CWE-601: Open Redirect
A web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a Redirect.
Yearly Trend
Top Affected Vendors
All Open Redirect CVEs (263)
This vulnerability in HCL BigFix Remote Control Lite Web Portal allows attackers to execute malicious code by exploiting improper path-relative styles...
Dec 17, 2025This CVE describes an open redirect vulnerability in the WP YouTube Lyte WordPress plugin that allows attackers to redirect users to malicious website...
Nov 21, 2025This CVE describes an open redirect vulnerability in Edimax BR-6258n routers up to version 1.18. Attackers can manipulate the submit-url parameter to ...
Feb 5, 2026An open redirect vulnerability in Moodle's OAuth login flow allows attackers to redirect authenticated users to malicious websites. This affects all M...
Feb 3, 2026This CVE describes an open redirect vulnerability in the Edimax BR-6208AC router's web configuration interface. Attackers can manipulate the wlan-url ...
Dec 30, 2025This CVE describes an open redirect vulnerability in CloudPanel Community Edition where attackers can manipulate the Referer HTTP header to redirect u...
Dec 30, 2025This CVE describes an unvalidated redirect vulnerability in Splunk Enterprise and Cloud Platform where low-privileged authenticated users can create d...
Dec 3, 2025Mattermost versions 10.11.4 and earlier contain an open redirect vulnerability on the /error page. An attacker can craft a malicious link that redirec...
Dec 17, 2025This vulnerability allows unauthenticated attackers to craft malicious URLs that exploit an unvalidated redirect in Splunk Web's login endpoint. When ...
Nov 12, 2025An open redirect vulnerability in Angular SSR allows attackers to manipulate URLs when applications are deployed behind proxies that pass unsanitized ...
Feb 25, 2026Qwik versions before 1.19.0 contain an open redirect vulnerability in Qwik City's default request handler middleware. This allows attackers to create ...
Feb 3, 2026This vulnerability in Jitsi Meet allows attackers to hijack the OAuth authentication window for Microsoft accounts, potentially stealing login credent...
Nov 13, 2025Datasette versions 0.65.1 and below, and 1.0a0 through 1.0a19 contain an open redirect vulnerability where requests to paths starting with double slas...
Nov 7, 2025About Open Redirect (CWE-601)
A web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a Redirect.
Our database tracks 263 CVEs classified as CWE-601, with 8 rated critical and 49 rated high severity. The average CVSS score for Open Redirect vulnerabilities is 5.9.
External reference: View CWE-601 on MITRE CWE →
Monitor Open Redirect Vulnerabilities
Get alerted when new Open Redirect CVEs affect your infrastructure.
Start Monitoring Free