Flask-AppBuilder is an application development framework, built on top of the Flask web framework. Flask-AppBuilder contains an open redirect vulnera…
Open Redirect on login in GitHub repository go-gitea/gitea prior to 1.16.5.
Cscms Music Portal System v4.2 was discovered to contain a redirection vulnerability via the backurl parameter.
The Page Builder KingComposer WordPress plugin through 2.9.6 does not validate the id parameter before redirecting the user to it via the kc_get_thum…
The redirect URI in the LTI authorization endpoint required extra sanitizing to prevent reflected XSS and open redirect risks. Moodle versions 3.10 t…
alltube is an html front end for youtube-dl. On releases prior to 3.0.3, an attacker could craft a special HTML page to trigger either an open redire…
Nextcloud talk is a self hosting messaging service. In versions prior 12.1.2 an attacker is able to control the link of a geolocation preview in the …
Open Redirect in GitHub repository archivy/archivy prior to 1.7.0.
Open Redirect in GitHub repository medialize/uri.js prior to 1.19.10.
Multiple Open Redirect in GitHub repository nitely/spirit prior to 0.12.3.
DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through URL redirection to untrusted site.
A vulnerability was found in openstack-nova's console proxy, noVNC. By crafting a malicious URL, noVNC could be made to redirect to any desired URL.
An issue was discovered in the web application in Cherwell Service Management (CSM) 10.2.3. Injection of a malicious payload within the RelayState= p…
An issue was discovered in the web application in Cherwell Service Management (CSM) 10.2.3. It accepts and reflects arbitrary domains supplied via a …
The package karma before 6.3.16 are vulnerable to Open Redirect due to missing validation of the return_url query parameter.
In JetBrains TeamCity before 2021.2.1, a redirection to an external site was possible.
A remote URL redirection vulnerability was discovered in HPE OneView Global Dashboard version(s): Prior to 2.5. HPE has provided a software update to…
Open Redirect on Rudloff/alltube in Packagist rudloff/alltube prior to 3.0.1.
Jenkins GitLab Authentication Plugin 1.13 and earlier records the HTTP Referer header as part of the URL query parameters when the authentication pro…
Open Redirect in Packagist microweber/microweber prior to 1.2.11.
The WordPress Newsletter Plugin WordPress plugin before 1.6.5 does not validate the to parameter before redirecting the user to its given value, lead…
An issue in the Login page of Magnolia CMS v6.2.3 and below allows attackers to exploit both an Open Redirect vulnerability and Cross-Site Request Fo…
Open Redirect in Packagist microweber/microweber prior to 1.2.11.
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions there is no protection …
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0). Affected products contain an open redirect vulnerability. …
Gitea before 1.4.3 is affected by URL Redirection to Untrusted Site ('Open Redirect') via internal URLs.
In affected Octopus Server versions when the server HTTP and HTTPS bindings are configured to localhost, Octopus Server will allow open redirects.
Open Redirect vulnerability exists in SeedDMS 6.0.15 in out.Login.php, which llows remote malicious users to redirect users to malicious sites using …
Adenza AxiomSL ControllerView through 10.8.1 allows redirection for SSO login URLs.
Products.ATContentTypes are the core content types for Plone 2.1 - 4.3. Versions of Plone that are dependent on Products.ATContentTypes prior to vers…