Returnfi develops the Blitz returns-management platform for e-commerce, a focused application operating within the order-fulfillment supply chain. The vendor's observed vulnerability pattern centers on URL-redirection issues that can lead to open redirects, a class typical of web applications handling external integrations and user-facing workflows. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Returnfi over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-60935MEDIUM An open redirect vulnerability in the login endpoint of Blitz Panel v1.17.0 allows attackers to redirect users to malicious domains via a crafted URL. This issue affects the next_u | Dec 24, 2025 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Returnfi.
Media articles that mention a CVE ID that affects a product developed by Returnfi — matched by CVE ID, not by vendor name.