CWE-841— Improper Enforcement of Behavioral Workflow
The product supports a session in which more than one behavior must be performed by an actor, but it does not properly ensure that the actor performs the behaviors in the required sequence.— MITRE CWE catalog
62 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-841page 1 of 2
- CVE-2022-1667HIGHCVSS 7.5EG 7.52022-06-24
Client-side JavaScript controls may be bypassed by directly running a JS function to reboot the PLC (e.g., from the browser console) or by loading the corresponding, browser accessible PHP script
- CVE-2022-2102CRITICALCVSS 9.4EG 9.42022-06-24
Controls limiting uploads to certain file extensions may be bypassed. This could allow an attacker to intercept the initial file upload page response and modify the associated code. This modified code can be forwarded and used by a script …
- CVE-2022-2105CRITICALCVSS 9.4EG 9.42022-06-24
Client-side JavaScript controls may be bypassed to change user credentials and permissions without authentication, including a “root” user level meant only for the vendor. Web server root level access allows for changing of safety crit…
- CVE-2022-46710MEDIUMCVSS 5.5EG 5.52024-01-10
A logic issue was addressed with improved checks. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1. Location data may be shared via iCloud links even if Location metadata is disabled via the Share Sheet.
- CVE-2023-1383MEDIUMCVSS 5.4EG 5.42023-05-03
An Improper Enforcement of Behavioral Workflow vulnerability in the exchangeDeviceServices function on the amzn.dmgr service allowed an attacker to register services that are only locally accessible. This issue affects: Amazon Fire TV St…
- CVE-2023-4181CRITICALCVSS 9.8EG 9.82023-08-06
A vulnerability, which was classified as critical, has been found in SourceCodester Free Hospital Management System for Small Practices 1.0. Affected by this issue is some unknown functionality of the file /vm/admin/delete-doctor.php?id=2 …
- CVE-2023-42939LOWCVSS 3.3EG 3.32024-02-21
A logic issue was addressed with improved checks. This issue is fixed in iOS 17.1 and iPadOS 17.1. A user's private browsing activity may be unexpectedly saved in the App Privacy Report.
- CVE-2023-5921HIGHCVSS 7.1EG 7.12023-11-22
Improper Enforcement of Behavioral Workflow vulnerability in DECE Software Geodi allows Functionality Bypass. This issue affects Geodi: before 8.0.0.27396.
- CVE-2024-0410HIGHCVSS 7.7EG 7.72024-02-22
An authorization bypass vulnerability was discovered in GitLab affecting versions 15.1 prior to 16.7.6, 16.8 prior to 16.8.3, and 16.9 prior to 16.9.1. A developer could bypass CODEOWNERS approvals by creating a merge conflict.
- CVE-2024-12543MEDIUMCVSS 5.9EG 5.92025-04-21
User Enumeration and Data Integrity in Barcode functionality in OpenText Content Management versions 24.3-25.1on Windows and Linux allows a malicous authenticated attacker to potentially alter barcode attributes.
- CVE-2024-13065MEDIUMCVSS 6.3EG 6.32025-09-03
Improper Enforcement of Behavioral Workflow, Uncontrolled Resource Consumption vulnerability in Akinsoft MyRezzta allows Input Data Manipulation, CAPEC - 125 - Flooding. This issue affects MyRezzta: from s2.02.02 before v2.05.01.
- CVE-2024-37296MEDIUMCVSS 5.3EG 5.32024-06-11
The Aimeos HTML client provides Aimeos HTML components for e-commerce projects. Starting in version 2020.04.1 and prior to versions 2020.10.27, 2021.10.21, 2022.10.12, 2023.10.14, and 2024.04.5, digital downloads sold in online shops can b…
- CVE-2024-39325MEDIUMCVSS 5.3EG 5.32024-07-02
aimeos/ai-controller-frontend is the Aimeos frontend controller. Prior to versions 2024.04.2, 2023.10.9, 2022.10.8, 2021.10.8, and 2020.10.15, aimeos/ai-controller-frontend doesn't reset the payment status of a user's basket after the use…
- CVE-2024-44128MEDIUMCVSS 5.5EG 5.52024-09-17
This issue was addressed by adding an additional prompt for user consent. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura 13.7. An Automator Quick Action workflow may be able to bypass Gatekeeper.
