CVE-2026-25198Medium· 4.7▾ Sunlitweb2py has an Open Redirect Vulnerability
▾ Sunlit zone — Low / medium · no exploitation signal
impact 25.9 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 13.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.3%
0.3% → 0.3%
web2py versions 2.27.1-stable+timestamp.2023.11.16.08.03.57 and prior contain an Open Redirect vulnerability. If this vulnerability is exploited, the user may be redirected to an arbitrary website when accessing a specially crafted URL. As a result, the user may become a victim of a phishing attack.
web2py < 3.1.1Upgrade to a patched release:
web2py 3.1.1Connected by shared product, vendor, weakness, or advisory.
CVE-2016-4807Medium· 4.8Web2py Reflected XSS vulnerability
CVE-2016-3954Medium· 5.5web2py exposure of sensitive information
CVE-2016-4808Medium· 4.5Web2py Cross-Site Request Forgery vulnerability
CVE-2022-33146Medium· 6.1Open redirect in web2py
CVE-2023-22432Medium· 6.1Open redirect in web2py