VYPR

CWE-841

Improper Enforcement of Behavioral Workflow

ClassIncomplete

Description

The product supports a session in which more than one behavior must be performed by an actor, but it does not properly ensure that the actor performs the behaviors in the required sequence.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (62)

page 3 of 4
  • CVE-2026-16103MedJul 17, 2026
    risk 0.28cvss 4.3epss 0.00

    A flaw was found in the keycloak-services component of Keycloak. This issue is an incomplete fix for CVE-2026-9798, where brute-force protection checks were added to the Client-Initiated Backchannel Authentication (CIBA) initiation handler but were omitted from the token…

  • CVE-2026-24774MedFeb 3, 2026
    risk 0.28cvss 4.3epss 0.00

    The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, a business logic vulnerability allows authenticated students to improperly mark themselves as present in attendance activities, including activities that have…

  • CVE-2025-13129MedDec 1, 2025
    risk 0.28cvss 4.3epss 0.00

    Improper Enforcement of Behavioral Workflow vulnerability in Seneka Software Hardware Information Technology Trade Contracting and Industry Ltd. Co. Onaylarım allows Functionality Misuse. This issue affects Onaylarım: from 25.09.26.01 through 18112025.

  • CVE-2025-13239MedNov 16, 2025
    risk 0.28cvss 4.3epss 0.00

    A security vulnerability has been detected in Bdtask/CodeCanyon Isshue Multi Store eCommerce Shopping Cart Solution 5. Affected by this issue is some unknown functionality of the file /submit_checkout. Such manipulation of the argument order_total_amount/cart_total_amount leads…

  • CVE-2025-48482MedMay 30, 2025
    risk 0.28cvss 4.3epss 0.00

    FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, there is a mass assignment vulnerability. The Customer object is updated using the fill() method, which processes fields such as channel and channel_id. However, the fill() method is called…

  • CVE-2025-2323MedMar 15, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in 274056675 springboot-openai-chatgpt e84f6f5. It has been declared as problematic. This vulnerability affects the function updateQuestionCou of the file /api/mjkj-chat/chat/mng/update/questionCou of the component Number of Question Handler. The…

  • CVE-2024-39325MedJul 2, 2024
    risk 0.27cvss 5.3epss 0.00

    aimeos/ai-controller-frontend is the Aimeos frontend controller. Prior to versions 2024.04.2, 2023.10.9, 2022.10.8, 2021.10.8, and 2020.10.15, aimeos/ai-controller-frontend doesn't reset the payment status of a user's basket after the user completes a purchase. Versions…

  • CVE-2024-37296MedJun 11, 2024
    risk 0.27cvss 5.3epss 0.01

    The Aimeos HTML client provides Aimeos HTML components for e-commerce projects. Starting in version 2020.04.1 and prior to versions 2020.10.27, 2021.10.21, 2022.10.12, 2023.10.14, and 2024.04.5, digital downloads sold in online shops can be downloaded without valid payment, e.g.…

  • CVE-2026-53637medJul 9, 2026
    risk 0.26cvss epss

    ### Impact A user opens the cart page in the browser. In the background, the order gets completed, e.g. an admin changes the status, or the user finalizes payment in another tab. The browser still displays the old cart: the LiveComponent is unaware the underlying order state has…

  • CVE-2026-19208LowAug 7, 2026
    risk 0.24cvss 3.7epss 0.00

    A vulnerability was detected in WonderTrader up to 0.9.9. Impacted is the function TraderDD::queryTrades of the file src/TraderDD/TraderDD.cpp. The manipulation of the argument FID_JYLB results in enforcement of behavioral workflow. The attack can be launched remotely. A high…

  • CVE-2023-42939LowFeb 21, 2024
    risk 0.21cvss 3.3epss 0.00

    A logic issue was addressed with improved checks. This issue is fixed in iOS 17.1 and iPadOS 17.1. A user's private browsing activity may be unexpectedly saved in the App Privacy Report.

  • CVE-2026-8477LowMay 22, 2026
    risk 0.18cvss 2.7epss 0.00

    Improper enforcement of the sealed-entry workflow in the entry sensitive-data retrieval feature in Devolutions Server allows an authenticated user with access to a sealed entry to retrieve its sensitive data without triggering the unseal audit notification via a crafted API…

  • CVE-2025-13459LowMar 16, 2026
    risk 0.18cvss 2.7epss 0.00

    IBM Aspera Console 3.3.0 through 3.4.8 could allow a privileged user to cause a denial of service due to improper enforcement of behavioral workflow.

  • CVE-2025-48480LowMay 30, 2025
    risk 0.18cvss 2.7epss 0.00

    FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, an authorized user with the administrator role or with the privilege User::PERM_EDIT_USERS can create a user, specifying the path to the user's avatar ../.htaccess during creation, and then…

  • CVE-2025-48479LowMay 30, 2025
    risk 0.18cvss 2.7epss 0.00

    FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the laravel-translation-manager package does not correctly validate user input, enabling the deletion of any directory, given sufficient access rights. This issue has been patched in version…

  • CVE-2025-48376LowMay 23, 2025
    risk 0.16cvss 3.5epss 0.00

    DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 9.13.9, a malicious SuperUser (Host) could craft a request to use an external url for a site export to then be imported. Version 9.13.9 fixes the issue.

  • CVE-2026-18029MedJul 28, 2026
    risk 0.00cvss epss 0.00

    Our payment integration with GiroCheckout did not properly validate payment status responses. An attacker could use a successful payment status response from one payment and supply it to the system for a different payment, gaining access to multiple valid tickets with only …

  • CVE-2025-36333MedJun 30, 2026
    risk 0.00cvss 4.3epss 0.00

    IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 could allow an authenticated user to perform unauthorized actions due to the improper enforcement of behavioral workflow.

  • CVE-2026-57536MedJun 25, 2026
    risk 0.00cvss epss 0.00

    Our payment integration with Mollie did not properly validate payment status responses. An attacker could use a successful payment status response from one payment and supply it to the system for a different payment, gaining access to multiple valid tickets with only one…

  • CVE-2025-52469HigMar 2, 2026
    risk 0.00cvss 7.1epss 0.00

    Chamilo is a learning management system. Prior to version 1.11.30, a logic vulnerability in the friend request workflow of Chamilo’s social network module allows an authenticated user to forcibly add any user as a friend by directly calling the AJAX endpoint. The attacker can…