- CVE-2024-46307HIGHCVSS 7.5EG 7.52024-10-09
A loop hole in the payment logic of Sparkshop v1.16 allows attackers to arbitrarily modify the number of products.
- CVE-2024-51738HIGHCVSS 8.1EG 8.12025-01-20
Sunshine is a self-hosted game stream host for Moonlight. In 0.23.1 and earlier, Sunshine's pairing protocol implementation does not validate request order and is thereby vulnerable to a MITM attack, potentially allowing an unauthenticated…
- CVE-2024-6128MEDIUMCVSS 5.3EG 5.32024-06-18
A vulnerability, which was classified as problematic, has been found in spa-cartcms 1.9.0.6. This issue affects some unknown processing of the file /checkout of the component Checkout Page. The manipulation of the argument quantity with th…
- CVE-2025-13129MEDIUMCVSS 4.3EG 4.32025-12-01
Improper Enforcement of Behavioral Workflow vulnerability in Seneka Software Hardware Information Technology Trade Contracting and Industry Ltd. Co. Onaylarım allows Functionality Misuse. This issue affects Onaylarım: from 25.09.26.01 t…
- CVE-2025-13239MEDIUMCVSS 4.3EG 4.32025-11-16
A security vulnerability has been detected in Bdtask/CodeCanyon Isshue Multi Store eCommerce Shopping Cart Solution 5. Affected by this issue is some unknown functionality of the file /submit_checkout. Such manipulation of the argument ord…
- CVE-2025-13459MEDIUMCVSS 4.9EG 4.92026-03-16
IBM Aspera Console 3.3.0 through 3.4.8 could allow a privileged user to cause a denial of service due to improper enforcement of behavioral workflow.
- CVE-2025-13751MEDIUMCVSS 5.5EG 5.52025-12-03
Interactive service agent in OpenVPN version 2.5.0 through 2.6.16 and 2.7_alpha1 through 2.7_rc2 on Windows allows a local authenticated user to connect to the service and trigger an error causing a local denial of service.
- CVE-2025-2323MEDIUMCVSS 4.3EG 4.32025-03-15
A vulnerability was found in 274056675 springboot-openai-chatgpt e84f6f5. It has been declared as problematic. This vulnerability affects the function updateQuestionCou of the file /api/mjkj-chat/chat/mng/update/questionCou of the componen…
- CVE-2025-36333MEDIUMCVSS 4.3EG 4.32026-06-30
IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 could allow an authenticated user to perform unauthorized actions due to the improper enforcement of behavioral workflow.
- CVE-2025-48376LOWCVSS 3.5EG 3.52025-05-23
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 9.13.9, a malicious SuperUser (Host) could craft a request to use an external url for a site export to then be i…
- CVE-2025-48476HIGHCVSS 8.8EG 8.82025-05-30
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, when adding and editing user records using the fill() method, there is no check for the absence of the password field in the data coming from the user,…
- CVE-2025-48477HIGHCVSS 8.1EG 8.12025-05-30
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the application's logic requires the user to perform a correct sequence of actions to implement a functional capability, but the application allows acc…
- CVE-2025-48478MEDIUMCVSS 4.9EG 4.92025-05-30
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, insufficient input validation during user creation has resulted in a mass assignment vulnerability, allowing an attacker to manipulate all fields of th…
- CVE-2025-48479LOWCVSS 2.7EG 2.72025-05-30
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the laravel-translation-manager package does not correctly validate user input, enabling the deletion of any directory, given sufficient access rights.…
- CVE-2025-48480LOWCVSS 2.7EG 2.72025-05-30
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, an authorized user with the administrator role or with the privilege User::PERM_EDIT_USERS can create a user, specifying the path to the user's avatar …
- CVE-2025-48481CRITICALCVSS 9.8EG 9.82025-05-30
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, an attacker with an unactivated email invitation containing invite_hash, can exploit this vulnerability to self-activate their account, despite it bein…
- CVE-2025-48482MEDIUMCVSS 4.3EG 4.32025-05-30
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, there is a mass assignment vulnerability. The Customer object is updated using the fill() method, which processes fields such as channel and channel_id…
- CVE-2025-52469HIGHCVSS 7.1EG 7.12026-03-02
Chamilo is a learning management system. Prior to version 1.11.30, a logic vulnerability in the friend request workflow of Chamilo’s social network module allows an authenticated user to forcibly add any user as a friend by directly call…
