The AnyComment WordPress plugin before 0.3.5 has an API endpoint which passes user input via the redirect parameter to t
The Event Tickets WordPress plugin before 5.2.2 does not validate the tribe_tickets_redirect_to parameter before redirec
The WebP Converter for Media WordPress plugin before 4.0.3 contains a file (passthru.php) which does not validate the sr
Adenza AxiomSL ControllerView through 10.8.1 allows redirection for SSO login URLs.
Open Redirect vulnerability exists in SeedDMS 6.0.15 in out.Login.php, which llows remote malicious users to redirect us
In affected Octopus Server versions when the server HTTP and HTTPS bindings are configured to localhost, Octopus Server
Gitea before 1.4.3 is affected by URL Redirection to Untrusted Site ('Open Redirect') via internal URLs.
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0). Affected products contain an
Open Redirect in Packagist microweber/microweber prior to 1.2.11.
The WordPress Newsletter Plugin WordPress plugin before 1.6.5 does not validate the to parameter before redirecting the
Open Redirect in Packagist microweber/microweber prior to 1.2.11.
Open Redirect on Rudloff/alltube in Packagist rudloff/alltube prior to 3.0.1.
A remote URL redirection vulnerability was discovered in HPE OneView Global Dashboard version(s): Prior to 2.5. HPE has
In JetBrains TeamCity before 2021.2.1, a redirection to an external site was possible.
An issue was discovered in the web application in Cherwell Service Management (CSM) 10.2.3. Injection of a malicious pay
An issue was discovered in the web application in Cherwell Service Management (CSM) 10.2.3. It accepts and reflects arbi
A vulnerability was found in openstack-nova's console proxy, noVNC. By crafting a malicious URL, noVNC could be made to
DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through URL redirection to untrust
Multiple Open Redirect in GitHub repository nitely/spirit prior to 0.12.3.
Open Redirect in GitHub repository medialize/uri.js prior to 1.19.10.
Open Redirect in GitHub repository archivy/archivy prior to 1.7.0.
The redirect URI in the LTI authorization endpoint required extra sanitizing to prevent reflected XSS and open redirect
The Page Builder KingComposer WordPress plugin through 2.9.6 does not validate the id parameter before redirecting the u
Open Redirect on login in GitHub repository go-gitea/gitea prior to 1.16.5.
Flask-AppBuilder is an application development framework, built on top of the Flask web framework. Flask-AppBuilder cont
An issue was discovered in Joomla! 2.5.0 through 3.10.6 & 4.0.0 through 4.1.0. Inadequate validation of URLs could resul
URL Confusion When Scheme Not Supplied in GitHub repository medialize/uri.js prior to 1.19.11.
Open redirect vulnerability in objects/login.json.php in WWBN AVideo through 11.6, allows attackers to arbitrarily redir
A PHP Local File inclusion vulnerability in the Redbasic theme for Hubzilla before version 7.2 allows remote attackers t
Open redirect vulnerability via endpoint authorize_and_redirect/?redirect= in GitHub repository posthog/posthog prior to
next-auth v3 users before version 3.29.2 are impacted. next-auth version 4 users before version 4.3.2 are also impacted.
A URL redirection vulnerability in Skyhigh SWG in main releases 10.x prior to 10.2.9, 9.x prior to 9.2.20, 8.x prior to
An intent redirection vulnerability in the Mi App Store product. This vulnerability is caused by the Mi App Store does n
The English WordPress Admin WordPress plugin before 1.5.2 does not validate the admin_custom_language_return_url before
In nopCommerce 4.50.1, an open redirect vulnerability can be triggered by luring a user to authenticate to a nopCommerce
SonicWall SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier versions accept a user-controlled input that specifie
Open redirect via user-controlled query parameter. The following products are affected: Acronis Cyber Protect 15 (Linux,
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository jgraph/drawio prior to 18.0.7.
NextAuth.js (next-auth) is am open source authentication solution for Next.js applications. Prior to versions 3.29.3 and
E-Series SANtricity OS Controller Software 11.x versions through 11.70.2 are vulnerable to host header injection attacks
Caddy v2.4 was discovered to contain an open redirect vulnerability. A remote unauthenticated attacker may exploit this
bypass CVE-2021-25640 > In Apache Dubbo prior to 2.6.12 and 2.7.15, the usage of parseURL method will lead to the bypass
An issue was discovered in u5cms verion 8.3.5 There is a URL redirection vulnerability that can cause a user's browser t
Open redirect vulnerability in web2py versions prior to 2.22.5 allows a remote attacker to redirect a user to an arbitra
In Nagios XI through 5.8.5, an open redirect vulnerability exists in the login function that could lead to spoofing.
ApiFest OAuth 2.0 Server 0.3.1 does not validate the redirect URI in accordance with RFC 6749 and is susceptible to an o
Open Redirect in GitHub repository microweber/microweber prior to 1.2.19.
Best Practical Request Tracker (RT) before 5.0.3 has an Open Redirect via a ticket search.
An open redirect issue was found in Moodle due to improper sanitization of user-supplied data in mobile auto-login featu
Open redirect vulnerability in Booked versions prior to 3.3 allows a remote unauthenticated attacker to redirect a user
Frequently Asked Questions
What is CWE-601?
CWE-601 (CWE-601) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-601?
There are 1,953 CVE records associated with CWE-601 in our database. Of these, 31 are critical severity, 165 are high severity, and 1323 are medium severity.
How can I protect against CWE-601 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-601 using AI-powered security agents.
Detect CWE-601 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-601 vulnerabilities across your infrastructure.
Get Started