Open Redirect
CWE-601 · 3 records · 1 with a public proof-of-concept
Records the NVD classes as Open Redirect (CWE-601), highest CVSS first.
- MEDIUM 5.4CVE-2026-14219
URL redirection to untrusted site ('open redirect') vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Phishing. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.
- MEDIUM 4.7CVE-2026-16296
The Clearfy Cache WordPress plugin before 2.4.3 does not validate the redirect target in its Cyrlitera old-URL redirect handler, passing a decoded request URI to an unsafe redirect function, which allows unauthenticated attackers to redirect visitors to an ar…
- MEDIUM 4.3CVE-2026-71240public PoC
DjangoCRM's toggle_default_sorting view is the only route in common/urls.py that is not wrapped in login_required or staff_member_required, and it redirects to a caller-supplied next_url GET parameter after only checking secure_url(next_url), which merely veri…