vulnerability allows attackers to redirect users to malicious websites by manipulating the 'nexturl' parameter on the admin verification page in ...

Dec 27, 2024
CVE-2024-7941
4.3

This vulnerability is an Open Redirect issue in Hitachi Energy products where an HTTP parameter can be manipulated to redirect users to malicious webs...

Aug 27, 2024
CVE-2024-7902
4.3

This vulnerability allows attackers to redirect users to malicious websites by manipulating the 'source' parameter in the PKP OJS login/signOut endpoi...

Aug 17, 2024
CVE-2024-21684
4.3

This is an open redirect vulnerability in Bitbucket Data Center that allows unauthenticated attackers to redirect users to arbitrary websites after lo...

Jul 24, 2024
CVE-2024-22244
4.3

This CVE describes an open redirect vulnerability in Harbor container registry software. Attackers can craft malicious URLs that redirect Harbor users...

Jun 10, 2024
CVE-2024-36419
4.3

SuiteCRM versions before 8.6.1 contain a Host Header Injection vulnerability in the /legacy route. This allows attackers to manipulate host headers to...

Jun 10, 2024
CVE-2023-6812
4.3

The WP Compress Image Optimizer WordPress plugin contains an open redirect vulnerability that allows unauthenticated attackers to redirect users to ma...

May 14, 2024
CVE-2025-58067
4.2

This vulnerability in Basecamp's google_sign_in gem allows open redirect attacks when using Google Sign-In in Rails applications. Attackers could redi...

Aug 29, 2025
CVE-2025-57821
4.2

This vulnerability in Basecamp's Google Sign-In gem allows attackers to craft URLs that bypass same-origin checks, potentially redirecting users to ma...

Aug 27, 2025
CVE-2025-6197
4.2

This CVE describes an open redirect vulnerability in Grafana OSS organization switching functionality. Attackers can craft malicious URLs that redirec...

Jul 18, 2025

About Open Redirect (CWE-601)

A web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a Redirect.

Our database tracks 263 CVEs classified as CWE-601, with 8 rated critical and 49 rated high severity. The average CVSS score for Open Redirect vulnerabilities is 5.9.

External reference: View CWE-601 on MITRE CWE →

Monitor Open Redirect Vulnerabilities

Get alerted when new Open Redirect CVEs affect your infrastructure.

Start Monitoring Free