CWE-601: Open Redirect

A web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a Redirect.

263
Total CVEs
8
Critical
49
High
5.9
Avg CVSS

Yearly Trend

2026
35
2025
149
2024
56
2023
18
2022
2

Top Affected Vendors

1 Wegia 7
2 Adobe 7
3 Mozilla 7
4 Sap 6
5 Liferay 4
6 Microsoft 4
7 Redhat 4
8 Solarwinds 3
9 Esri 3
10 Sir 3

All Open Redirect CVEs (263)

CVE-2025-55254
3.7

This vulnerability in HCL BigFix Remote Control Lite Web Portal allows attackers to execute malicious code by exploiting improper path-relative styles...

Dec 17, 2025
CVE-2025-66062
3.7

This CVE describes an open redirect vulnerability in the WP YouTube Lyte WordPress plugin that allows attackers to redirect users to malicious website...

Nov 21, 2025
CVE-2026-1970
3.5

This CVE describes an open redirect vulnerability in Edimax BR-6258n routers up to version 1.18. Attackers can manipulate the submit-url parameter to ...

Feb 5, 2026
CVE-2025-67852
3.5

An open redirect vulnerability in Moodle's OAuth login flow allows attackers to redirect authenticated users to malicious websites. This affects all M...

Feb 3, 2026
CVE-2025-15258
3.5

This CVE describes an open redirect vulnerability in the Edimax BR-6208AC router's web configuration interface. Attackers can manipulate the wlan-url ...

Dec 30, 2025
CVE-2025-15241
3.5

This CVE describes an open redirect vulnerability in CloudPanel Community Edition where attackers can manipulate the Referer HTTP header to redirect u...

Dec 30, 2025
CVE-2025-20382
3.5

This CVE describes an unvalidated redirect vulnerability in Splunk Enterprise and Cloud Platform where low-privileged authenticated users can create d...

Dec 3, 2025
CVE-2025-62690
3.1

Mattermost versions 10.11.4 and earlier contain an open redirect vulnerability on the /error page. An attacker can craft a malicious link that redirec...

Dec 17, 2025
CVE-2025-20378
3.1

This vulnerability allows unauthenticated attackers to craft malicious URLs that exploit an unvalidated redirect in Splunk Web's login endpoint. When ...

Nov 12, 2025
CVE-2026-27738
N/A

An open redirect vulnerability in Angular SSR allows attackers to manipulate URLs when applications are deployed behind proxies that pass unsanitized ...

Feb 25, 2026
CVE-2026-25149
N/A

Qwik versions before 1.19.0 contain an open redirect vulnerability in Qwik City's default request handler middleware. This allows attackers to create ...

Feb 3, 2026
CVE-2025-64754
N/A

This vulnerability in Jitsi Meet allows attackers to hijack the OAuth authentication window for Microsoft accounts, potentially stealing login credent...

Nov 13, 2025
CVE-2025-64481
N/A

Datasette versions 0.65.1 and below, and 1.0a0 through 1.0a19 contain an open redirect vulnerability where requests to paths starting with double slas...

Nov 7, 2025

About Open Redirect (CWE-601)

A web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a Redirect.

Our database tracks 263 CVEs classified as CWE-601, with 8 rated critical and 49 rated high severity. The average CVSS score for Open Redirect vulnerabilities is 5.9.

External reference: View CWE-601 on MITRE CWE →

Monitor Open Redirect Vulnerabilities

Get alerted when new Open Redirect CVEs affect your infrastructure.

Start Monitoring Free