Open Redirect

CWE-601 · 3 records · 1 with a public proof-of-concept

Records the NVD classes as Open Redirect (CWE-601), highest CVSS first.

  1. MEDIUM 5.4CVE-2026-14219

    URL redirection to untrusted site ('open redirect') vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Phishing. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.

    AI risk analysis on Exploit-DB.ai →

  2. MEDIUM 4.7CVE-2026-16296

    The Clearfy Cache WordPress plugin before 2.4.3 does not validate the redirect target in its Cyrlitera old-URL redirect handler, passing a decoded request URI to an unsafe redirect function, which allows unauthenticated attackers to redirect visitors to an ar

    AI risk analysis on Exploit-DB.ai →

  3. MEDIUM 4.3CVE-2026-71240public PoC

    DjangoCRM's toggle_default_sorting view is the only route in common/urls.py that is not wrapped in login_required or staff_member_required, and it redirects to a caller-supplied next_url GET parameter after only checking secure_url(next_url), which merely veri

    AI risk analysis on Exploit-DB.ai →