- CVE-2025-55330MEDIUMCVSS 6.1EG 6.12025-10-14
Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
- CVE-2025-55332MEDIUMCVSS 6.1EG 6.12025-10-14
Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
- CVE-2025-55337MEDIUMCVSS 6.1EG 6.12025-10-14
Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
- CVE-2025-55682MEDIUMCVSS 6.1EG 6.12025-10-14
Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
- CVE-2025-58051MEDIUMCVSS 6.5EG 6.52025-10-16
Nextcloud Tables allows you to create your own tables with individual columns. Prior 0.7.6, 0.8.8, and 0.9.5, when importing a table, a user was able to specify files on the server and when their format is supported by the used PhpSpreadsh…
- CVE-2026-13222MEDIUMCVSS 6.3EG 6.32026-06-25
Our payment integration with Oppwa-based payment methods did not properly validate payment status responses. An attacker could use a successful payment status response from one payment and supply it to the system for a different payment…
- CVE-2026-13223MEDIUMCVSS 6.3EG 6.32026-06-25
Our payment integration with Computop-based payment methods did not properly validate payment status responses. An attacker could use a successful payment status response from one payment and supply it to the system for a different paym…
- CVE-2026-16103MEDIUMCVSS 4.3EG 4.32026-07-17
A flaw was found in the keycloak-services component of Keycloak. This issue is an incomplete fix for CVE-2026-9798, where brute-force protection checks were added to the Client-Initiated Backchannel Authentication (CIBA) initiation handler…
- CVE-2026-18029MEDIUMCVSS 6.3EG 6.32026-07-28
Our payment integration with GiroCheckout did not properly validate payment status responses. An attacker could use a successful payment status response from one payment and supply it to the system for a different payment, gaining acces…
- CVE-2026-19037MEDIUMCVSS 4.3EG 4.32026-08-06
A weakness has been identified in WonderTrader up to 0.9.9. This vulnerability affects the function MatchEngine::update_lob of the file src/WtBtCore/MatchEngine.cpp of the component Internal Limit Order Book Cache Handler. This manipulatio…
- CVE-2026-19208LOWCVSS 3.7EG 3.72026-08-07
A vulnerability was detected in WonderTrader up to 0.9.9. Impacted is the function TraderDD::queryTrades of the file src/TraderDD/TraderDD.cpp. The manipulation of the argument FID_JYLB results in enforcement of behavioral workflow. The at…
- CVE-2026-19213MEDIUMCVSS 4.3EG 4.32026-08-07
A vulnerability was identified in WonderTrader up to 0.9.9. Affected is the function _undone_qty in the library src/WtCore/TraderAdapter.h of the component Pending Order Handler. The manipulation of the argument getUndoneQty leads to enfor…
- CVE-2026-19993MEDIUMCVSS 4.3EG 4.32026-08-17
A vulnerability has been found in Webkul Bagisto up to 2.4.4. Affected by this vulnerability is an unknown functionality of the file /customer/account/rma/update-status of the component RMA State Validation. The manipulation leads to enfor…
- CVE-2026-24774MEDIUMCVSS 4.3EG 4.32026-02-03
The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, a business logic vulnerability allows authenticated students to improperly mark themselves as present in attendance act…
- CVE-2026-30574HIGHCVSS 7.5EG 7.52026-03-27
A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0 in the add-sales.php file. The application fails to verify if the requested sales quantity (txtqty) exceeds the available stock level. An attack…
- CVE-2026-30783CRITICALCVSS 9.8EG 9.82026-03-05
A vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android, WebClient (Client signaling, API sync loop, config management modules) allows Privilege Abuse. This vulnerability is associated wi…
- CVE-2026-3130CRITICALCVSS 9.8EG 9.82026-03-03
Improper Enforcement of Behavioral Controls in Devolutions Server 2025.3.15 and earlier allows an authenticated attacker with the delete permission to delete a PAM account that is currently checked out by selecting it alongside at least o…
- CVE-2026-34582CRITICALCVSS 9.1EG 9.12026-04-07
Botan is a C++ cryptography library. Prior to version 3.11.1, the TLS 1.3 implementation allowed ApplicationData records to be processed prior to the Finished message being received. A server which is attempting to enforce client authentic…
Map vulnerabilities like CWE-841 to your infrastructure
EchelonGraph correlates every CVE — across CWE-841 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →