CVE-2022-33146Medium· 6.1▾ SunlitOpen redirect in web2py
▾ Sunlit zone — Low / medium · no exploitation signal
impact 33.6 · likelihood 0.3 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
1.4%
1.4% → 1.6%
Open redirect vulnerability in web2py versions prior to 2.22.5 allows a remote attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having a user to access a specially crafted URL.
web2py < 2.22.5Upgrade to a patched release:
web2py 2.22.5Connected by shared product, vendor, weakness, or advisory.
CVE-2026-25198Medium· 4.7web2py has an Open Redirect Vulnerability
CVE-2023-22432Medium· 6.1Open redirect in web2py
CVE-2016-4807Medium· 4.8Web2py Reflected XSS vulnerability
CVE-2016-3954Medium· 5.5web2py exposure of sensitive information
CVE-2016-4808Medium· 4.5Web2py Cross-Site Request Forgery vulnerability