CWE-799: Improper Control of Interaction Frequency
The product does not properly limit the number or frequency of interactions that it has with an actor, such as the number of incoming requests.
74 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2024-32943 — Westermo L210-F2G Lynx Improper Control of Interaction Frequency
- CVE-2025-29998 — No Rate Limiting Vulnerability in CAP back office application
- CVE-2026-32729 — Runtipi has a TOTP two-factor authentication bypass via unrestricted brute-force on `/api/auth/verify-totp`
- CVE-2026-24017 — An Improper Control of Interaction Frequency vulnerability [CWE-799] vulnerability in Fortinet FortiWeb 8.0.0 through 8.
- CVE-2024-51557 — No Rate Limiting Vulnerability in Wave 2.0
- CVE-2024-47654 — No Rate Limiting vulnerability
- CVE-2026-30972 — Parse Server has a rate limit bypass via batch request endpoint
- CVE-2026-22216 — wpDiscuz before 7.6.47 - No Rate Limiting on Subscription Endpoints with LIKE Wildcard Bypass
- CVE-2025-32378 — Shopware's default newsletter opt-in settings allow for mass sign-up abuse
- CVE-2025-12310 — VirtFusion Email Change _settings excessive authentication
- CVE-2026-7402 — Improper Rate Limiting in MeWare Software's PDKS
- CVE-2026-2110 — Tasin1025 SwiftBuy login.php excessive authentication
- CVE-2026-1685 — D-Link DIR-823X Login sub_40AC74 excessive authentication
- CVE-2025-9004 — mtons mblog password excessive authentication
- CVE-2025-8927 — mtons mblog Verification Code send_code excessive authentication
- CVE-2025-8742 — macrozheng mall Admin Login excessive authentication
- CVE-2025-5864 — Tenda TDSEE App Password Reset Confirmation Code ConfirmSmsCode excessive authentication
- CVE-2025-57816 — Fides Webserver API Rate Limiting Vulnerability in Proxied Environments
- CVE-2025-3556 — ScriptAndTools eCommerce-website-in-PHP login.php excessive authentication
- CVE-2025-3555 — ScriptAndTools eCommerce-website-in-PHP login.php excessive authentication
Recently published
- CVE-2026-85586 — phpMyFAQ before 4.1.8 CAPTCHA Bypass via store parameter
- CVE-2026-54738 — Lemmy: Rate limit bypass via X-Forwarded-For header spoofing in actix-web ConnectionInfo
- CVE-2026-75773 — karakeep-app karakeep Login Endpoint auth.ts authorize excessive authentication
- CVE-2026-19898 — VictoriaMetrics VMAuth Authentication Endpoint main.go requestHandler excessive authentication
- CVE-2026-19897 — mangroup dtale Login Endpoint auth.py login excessive authentication
- CVE-2026-19895 — opensourcepos Open Source Point of Sale Login Endpoint Filters.php index excessive authentication
- CVE-2024-23565 — HCL Aftermarket EPC is vulnerable to email flooding as the application does not have a proper mail limitation mechanism
- CVE-2026-33434 — Wazuh: Rate Limit Bypass via /events Endpoint
- CVE-2026-5233 — Missing Rate Limiting in Mia Technologies' Pizzy Library
- CVE-2026-10216 — unitedbyai droidclaw claim Endpoint pairing.ts excessive authentication
- CVE-2026-7671 — CodeWise Tornet Scooter Mobile App TwoFactor excessive authentication
- CVE-2026-7402 — Improper Rate Limiting in MeWare Software's PDKS
- CVE-2026-41346 — OpenClaw 2026.2.26 < 2026.3.31 - Denial of Service via Improper Pending Pairing Request Cap Enforcement
- CVE-2026-41343 — OpenClaw < 2026.3.31 - Denial of Service via LINE Webhook Handler Pre-Auth Concurrency
- CVE-2026-41333 — OpenClaw < 2026.3.31 - Authentication Rate Limiting Bypass via Fake DeviceToken
- CVE-2025-55268 — HCL Aftermarket DPC is affected by Spamming Vulnerability
- CVE-2026-32729 — Runtipi has a TOTP two-factor authentication bypass via unrestricted brute-force on `/api/auth/verify-totp`
- CVE-2025-13212 — IBM Aspera Console Denial of Service
- CVE-2026-22216 — wpDiscuz before 7.6.47 - No Rate Limiting on Subscription Endpoints with LIKE Wildcard Bypass
- CVE-2026-30972 — Parse Server has a rate limit bypass via batch request endpoint
More specific weaknesses
- CWE-837 — Improper Enforcement of a Single, Unique Action