CWE-837: Improper Enforcement of a Single, Unique Action
The product requires that an actor should only be able to perform an action once, or to have only one unique action, but the product does not enforce or improperly enforces this restriction.
18 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-54315 — The Matrix specification before 1.16 (i.e., with a room version before 12) lacks create event uniqueness.
- CVE-2026-42609 — Grav: Administrative Account Disruption and Privilege De-escalation via User Overwrite Logic
- CVE-2024-4629 — Keycloak: potential bypass of brute force protection
- CVE-2025-62782 — InventoryGUI vulnerable to item duplication via Bundle items when using GuiStorageElement
- CVE-2025-62784 — InventoryGui allows item duplication in GUIs which use GuiStorageElement
- CVE-2025-58135 — Zoom Workplace Clients for Windows - Improper Action Enforcement
- CVE-2024-12123 — Unauthorized Modification of Ticket Requester
- CVE-2025-62783 — InventoryGui affected by item duplication in GUIs which use GuiStorageElement
- CVE-2026-45734 — MyBB: Default CAPTCHA missing invalidation
- CVE-2026-44601 — Tor before 0.4.9.7, when circuit queue memory pressure exists, can experience a client crash because of a double close o
- CVE-2026-86198 — PocketMine-MP before 5.44.2 Denial of Service via ResourcePackClientResponsePacket
Recently published
- CVE-2026-86198 — PocketMine-MP before 5.44.2 Denial of Service via ResourcePackClientResponsePacket
- CVE-2026-45734 — MyBB: Default CAPTCHA missing invalidation
- CVE-2026-42609 — Grav: Administrative Account Disruption and Privilege De-escalation via User Overwrite Logic
- CVE-2026-44601 — Tor before 0.4.9.7, when circuit queue memory pressure exists, can experience a client crash because of a double close o
- CVE-2025-62784 — InventoryGui allows item duplication in GUIs which use GuiStorageElement
- CVE-2025-62783 — InventoryGui affected by item duplication in GUIs which use GuiStorageElement
- CVE-2025-62782 — InventoryGUI vulnerable to item duplication via Bundle items when using GuiStorageElement
- CVE-2025-54315 — The Matrix specification before 1.16 (i.e., with a room version before 12) lacks create event uniqueness.
- CVE-2025-58135 — Zoom Workplace Clients for Windows - Improper Action Enforcement
- CVE-2024-12123 — Unauthorized Modification of Ticket Requester
- CVE-2024-4629 — Keycloak: potential bypass of brute force protection