Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1310 CNY

100%

CWE-840 (业务逻辑错误) — Vulnerability Class 83

83 vulnerabilities classified as CWE-840 (业务逻辑错误). AI Chinese analysis included.

This page is a vulnerability aggregation resource dedicated to the weakness type identified as CWE-840, which involves making security decisions based on untrusted inputs. It serves as a centralized repository for data related to this specific category of software flaws, focusing on incidents where the integrity of input validation was compromised. The collection includes publicly disclosed security vulnerabilities affecting various vendors and products, spanning a comprehensive historical timeline from early discoveries to recent reports. By consolidating this information, the page provides a structured view of how CWE-840 manifests across different software ecosystems and implementation contexts. Readers can utilize this resource to track advisory publications from specific vendors, allowing them to monitor how organizations respond to and remediate these particular security issues. Furthermore, the aggregated data enables security professionals and researchers to understand the broader patterns and characteristics of the CWE-840 weakness class, identifying common mitigation strategies and recurring failure modes. Users can also look up the vulnerability history of specific products to assess their long-term security posture and exposure to untrusted input related flaws. This approach facilitates a deeper analysis of risk trends and helps in prioritizing remediation efforts based on empirical data rather than isolated incidents. The page aims to support informed decision-making by providing clear, accessible insights into the prevalence and impact of this critical weakness type without unnecessary noise or redundant information.

CVE IDTitleCVSSSeverityPublished
CVE-2025-24425 Adobe Commerce | Business Logic Errors (CWE-840) — Adobe Commerce 5.3 Medium2025-02-11
CVE-2024-56449 Huawei HarmonyOS 安全漏洞 — HarmonyOS 6.6 Medium2025-01-08
CVE-2024-54098 Huawei EMUI和Huawei HarmonyOS 安全漏洞 — HarmonyOS 8.5 High2024-12-12
CVE-2024-1682 Unclaimed S3 Bucket Reference in psf/requests Documentation — psf/requests 9.8 -2024-11-14
CVE-2024-51523 Huawei HarmonyOS 安全漏洞 — HarmonyOS 7.1 High2024-11-05
CVE-2018-25104 CoinGate Plugin Payment callback.php postProcess logic error — CoinGate Plugin 4.3 Medium2024-10-17
CVE-2024-6446 Business Logic Errors in GitLab — GitLab 3.5 Low2024-09-12
CVE-2024-42034 Huawei EMUI和Huawei HarmonyOS 安全漏洞 — HarmonyOS 6.6 Medium2024-08-08
CVE-2024-39671 Huawei EMUI和Huawei HarmonyOS 安全漏洞 — HarmonyOS 9.3 Critical2024-07-25
CVE-2023-7271 Huawei EMUI和Huawei HarmonyOS 安全漏洞 — HarmonyOS 5.5 Medium2024-07-25
CVE-2024-4046 Huawei HarmonyOS 安全漏洞 — HarmonyOS 6.4 Medium2024-05-11
CVE-2024-32999 Huawei HarmonyOS 安全漏洞 — HarmonyOS 6.8 Medium2024-05-11
CVE-2024-1456 S3 Bucket Takeover in h2oai/h2o-3 — h2oai/h2o-3 9.8 -2024-04-16
CVE-2024-2267 keerti1924 Online-Book-Store-Website shop.php logic error — Online-Book-Store-Website 4.3 Medium2024-03-07
CVE-2024-2151 SourceCodester Online Mobile Management Store Product Price logic error — Online Mobile Management Store 4.3 Medium2024-03-03
CVE-2023-6832 Business Logic Errors in microweber/microweber — microweber/microweber 5.3 -2023-12-15
CVE-2023-6566 Business Logic Errors in microweber/microweber — microweber/microweber 5.3 -2023-12-07
CVE-2023-6514 Huawei Smart Screen 授权问题漏洞 — AJMD-370S 8.8 High2023-12-06
CVE-2023-6017 H2O S3 Bucket Takeover — h2oai/h2o-3 9.3 -2023-11-16
CVE-2023-4304 Business Logic Errors in froxlor/froxlor — froxlor/froxlor 3.8 Low2023-08-11
CVE-2023-29294 Bypass Purchase Order Approval using Company User in Adobe Commerce B2B — Magento Commerce 4.3 Medium2023-06-15
CVE-2023-3228 Business Logic Errors in fossbilling/fossbilling — fossbilling/fossbilling 4.3 -2023-06-14
CVE-2023-3229 Business Logic Errors in fossbilling/fossbilling — fossbilling/fossbilling 4.3 -2023-06-14
CVE-2023-1887 Business Logic Errors in thorsten/phpmyfaq — thorsten/phpmyfaq 4.3 -2023-04-05
CVE-2023-1542 Business Logic Errors in answerdev/answer — answerdev/answer 7.1 -2023-03-21
CVE-2023-1541 Business Logic Errors in answerdev/answer — answerdev/answer 7.1 -2023-03-21
CVE-2023-0565 Business Logic Errors in froxlor/froxlor — froxlor/froxlor 5.5 Medium2023-01-29
CVE-2022-4719 Business Logic Errors in ikus060/rdiffweb — ikus060/rdiffweb 5.3 -2022-12-23
CVE-2022-3363 Business Logic Errors in ikus060/rdiffweb — ikus060/rdiffweb 5.3 -2022-10-26
CVE-2022-32208 curl 缓冲区错误漏洞 — https://github.com/curl/curl 5.9 -2022-07-07

Vulnerabilities classified as CWE-840 (业务逻辑错误) represent 83 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.