CWE-840
100 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-840page 2 of 2
- CVE-2023-7271MEDIUMCVSS 5.5EG 5.52024-07-25
Privilege escalation vulnerability in the NMS module Impact: Successful exploitation of this vulnerability will affect availability.
- CVE-2023-0565MEDIUMCVSS 5.5EG 5.52023-01-29
Business Logic Errors in GitHub repository froxlor/froxlor prior to 2.0.10.
- CVE-2026-82423MEDIUMCVSS 5.4EG 5.42026-08-29
A vulnerability has been found in macrozheng mall up to 1.0.3. The affected element is an unknown function of the file /order/paySuccess of the component Payment Status Endpoint. The manipulation of the argument orderId leads to enforcemen…
- CVE-2026-5812MEDIUMCVSS 5.4EG 5.42026-04-08
A security flaw has been discovered in SourceCodester Pharmacy Product Management System 1.0. This affects an unknown part of the file add-sales.php of the component POST Parameter Handler. Performing a manipulation of the argument txtqty …
- CVE-2026-5811MEDIUMCVSS 5.4EG 5.42026-04-08
A vulnerability was identified in SourceCodester Online Food Ordering System 1.0. Affected by this issue is the function save_product of the file /Actions.php of the component POST Parameter Handler. Such manipulation of the argument price…
- CVE-2023-1542MEDIUMCVSS 5.4EG 5.42023-03-21
Business Logic Errors in GitHub repository answerdev/answer prior to 1.0.6.
- CVE-2026-13571MEDIUMCVSS 5.3EG 5.32026-06-29
A flaw has been found in SourceCodester Simple Food Ordering System 1.0. The affected element is an unknown function of the file /cart.php. Executing a manipulation of the argument item_price can lead to business logic errors. The attack m…
- CVE-2024-45424MEDIUMCVSS 5.3EG 5.32025-02-25
Business logic error in some Zoom Workplace Apps may allow an unauthenticated user to conduct a disclosure of information via network access.
- CVE-2025-24425MEDIUMCVSS 5.3EG 5.32025-02-11
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a Business Logic Error vulnerability that could result in a security feature bypass. An attacker could exploit this vulnerability to …
- CVE-2022-1848MEDIUMCVSS 5.3EG 5.32022-05-24
Business Logic Errors in GitHub repository erudika/para prior to 1.45.11.
- CVE-2022-0689MEDIUMCVSS 5.3EG 5.32022-02-19
Use multiple time the one-time coupon in Packagist microweber/microweber prior to 1.2.11.
- CVE-2021-22897MEDIUMCVSS 5.3EG 5.32021-06-11
curl 7.61.0 through 7.76.1 suffers from exposure of data element to wrong session due to a mistake in the code for CURLOPT_SSL_CIPHER_LIST when libcurl is built to use the Schannel TLS library. The selected cipher set was stored in a singl…
- CVE-2020-8228MEDIUMCVSS 5.3EG 5.32020-10-05
A missing rate limit in the Preferred Providers app 1.7.0 allowed an attacker to set the password an uncontrolled amount of times.
- CVE-2026-1274MEDIUMCVSS 4.9EG 4.92026-04-23
IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to a Bypass Business Logic vulnerability in the access management control panel.
- CVE-2022-0688MEDIUMCVSS 4.9EG 4.92022-02-20
Business Logic Errors in Packagist microweber/microweber prior to 1.2.11.
