CWE-307— Improper Restriction of Excessive Authentication Attempts
The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.— MITRE CWE catalog
689 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-307page 9 of 14
- CVE-2022-4006HIGHCVSS 3.7EG 7.52022-11-15
A vulnerability, which was classified as problematic, has been found in WBCE CMS. Affected by this issue is the function increase_attempts of the file wbce/framework/class.login.php of the component Header Handler. The manipulation of the …
- CVE-2022-3031HIGHCVSS 3.7EG 7.52022-10-17
An issue has been discovered in GitLab CE/EE affecting all versions before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. It may be possible for an attacker to guess a user's password …
- CVE-2026-76779HIGHCVSS 7.4EG 7.42026-10-09
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Restriction of Excessive Authentication Attempts vulnerability. An unauthenticated attacker with remote access could potentially exploit t…
- CVE-2026-105835HIGHCVSS 7.4EG 7.42026-10-06
PLANKA 2.2.0 through 2.2.1 fails to limit incorrect TOTP codes submitted to POST /api/access-tokens/verify-totp, allowing attackers to brute force two-factor authentication codes. Attackers who know a user's password can reuse the ten-minu…
- CVE-2026-102334HIGHCVSS 7.4EG 7.42026-09-28
Nginx Proxy Manager through 2.16.0 lacks rate-limiting on authentication endpoints, allowing unauthenticated attackers to make unlimited password guesses against any account. Attackers can brute-force login credentials via POST /api/tokens…
- CVE-2026-86729HIGHCVSS 7.4EG 7.42026-09-08
WWBN AVideo through commit e01e41ecc (no patched version available) exposes get_api_preauthorize in plugin/API/API.php as a second, undocumented login path. Unlike get_api_signIn, which enforces a rate limit of 10 attempts per 5 minutes vi…
- CVE-2026-76213HIGHCVSS 7.4EG 7.42026-08-19
phpMyFAQ before 4.1.7 contains a brute-force vulnerability in the two-factor authentication step where the failure counter is session-scoped and reset on each successful password re-authentication. Attackers with a valid password can bypas…
- CVE-2026-48084HIGHCVSS 7.4EG 7.42026-08-06
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Versions prior to 1.0.2 don't throttle failed passphrase login attempts. An attacker can submit unlimited wrong passphrase guesses …
- CVE-2026-33667HIGHCVSS 7.4EG 7.42026-04-15
OpenProject is an open-source project management application. In versions prior to 17.3.0, 2FA OTP verification in the confirm_otp action of the two_factor_authentication module has no rate limiting, lockout mechanism, or failed-attempt tr…
- CVE-2026-27981HIGHCVSS 7.4EG 7.42026-03-03
HomeBox is a home inventory and organization system. Prior to 0.24.0, the authentication rate limiter (authRateLimiter) tracks failed attempts per client IP. It determines the client IP by reading, 1. X-Real-IP header, 2. First entry of X-…
- CVE-2024-39398HIGHCVSS 7.4EG 7.42024-08-14
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Restriction of Excessive Authentication Attempts vulnerability that could result in a security feature bypass. An attacker could exploit…
- CVE-2026-65948HIGHCVSS 7.3EG 7.32026-08-10
UnixAuth lacks brute-force protection in Apache Ranger versions <= 2.8.0. Note: UnixAuth is NOT a recommended option for production deployments. Users are recommended to upgrade to version 2.9.0, which fixes this issue.
- CVE-2026-32825HIGHCVSS 7.3EG 7.32026-07-20
dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, the applica…
- CVE-2026-55501HIGHCVSS 7.3EG 7.32026-07-06
9Router is an AI router & token saver. Prior to 0.4.80, the dashboard login rate limiter in src/lib/auth/loginLimiter.js derives the client identity from the attacker-controlled X-Forwarded-For HTTP header, and src/app/api/auth/login/route…
- CVE-2026-45364HIGHCVSS 7.3EG 7.32026-05-15
Better Auth is an authentication and authorization library for TypeScript. Prior to 1.4.17 and 1.5.0-beta.9, Better Auth's HTTP rate limiter keyed each request by the exact textual IP address it received in x-forwarded-for (or the configur…
- CVE-2026-43914HIGHCVSS 7.3EG 7.32026-05-11
Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.4, there is a security vulnerability in Vaultwarden that allows bypassing the login brute-force protection if email 2fa is enabled. If email 2fa is enabled, the un…
- CVE-2025-14362HIGHCVSS 7.3EG 7.32026-04-21
The login limit is not enforced on the SFTP service of Fortra's GoAnywhere MFT prior to 7.10.0 if the Web User attempting to be logged in to is configured to log in with an SSH Key, making the SSH key vulnerable to being guessed via Brute…
- CVE-2025-10161HIGHCVSS 7.3EG 7.32025-11-11
Improper Restriction of Excessive Authentication Attempts, Client-Side Enforcement of Server-Side Security, Reliance on Untrusted Inputs in a Security Decision vulnerability in Turkguven Software Technologies Inc. Perfektive allows Brute F…
- CVE-2023-49810HIGHCVSS 7.3EG 7.32024-01-10
A login attempt restriction bypass vulnerability exists in the checkLoginAttempts functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to captcha bypass, which can be abused by an attacker to…
- CVE-2023-45582HIGHCVSS 7.3EG 7.32023-11-14
An improper restriction of excessive authentication attempts vulnerability [CWE-307] in FortiMail webmail version 7.2.0 through 7.2.4, 7.0.0 through 7.0.6 and before 6.4.8 may allow an unauthenticated attacker to perform a brute force at…
- CVE-2021-3412HIGHCVSS 7.3EG 7.32021-06-01
It was found that all versions of 3Scale developer portal lacked brute force protections. An attacker could use this gap to bypass login controls, and access privileged information, or possibly conduct further attacks.
- CVE-2019-20881HIGHCVSS 7.3EG 7.32020-06-19
An issue was discovered in Mattermost Server before 5.8.0. It mishandles brute-force attacks against MFA.
- CVE-2026-0972HIGHCVSS 5.4EG 7.32026-04-21
HTML injection is possible in system generated emails in Fortra's GoAnywhere MFT prior to 7.10.0. Note: The title, details, and description of this CVE were corrected post-publishing.
- CVE-2025-46606HIGHCVSS 7.2EG 7.22026-04-17
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 contain an improper restriction of excessive authentication attempts vulnerability. A high privileged attacker with remote …
- CVE-2024-39917HIGHCVSS 7.2EG 7.22024-07-12
xrdp is an open source RDP server. xrdp versions prior to 0.10.0 have a vulnerability that allows attackers to make an infinite number of login attempts. The number of max login attempts is supposed to be limited by a configuration parame…
- CVE-2026-53904HIGHCVSS 7.1EG 7.12026-07-01
MCO is vulnerable to Account Denial of Service due to improper implementation of password reset functionality. Each password reset request invalidates previously set password as well as previously issued temporary passwords, furthermore, p…
- CVE-2025-46603HIGHCVSS 7.0EG 7.02025-12-05
Dell CloudBoost Virtual Appliance, versions 19.13.0.0 and prior, contains an Improper Restriction of Excessive Authentication Attempts vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerabili…
- CVE-2025-0417HIGHCVSS 7.0EG 7.02025-04-01
Lack of protection against brute force attacks in Valmet DNA visualization in DNA Operate. The possibility to make an arbitrary number of login attempts without any rate limit gives an attacker an increased chance of guessing passwords an…
- CVE-2026-105866MEDIUMCVSS 6.9EG 6.92026-10-06
Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, an unauthenticated attacker who knows an account email address or username can abuse the account lo…
- CVE-2026-84461MEDIUMCVSS 6.9EG 6.92026-09-25
Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, the two-factor login step let an attacker try unlimited password guesses for any account without triggering Zammad's normal lockout or rate limiting. The r…
- CVE-2026-13348MEDIUMCVSS 6.9EG 6.92026-09-01
CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow an attacker to gain unauthorized access to a user account by performing an arbitrary number of authentication attempts when redirect h…
- CVE-2026-8793MEDIUMCVSS 6.9EG 6.92026-08-03
PaperCut NG/MF does not properly restrict excessive authentication attempts within its login component. An unauthenticated remote attacker can exploit this vulnerability to perform unrestricted brute-force or credential-stuffing attacks wi…
- CVE-2026-35098MEDIUMCVSS 6.9EG 6.92026-06-30
KTM System e-BOK does not implement any limit or timeout on consecutive login attempts, allowing an attacker to perform unlimited authentication requests. This lack of rate‑limiting enables efficient brute‑force attacks against user ac…
- CVE-2026-55795MEDIUMCVSS 6.9EG 6.92026-06-19
Craft Commerce is an ecommerce platform for Craft CMS. From 4.0.0 until 4.11.2 and 5.6.5, CartController in src/controllers/CartController.php activates its RateLimiter only when the number POST or GET parameter is supplied. An unauthentic…
- CVE-2025-11566MEDIUMCVSS 6.9EG 6.92025-11-12
CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that would allow an attacker on the local network to gain access to the user account by performing an arbitrary number of authentication attempts with …
- CVE-2025-1714MEDIUMCVSS 6.9EG 6.92025-03-05
Lack of Rate Limiting in Sign-up workflow in Perforce Gliffy prior to version 4.14.0-7 on Gliffy online allows attacker to enumerate valid user emails and potentially DOS the server
- CVE-2026-107638MEDIUMCVSS 6.8EG 6.82026-10-08
pH7Builder (pH7 Social Dating CMS) before 18.5.0 contains an improper restriction of authentication attempts vulnerability that allows attackers to bypass two-factor authentication by guessing TOTP codes without limits. Attackers who know …
- CVE-2026-58271MEDIUMCVSS 6.8EG 6.82026-09-21
Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.4.0, `POST /api/app/sync/register` accepts credentials and a TOTP code to register a desktop sync client. On a failed TOTP,…
- CVE-2024-1345MEDIUMCVSS 6.8EG 6.82024-02-19
Weak MySQL database root password in LaborOfficeFree affects version 19.10. This vulnerability allows an attacker to perform a brute force attack and easily discover the root password.
- CVE-2021-44033MEDIUMCVSS 6.8EG 6.82021-11-19
In Ionic Identity Vault before 5.0.5, the protection mechanism for invalid unlock attempts can be bypassed.
- CVE-2020-27747MEDIUMCVSS 6.8EG 6.82020-10-29
An issue was discovered in Click Studios Passwordstate 8.9 (Build 8973).If the user of the system has assigned himself a PIN code for entering from a mobile device using the built-in generator (4 digits), a remote attacker has the opportun…
- CVE-2026-20512MEDIUMCVSS 6.7EG 6.72026-09-07
In Audio HAL, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for…
- CVE-2026-108580MEDIUMCVSS 6.5EG 6.52026-10-10
AniWorld Downloader before 5.3.0 contains an improper restriction of authentication attempts vulnerability in the WebUI /login POST handler that allows unauthenticated attackers to guess passwords without throttling. Attackers can enumerat…
- CVE-2026-108163MEDIUMCVSS 6.5EG 6.52026-10-10
Pingvin Share X before 1.22.0 contains an ineffective rate limiting vulnerability because throttler TTL values specified in seconds are interpreted as milliseconds. Unauthenticated attackers can send effectively unthrottled requests to /ap…
- CVE-2026-100678MEDIUMCVSS 6.5EG 6.52026-09-26
stoatchat before 0.15.5 fails to enforce account-level attempt limits on MFA login challenges, allowing attackers who know a password to guess TOTP codes with only IP-based rate limiting. Attackers can reuse MFA challenge tickets across mu…
- CVE-2026-100501MEDIUMCVSS 6.5EG 6.52026-09-25
Flame through 2.4.0 contains an improper restriction of excessive authentication attempts vulnerability in the POST /api/auth login endpoint that allows unauthenticated attackers to brute-force the admin password. Attackers can submit unli…
- CVE-2026-37603MEDIUMCVSS 6.5EG 6.52026-09-22
Improper Restriction of Excessive Authentication Attempts in the administration login of pH7Software pH7Builder (pH7 Social Dating CMS) through 19.2.0. The CAPTCHA escalation flag is stored in the PHP session as captcha_admin_enabled and t…
- CVE-2026-56592MEDIUMCVSS 6.5EG 6.52026-09-18
HCL BigFix Service Management is affected by an Improper Authentication validation vulnerability related to inadequate account lockouts, which could allow an unauthenticated attacker to execute sustained brute-force attacks against the log…
- CVE-2026-92583MEDIUMCVSS 6.5EG 6.52026-09-16
AVideo through 29.0 contains a race condition in the enforceRateLimit() function that fails to atomically increment rate limit counters, allowing attackers to bypass all rate limits including login brute-force protection by issuing concurr…
- CVE-2026-88770MEDIUMCVSS 6.5EG 6.52026-09-10
A flaw was found in the Device Authorization Grant flow of Keycloak, an identity and access management solution. The issue occurs because the token redemption process fails to check if a user account is currently locked due to brute-force …
Map vulnerabilities like CWE-307 to your infrastructure
EchelonGraph correlates every CVE — across CWE-307 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →