VulnSea

CWE-601

CVEs classified under CWE-601, newest first.

140 CVEsRSS

CVE-2026-54915Medium· 5.4
today

Tautulli: Open redirect via whitespace bypass in /auth/redirect

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to 2.17.2, the unauthenticated /auth/redirect endpoint in plexpy/webauth.py removes forward slashes from the user-controlled redirect_uri parameter but …

SunlitTautulli · Tautullivia CVEORG
CVE-2026-94216Medium· 4.3PoC
today

A vulnerability was determined in ST Engineering iDirect Evolution and Velocity WebServer Evolution up to 20260717

A vulnerability was determined in ST Engineering iDirect Evolution and Velocity WebServer Evolution up to 20260717. This vulnerability affects the function authorize of the file /usr/sbin/webserver of the component HTTP Header Handler. E…

TwilightST Engineering iDirect · Evolutionvia NVD
CVE-2026-94214Medium· 4.3
today

A vulnerability was found in ST Engineering iDirect Evolution and Velocity WebServer Evolution up to 20260717

A vulnerability was found in ST Engineering iDirect Evolution and Velocity WebServer Evolution up to 20260717. This affects an unknown part of the file /login.html of the component Management Service. Performing a manipulation of the arg…

SunlitST Engineering iDirect · Evolutionvia NVD
CVE-2026-94102Medium· 4.3
today

A flaw has been found in WuzhiCMS up to 4.1.0

A flaw has been found in WuzhiCMS up to 4.1.0. This affects an unknown function of the file /index.php?m=member&v=Login of the component Login. This manipulation of the argument forward causes open redirect. The attack can be initiated r…

SunlitEPSS 0.25%via NVD
CVE-2026-7527Medium· 4.7
2d ago

The WP Ghost (Hide My WP Ghost) – Security & Firewall plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 7.0.02

The WP Ghost (Hide My WP Ghost) – Security & Firewall plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 7.0.02. This is due to the plugin not properly validating user input. This makes it possible …

Sunlitjohndarrel · Hide My WP Ghost – Security & FirewallEPSS 0.22%via NVD
CVE-2026-93871Medium· 5.4PoC
3d ago

Cotonti through 1.0.0 fails to validate redirect destinations in page bodies prefixed with redir:, allowing authenticated users with page creation or edit permissions to store redirects to arbitrary external hosts

Cotonti through 1.0.0 fails to validate redirect destinations in page bodies prefixed with redir:, allowing authenticated users with page creation or edit permissions to store redirects to arbitrary external hosts. Attackers can craft pa…

TwilightCotonti · CotontiEPSS 0.17%via NVD
CVE-2026-93869Medium· 6.1PoC
3d ago

Cotonti through 1.0.0 contains an open redirect vulnerability in the cot_url_check() function that validates redirect destinations using a regular expression lacking an end-of-string anchor

Cotonti through 1.0.0 contains an open redirect vulnerability in the cot_url_check() function that validates redirect destinations using a regular expression lacking an end-of-string anchor. Attackers can bypass the redirect guard by sup…

TwilightCotonti · CotontiEPSS 0.22%via NVD
CVE-2026-77386Medium· 6.5
3d ago

Kyoo is a self-hosted media server focused on movies, series, and anime

Kyoo is a self-hosted media server focused on movies, series, and anime. Prior to 5.1.0, an unauthenticated attacker could initiate the OIDC login flow with an attacker-controlled redirectUrl. The login handling in auth/oidc.go stored th…

Sunlitzoriya · KyooEPSS 0.39%via NVD
CVE-2026-77609Medium· 6.1
3d ago

Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages

Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Prior to version 7.2.0, `Special:URIResolver` resolves its user-controlled subpage to a MediaWiki title and is…

Sunlitmediawiki · mediawiki/semantic-media-wikiEPSS 0.15%via NVD
CVE-2026-54618Critical· 9.4
4d ago

Obsidian Web MCP is a secure remote MCP server for Obsidian vaults

Obsidian Web MCP is a secure remote MCP server for Obsidian vaults. Prior to 0.2.0, /oauth/authorize issues an authorization code without a login, consent, or session check, and /oauth/token can exchange that code for the static VAULT_MC…

Midnightjimprosser · obsidian-web-mcpEPSS 0.40%via NVD
CVE-2026-65388High· 7.5
5d ago

A remote attacker who controls a container registry may be able to direct a client's token request to a host of the attacker's choice, and disclose the victim's registry credentials to that host

A remote attacker who controls a container registry may be able to direct a client's token request to a host of the attacker's choice, and disclose the victim's registry credentials to that host. This vulnerability is addressed in contai…

TwilightApple · containerizationEPSS 0.27%via NVD
CVE-2026-92141Medium· 4.3
5d ago

Jenkins Keycloak Authentication Plugin 2.4.1 and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks.

Jenkins Keycloak Authentication Plugin 2.4.1 and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks.

SunlitJenkins Project · Jenkins Keycloak Authentication PluginEPSS 0.32%via NVD
CVE-2026-86823Medium· 5.3
5d ago

The Newsletter WordPress plugin before 9.3.7 does not validate the destination of the redirect performed after a public subscription action, allowing unauthenticated attackers to redirect users to arbitrary external sites and to disclos…

The Newsletter WordPress plugin before 9.3.7 does not validate the destination of the redirect performed after a public subscription action, allowing unauthenticated attackers to redirect users to arbitrary external sites and to disclos…

SunlitEPSS 0.25%via NVD
CVE-2026-92216Medium· 4.3
5d ago

A vulnerability was found in a2ui-project a2ui up to 0.10.7

A vulnerability was found in a2ui-project a2ui up to 0.10.7. Affected by this issue is the function openUrl of the file renderers/web_core/src/v0_9/rendering/generic-binder.ts of the component Binder. The manipulation results in open red…

Sunlita2ui-project · a2uiEPSS 0.44%via NVD
GHSA-rf68-8gjr-36q7Low
6d ago

Nezha: OAuth2 redirect_uri Host header injection regression when dashboard_host is empty

Nezha: OAuth2 redirect_uri Host header injection regression when dashboard_host is empty

Sunlitnezhahq · github.com/nezhahq/nezhavia OSV
CVE-2026-83320High· 7.6
6d ago

Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Administration)

Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Administration). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged at…

TwilightOracle Corporation · Oracle BI PublisherEPSS 0.26%via NVD
CVE-2026-83198Medium· 5.4
6d ago

Vulnerability in the Oracle Field Service product of Oracle E-Business Suite (component: Internal Operations)

Vulnerability in the Oracle Field Service product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with…

SunlitOracle Corporation · Oracle Field ServiceEPSS 0.17%via NVD
CVE-2026-89307Medium· 5.1
6d ago

The "Firma Circolare" feature in the "Design Scuole Italia" WordPress theme allows an authenticated attacker to inject arbitrary HTML via the sign parameter, enabling forced redirection of visiting users to an attacker-controlled URL (St…

The "Firma Circolare" feature in the "Design Scuole Italia" WordPress theme allows an authenticated attacker to inject arbitrary HTML via the sign parameter, enabling forced redirection of visiting users to an attacker-controlled URL (St…

SunlitDevelopers Italia · design-scuole-wordpress-themeEPSS 0.28%via NVD
CVE-2026-92069Low· 3.4
6d ago

Spoofing issue in the DOM: Navigation component

Spoofing issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

SunlitMozilla · FirefoxEPSS 0.14%via NVD
CVE-2026-91772Medium· 6.1PoC
6d ago

Halo through 2.26.1 contains an open redirect vulnerability in the anonymous thumbnail endpoint that fails to validate the uri query parameter

Halo through 2.26.1 contains an open redirect vulnerability in the anonymous thumbnail endpoint that fails to validate the uri query parameter. Attackers can craft malicious links on the trusted Halo domain that redirect visitors to arbi…

Twilighthalo-dev · haloEPSS 0.18%via NVD
CVE-2026-54724Medium· 6.1
6d ago

Kiwi TCMS is an open source test management system

Kiwi TCMS is an open source test management system. Prior to 16.1, the account confirmation endpoint accepted an unvalidated next parameter, allowing an unauthenticated attacker to create a URL on a trusted Kiwi TCMS hostname that redire…

Sunlitkiwitcms · KiwiEPSS 0.26%via NVD
CVE-2026-13277Medium· 4.7
1w ago

IBM Verify Identity Access could allow a remote attacker to conduct phishing attacks, using an open redirect attack

IBM Verify Identity Access could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoo…

SunlitIBM · Verify Identity AccessEPSS 0.28%via NVD
CVE-2026-15412Medium· 6.5
1w ago

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty could allow a remote attacker to conduct phishing attacks, using an open redirect attack

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted We…

SunlitIBM · WebSphere Application ServerEPSS 0.22%via NVD
CVE-2023-24034Low· 3.1
1w ago

An issue was discovered in twilio_ajax_handler.php in Nagios XI before 5.9.3

An issue was discovered in twilio_ajax_handler.php in Nagios XI before 5.9.3. An attacker can force a user to visit a malicious site by using a open redirect vulnerability.

SunlitNagios · Nagios XIEPSS 0.53%via NVD
CVE-2026-12985Medium· 6.8
1w ago

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7 Mattermost failed to validate Dynamic Client Registration redirect URIs by URL component (matching glob patterns against the raw URI string instead) which allows a …

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7 Mattermost failed to validate Dynamic Client Registration redirect URIs by URL component (matching glob patterns against the raw URI string instead) which allows a …

SunlitMattermost · MattermostEPSS 0.28%via NVD
CVE-2026-73191Medium· 6.1
1w ago

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache Syncope. When the Syncope SRA is configured for CAS authentication, the target Apereo CAS instance's URL is calculated by unconditionally looking at client-…

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache Syncope. When the Syncope SRA is configured for CAS authentication, the target Apereo CAS instance's URL is calculated by unconditionally looking at client-…

SunlitApache Software Foundation · org.apache.syncope:syncope-sraEPSS 0.29%via NVD
CVE-2026-80072Medium· 4.7
1w ago

The User Registration & Membership WordPress plugin before 5.2.8 does not validate the destination of a post-login redirect before redirecting, allowing unauthenticated attackers to redirect visitors to an arbitrary external URL, which …

The User Registration & Membership WordPress plugin before 5.2.8 does not validate the destination of a post-login redirect before redirecting, allowing unauthenticated attackers to redirect visitors to an arbitrary external URL, which …

SunlitEPSS 0.17%via NVD
CVE-2026-90453Medium· 5.1
1w ago

A file-upload handler redirects the authenticated client's browser to a URL taken directly from that same request's Referer header, without validating it against the application's own origin

A file-upload handler redirects the authenticated client's browser to a URL taken directly from that same request's Referer header, without validating it against the application's own origin. This allows an authenticated attacker to craf…

SunlitCISA · MalcolmEPSS 0.22%via NVD
CVE-2026-81913Medium· 5.3
1w ago

Concrete CMS versions 9.5.0 through 9.5.2 are vulnerable to Open Redirect via the rcURL parameter

Concrete CMS versions 9.5.0 through 9.5.2 are vulnerable to Open Redirect via the rcURL parameter. An attacker can craft a single link on the site's own domain that sends a user to an arbitrary external site immediately after authenticat…

SunlitConcrete CMS · Concrete CMSEPSS 0.59%via NVD
CVE-2026-54072Critical· 9.3PoC
1w ago

Authorizer is an open-source, self-hostable authentication and authorization server

Authorizer is an open-source, self-hostable authentication and authorization server. Prior to version 2.2.1, the `/authorize` endpoint accepts any `redirect_uri` without validating it against `AllowedOrigins`. When `response_type=token` …

Abyssalauthorizerdev · authorizerEPSS 0.27%via NVD
CWE-601 vulnerabilities (CVEs) · VulnSea