- CVE-2026-28550MEDIUMCVSS 4.7EG 4.72026-03-05
Race condition vulnerability in the security control module. Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2025-4037MEDIUMCVSS 4.4EG 4.42025-04-28
A vulnerability was found in code-projects ATM Banking 1.0. It has been classified as critical. Affected is the function moneyDeposit/moneyWithdraw. The manipulation leads to business logic errors. Local access is required to approach this…
- CVE-2026-105573MEDIUMCVSS 4.3EG 4.32026-10-06
A vulnerability was found in newbee-ltd newbee-mall up to 2.7.5. This impacts an unknown function of the file /jshERP-boot/accountHead/updateAccountHeadAndDetail of the component Shopping Cart Quantity Handler. Performing a manipulation of…
- CVE-2026-82982MEDIUMCVSS 4.3EG 4.32026-09-18
The Approval app's approve/reject endpoint is meant to require the file's current etag as a freshness check, preventing an approver from approving or rejecting a file whose contents changed after they reviewed it. The backend only enforced…
- CVE-2026-79406MEDIUMCVSS 4.3EG 4.32026-08-25
A security vulnerability has been detected in macrozheng mall up to 1.0.3. Affected is the function OmsCartItemServiceImpl.updateQuantity of the file /cart/update/quantity. The manipulation of the argument quantity leads to business logic …
- CVE-2026-75081MEDIUMCVSS 4.3EG 4.32026-08-17
A vulnerability was detected in Webkul Bagisto up to 2.4.4. Impacted is an unknown function of the file /customer/account/rma/store. The manipulation of the argument rma_qty/resolution_type/rma_reason_id results in enforcement of behaviora…
- CVE-2026-19993MEDIUMCVSS 4.3EG 4.32026-08-17
A vulnerability has been found in Webkul Bagisto up to 2.4.4. Affected by this vulnerability is an unknown functionality of the file /customer/account/rma/update-status of the component RMA State Validation. The manipulation leads to enfor…
- CVE-2026-19213MEDIUMCVSS 4.3EG 4.32026-08-07
A vulnerability was identified in WonderTrader up to 0.9.9. Affected is the function _undone_qty in the library src/WtCore/TraderAdapter.h of the component Pending Order Handler. The manipulation of the argument getUndoneQty leads to enfor…
- CVE-2026-19037MEDIUMCVSS 4.3EG 4.32026-08-06
A weakness has been identified in WonderTrader up to 0.9.9. This vulnerability affects the function MatchEngine::update_lob of the file src/WtBtCore/MatchEngine.cpp of the component Internal Limit Order Book Cache Handler. This manipulatio…
- CVE-2026-4547MEDIUMCVSS 4.3EG 4.32026-03-22
A security vulnerability has been detected in mickasmt next-saas-stripe-starter 1.0.0. Affected is the function generateUserStripe of the file actions/generate-user-stripe.ts of the component Checkout Handler. The manipulation of the argum…
- CVE-2026-1600MEDIUMCVSS 4.3EG 4.32026-01-29
A vulnerability was identified in Bdtask Bhojon All-In-One Restaurant Management System up to 20260116. The impacted element is an unknown function of the file /hungry/addtocart of the component Add-to-Cart Submission Endpoint. The manipul…
- CVE-2026-1599MEDIUMCVSS 4.3EG 4.32026-01-29
A vulnerability was determined in Bdtask Bhojon All-In-One Restaurant Management System up to 20260116. The affected element is an unknown function of the file /hungry/placeorder of the component Checkout. Executing a manipulation of the a…
- CVE-2025-13239MEDIUMCVSS 4.3EG 4.32025-11-16
A security vulnerability has been detected in Bdtask/CodeCanyon Isshue Multi Store eCommerce Shopping Cart Solution 5. Affected by this issue is some unknown functionality of the file /submit_checkout. Such manipulation of the argument ord…
- CVE-2025-8991MEDIUMCVSS 4.3EG 4.32025-08-15
A vulnerability was identified in linlinjava litemall up to 1.8.0. Affected by this vulnerability is an unknown functionality of the file /admin/config/express of the component Business Logic Handler. The manipulation of the argument litem…
- CVE-2025-2323MEDIUMCVSS 4.3EG 4.32025-03-15
A vulnerability was found in 274056675 springboot-openai-chatgpt e84f6f5. It has been declared as problematic. This vulnerability affects the function updateQuestionCou of the file /api/mjkj-chat/chat/mng/update/questionCou of the componen…
- CVE-2024-1682MEDIUMCVSS 4.3EG 4.32024-11-14
An unclaimed Amazon S3 bucket, 'codeconf', is referenced in an audio file link within the .rst documentation file. This bucket has been claimed by an external party. The use of this unclaimed S3 bucket could lead to data integrity issues, …
- CVE-2018-25104MEDIUMCVSS 4.3EG 4.32024-10-17
A vulnerability was found in CoinGate Plugin up to 1.2.7 on PrestaShop. It has been rated as problematic. Affected by this issue is the function postProcess of the file modules/coingate/controllers/front/callback.php of the component Payme…
- CVE-2024-2267MEDIUMCVSS 4.3EG 4.32024-03-07
A vulnerability was found in keerti1924 Online-Book-Store-Website 1.0 and classified as problematic. This issue affects some unknown processing of the file /shop.php. The manipulation of the argument product_price leads to business logic e…
- CVE-2024-2151MEDIUMCVSS 4.3EG 4.32024-03-04
A vulnerability classified as problematic was found in SourceCodester Online Mobile Management Store 1.0. Affected by this vulnerability is an unknown functionality of the component Product Price Handler. The manipulation of the argument q…
- CVE-2023-6832MEDIUMCVSS 4.3EG 4.32023-12-15
Business Logic Errors in GitHub repository microweber/microweber prior to 2.0.
