Skip to main content

CWE archive

CWE-601 CVEs

Programmatic archive

1,592 CVEs tagged with CWE-60125 Critical, 153 High, 1,315 Medium, 96 Low, 3 Unrated.

CVE-2025-34440

Published Dec 17, 2025

AVideo versions prior to 20.1 contain an open redirect vulnerability caused by insufficient validation of the siteRedirectUri parameter during user registration. Attackers can red…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-34439

Published Dec 17, 2025

AVideo versions prior to 20.1 are vulnerable to an open redirect flaw due to missing validation of the cancelUri parameter during user login. An attacker can craft a link to redir…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-62690

Published Dec 17, 2025

Mattermost versions 10.11.x <= 10.11.4 fail to validate redirect URLs on the /error page, which allows an attacker to redirect a victim to a malicious site via a crafted link open…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-65581

Published Dec 16, 2025

An open redirect vulnerability exists in the Account module in Volosoft ABP Framework >= 5.1.0 and < 10.0.0-rc.2. Improper validation of the returnUrl parameter in the register fu…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-53901

Published Dec 16, 2025

WBCE CMS 1.6.1 contains a cross-site scripting vulnerability that allows attackers to inject malicious HTML and CSS to capture user keystrokes. Attackers can upload a crafted HTML…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-64250

Published Dec 16, 2025

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in wpWax Directorist directorist allows Phishing.This issue affects Directorist: from n/a through <= 8.6.6.

CVSS 4.7 · Medium

CVE-2025-14692

Published Dec 15, 2025

A flaw has been found in Mayan EDMS up to 4.10.1. The impacted element is an unknown function of the file /authentication/. This manipulation causes open redirect. It is possible…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-14451

Published Dec 13, 2025

The Solutions Ad Manager plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 1.0.0. This is due to insufficient validation on the redirect UR…

CVSS 4.7 · Medium

CVE-2025-34504

Published Dec 11, 2025

KodExplorer 4.52 contains an open redirect vulnerability in the user login page that allows attackers to manipulate the 'link' parameter. Attackers can craft malicious URLs in the…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-67713

Published Dec 11, 2025

Miniflux 2 is an open source feed reader. Versions 2.2.14 and below treat redirect_url as safe when url.Parse(...).IsAbs() is false, enabling phishing flows after login. Protocol-…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-67502

Published Dec 10, 2025

Taguette is an open source qualitative research tool. In versions 1.5.1 and below, attackers can craft malicious URLs that redirect users to arbitrary external websites after aut…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-67587

Published Dec 9, 2025

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks WP Gravity Forms FreshDesk Plugin gf-freshdesk allows Phishing.This issue affects WP Gravity Forms F…

CVSS 4.7 · Medium

CVE-2025-67585

Published Dec 9, 2025

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in flexmls Flexmls® IDX flexmls-idx allows Phishing.This issue affects Flexmls® IDX: from n/a through <= 3.15.7.

CVSS 4.7 · Medium

CVE-2025-11222

Published Dec 4, 2025

Central Dogma versions before 0.78.0 contain an Open Redirect vulnerability that allows attackers to redirect users to untrusted sites via specially crafted URLs, potentially faci…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-58044

Published Dec 1, 2025

JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to v3.10.19 and v4.10.5, The /core/i18n// endpoint uses the Referer header…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-13819

Published Dec 1, 2025

Open redirect in the web server component of MiR Robot and Fleet software allows a remote attacker to redirect users to arbitrary external websites via a crafted parameter, facili…

CVSS 6.1 · Medium

CVE-2025-66062

Published Nov 21, 2025

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Frank Goossens WP YouTube Lyte wp-youtube-lyte allows Phishing.This issue affects WP YouTube Lyte: from n/a th…

CVSS 3.4 · Low

CVE-2024-8527

Published Nov 19, 2025

Open Redirect in URL parameter in Automated Logic WebCTRL and Carrier i-Vu versions 6.0, 6.5, 7.0, 8.0, 8.5, 9.0 may allow attackers to exploit user sessions.

CVSS 8.6 · High

CVE-2025-63828

Published Nov 18, 2025

Host Header Injection vulnerability in Backdrop CMS 1.32.1 allows attackers to manipulate the Host header in password reset requests, leading to redirects to malicious domains and…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-40545

Published Nov 18, 2025

SolarWinds Observability Self-Hosted is susceptible to an open redirection vulnerability. The URL is not properly sanitized, and an attacker could manipulate the string to redirec…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-13983

Published Nov 14, 2025

Inappropriate implementation in Lens in Google Chrome on iOS prior to 136.0.7103.59 allowed a remote attacker to perform UI spoofing via a crafted QR code. (Chromium security seve…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-64754

Published Nov 13, 2025

Jitsi Meet is an open source video conferencing application. A vulnerability present in versions prior to 2.0.10532 allows attackers to hijack the OAuth authentication window for…

CVSS 2.7 · Low

CVE-2025-20355

Published Nov 13, 2025

A vulnerability in the web-based management interface of Cisco Catalyst Center Virtual Appliance could allow an unauthenticated, remote attacker to redirect a user to a malicious…

CVSS 4.7 · Medium

CVE-2025-64716

Published Nov 13, 2025

Anubis is a Web AI Firewall Utility that challenges users' connections in order to protect upstream resources from scraper bots. Prior to version 1.23.0, when using subrequest aut…

CVSS 5.1 · Medium
Showing 276-300 of 1,592 CVEsPage 12 of 64