- CVE-2023-29294MEDIUMCVSS 4.3EG 4.32023-06-15
Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by a Business Logic Errors vulnerability that could result in a security feature bypass. A low-privileged attacker could leverage t…
- CVE-2023-1887MEDIUMCVSS 4.3EG 4.32023-04-05
Business Logic Errors in GitHub repository thorsten/phpmyfaq prior to 3.1.12.
- CVE-2022-0746MEDIUMCVSS 4.3EG 4.32022-02-25
Business Logic Errors in GitHub repository dolibarr/dolibarr prior to 16.0.
- CVE-2021-4146MEDIUMCVSS 4.3EG 4.32022-01-18
Business Logic Errors in GitHub repository pimcore/pimcore prior to 10.2.6.
- CVE-2021-4117MEDIUMCVSS 4.3EG 4.32021-12-15
yetiforcecrm is vulnerable to Business Logic Errors
- CVE-2020-8181MEDIUMCVSS 4.3EG 4.32020-07-10
A missing file type check in Nextcloud Contacts 3.2.0 allowed a malicious user to upload any file as avatars.
- CVE-2023-1541LOWCVSS 3.8EG 3.82023-03-21
Business Logic Errors in GitHub repository answerdev/answer prior to 1.0.6.
- CVE-2026-85030LOWCVSS 3.7EG 3.72026-09-03
A vulnerability has been found in HKUDS AI-Trader up to d03ff6c056b32ced735adf7c19ed8175adb1c8df. The affected element is an unknown function of the file service/server/routes_agent.py of the component selfRegister API Endpoint. Such manip…
- CVE-2026-19208LOWCVSS 3.7EG 3.72026-08-07
A vulnerability was detected in WonderTrader up to 0.9.9. Impacted is the function TraderDD::queryTrades of the file src/TraderDD/TraderDD.cpp. The manipulation of the argument FID_JYLB results in enforcement of behavioral workflow. The at…
- CVE-2025-10868LOWCVSS 3.5EG 3.52025-09-26
An issue has been discovered in GitLab CE/EE affecting all versions from 17.4 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 where certain string conversion methods exhibit performance degradation with large inputs.
- CVE-2024-6446LOWCVSS 3.5EG 3.52024-09-12
An issue has been discovered in GitLab affecting all versions starting from 17.1 to 17.1.7, 17.2 prior to 17.2.5 and 17.3 prior to 17.3.2. A crafted URL could be used to trick a victim to trust an attacker controlled application.
- CVE-2026-11465LOWCVSS 3.1EG 3.12026-06-07
A security flaw has been discovered in songquanpeng one-api up to 0.6.11-preview.7. Affected by this issue is the function Redeem of the file model/redemption.go of the component Redemption Code Top-Up Endpoint. The manipulation results in…
- CVE-2025-2938LOWCVSS 3.1EG 3.12025-06-26
An issue has been discovered in GitLab CE/EE affecting all versions from 17.3 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed authenticated users to gain elevated project privileges by requesting access t…
- CVE-2023-4304LOWCVSS 2.7EG 2.72023-08-11
Business Logic Errors in GitHub repository froxlor/froxlor prior to 2.0.22,2.1.0.
- CVE-2026-77166LOWCVSS 2.4EG 2.42026-09-21
The emoji field in the page emoji update endpoint does not properly validate user input. By injecting long text and line breaks, the sidebar layout becomes broken and can hide other items.
Map vulnerabilities like CWE-840 to your infrastructure
EchelonGraph correlates every CVE — across CWE-840 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →