CWE-1021— Improper Restriction of Rendered UI Layers or Frames (Clickjacking)
The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain.— MITRE CWE catalog
424 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-1021page 1 of 9
- CVE-2021-43048CRITICALCVSS 9.8EG 9.82021-11-16
The Interior Server and Gateway Server components of TIBCO Software Inc.'s TIBCO PartnerExpress contain a vulnerability that theoretically allows an unauthenticated attacker with network access to execute a clickjacking attack on the affec…
- CVE-2021-23274CRITICALCVSS 9.8EG 9.82021-03-23
The Config UI component of TIBCO Software Inc.'s TIBCO API Exchange Gateway and TIBCO API Exchange Gateway Distribution for TIBCO Silver Fabric contains a vulnerability that theoretically allows an unauthenticated attacker with network acc…
- CVE-2016-2496CRITICALCVSS 9.8EG 9.82016-06-13
The Framework UI permission-dialog implementation in Android 6.x before 2016-06-01 allows attackers to conduct tapjacking attacks and access arbitrary private-storage files by creating a partially overlapping window, aka internal bug 26677…
- CVE-2026-84388CRITICALCVSS 9.6EG 9.62026-09-22
A improper restriction of rendered ui layers or frames vulnerability in Fortinet FortiPAM Chrome Extension 8.0 all versions, FortiPAM Chrome Extension 7.4 all versions may allow attacker to information disclosure via remote unauthenticated…
- CVE-2023-41897CRITICALCVSS 9.6EG 9.62023-10-19
Home assistant is an open source home automation. Home Assistant server does not set any HTTP security headers, including the X-Frame-Options header, which specifies whether the web page is allowed to be framed. The omission of this and co…
- CVE-2021-21132CRITICALCVSS 9.6EG 9.62021-02-09
Inappropriate implementation in DevTools in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially perform a sandbox escape via a crafted Chrome Extension.
- CVE-2021-21111CRITICALCVSS 9.6EG 9.62021-01-08
Insufficient policy enforcement in WebUI in Google Chrome prior to 87.0.4280.141 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.
- CVE-2024-10004CRITICALCVSS 9.1EG 9.12024-10-15
Opening an external link to an HTTP website when Firefox iOS was previously closed and had an HTTPS tab open could in some cases result in the padlock icon showing an HTTPS indicator incorrectly This vulnerability affects Firefox for iOS <…
- CVE-2022-3167HIGHCVSS 8.8EG 8.82022-09-08
Improper Restriction of Rendered UI Layers or Frames in GitHub repository ikus060/rdiffweb prior to 2.4.1.
- CVE-2021-3734HIGHCVSS 8.8EG 8.82021-08-26
yourls is vulnerable to Improper Restriction of Rendered UI Layers or Frames
- CVE-2021-22866HIGHCVSS 8.8EG 8.82021-05-14
A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed more permissions to be granted during a GitHub App's user-authorization web flow than was displayed to the user during approval. To exploit this v…
- CVE-2015-5686HIGHCVSS 8.8EG 8.82020-02-27
Parts of the Puppet Enterprise Console 3.x were found to be susceptible to clickjacking and CSRF (Cross-Site Request Forgery) attacks. This would allow an attacker to redirect user input to an untrusted site or hijack a user session.
- CVE-2018-18496HIGHCVSS 8.8EG 8.82019-02-28
When the RSS Feed preview about:feeds page is framed within another page, it can be used in concert with scripted content for a clickjacking attack that confuses users into downloading and executing an executable file from a temporary dire…
- CVE-2026-87995HIGHCVSS 8.7EG 8.72026-09-09
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.11 until 0.11.1, src/lib/components/chat/FileNav/PortPreview.svelte rendered terminal port content in an iframe sandbox containing both allow-sc…
- CVE-2026-0007HIGHCVSS 8.6EG 8.62026-03-02
In writeToParcel of WindowInfo.cpp, there is a possible way to trick a user into accepting a permission due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. Us…
- CVE-2026-22918HIGHCVSS 8.2EG 8.22026-01-15
An attacker may exploit missing protection against clickjacking by tricking users into performing unintended actions through maliciously crafted web pages, leading to the extraction of sensitive data.
- CVE-2021-44683HIGHCVSS 8.2EG 8.22022-03-25
The DuckDuckGo browser 7.64.4 on iOS allows Address Bar Spoofing due to mishandling of the JavaScript window.open function (used to open a secondary browser window). This could be exploited by tricking users into supplying sensitive inform…
- CVE-2019-16371HIGHCVSS 8.2EG 8.22019-09-16
LogMeIn LastPass before 4.33.0 allows attackers to construct a crafted web site that captures the credentials for a victim's account on a previously visited web site, because do_popupregister can be bypassed via clickjacking.
- CVE-2026-74978HIGHCVSS 8.1EG 8.12026-08-18
Clickjacking issue in the Widget component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
- CVE-2026-58595HIGHCVSS 8.1EG 8.12026-07-14
Improper restriction of rendered ui layers or frames in Microsoft Bing App for IOS allows an unauthorized attacker to perform spoofing over a network.
- CVE-2024-11700HIGHCVSS 8.1EG 8.12024-11-26
Malicious websites may have been able to perform user intent confirmation through tapjacking. This could have led to users unknowingly approving the launch of external applications, potentially exposing them to underlying vulnerabilities. …
- CVE-2024-7523HIGHCVSS 8.1EG 8.12024-08-06
A select option could partially obscure security prompts. This could be used by a malicious site to trick a user into granting permissions. *This issue only affects Android versions of Firefox.* This vulnerability affects Firefox < 129.
- CVE-2024-33377HIGHCVSS 8.1EG 8.12024-06-14
LB-LINK BL-W1210M v2.0 was discovered to contain a clickjacking vulnerability via the Administrator login page. Attackers can cause victim users to perform arbitrary operations via interaction with crafted elements on the web page.
- CVE-2021-23976HIGHCVSS 8.1EG 8.12021-02-26
When accepting a malicious intent from other installed apps, Firefox for Android accepted manifests from arbitrary file paths and allowed declaring webapp manifests for other origins. This could be used to gain fullscreen access for UI spo…
- CVE-2020-13119HIGHCVSS 8.1EG 8.12020-09-24
ismartgate PRO 1.5.9 is vulnerable to clickjacking.
- CVE-2020-7705HIGHCVSS 7.1EG 8.12020-08-24
This affects the package MintegralAdSDK from 0.0.0. The SDK distributed by the company contains malicious functionality that tracks any URL opened by the app and reports it back to the company, along with performing advertisement attributi…
- CVE-2021-0433HIGHCVSS 8.0EG 8.02021-04-13
In onCreate of DeviceChooserActivity.java, there is a possible way to bypass user consent when pairing a Bluetooth device due to a tapjacking/overlay attack. This could lead to local escalation of privilege and pairing malicious devices wi…
- CVE-2026-43688HIGHCVSS 7.8EG 7.82026-09-14
A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27. Processing a maliciously crafted file may lead to unexpected app termination.
- CVE-2026-28577HIGHCVSS 7.8EG 7.82026-06-01
In addWindow of WindowManagerService.java, there is a possible tapjacking issue due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not ne…
- CVE-2026-0036HIGHCVSS 7.8EG 7.82026-06-01
In startAnimation of StageCoordinator.java, there is a possible tapjacking issue due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not n…
- CVE-2025-48597HIGHCVSS 7.8EG 7.82025-12-08
In multiple locations, there is a possible way to trick a user into accepting a permission due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interactio…
- CVE-2025-32350HIGHCVSS 7.8EG 7.82025-09-04
In maybeShowDialog of ControlsSettingsDialogManager.kt, there is a possible overlay of the ControlsSettingsDialog due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges …
- CVE-2025-32349HIGHCVSS 7.8EG 7.82025-09-04
In multiple locations, there is a possible privilege escalation due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploit…
- CVE-2024-43765HIGHCVSS 7.8EG 7.82025-01-21
In multiple locations, there is a possible way to obtain access to a folder due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploita…
- CVE-2024-34743HIGHCVSS 7.8EG 7.82024-08-15
In setTransactionState of SurfaceFlinger.cpp, there is a possible way to perform tapjacking due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction…
- CVE-2024-31323HIGHCVSS 7.8EG 7.82024-07-09
In onCreate of multiple files, there is a possible way to trick the user into granting health permissions due to tapjacking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction …
- CVE-2022-20443HIGHCVSS 7.8EG 7.82023-06-28
In hasInputInfo of Layer.cpp, there is a possible bypass of user interaction requirements due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction…
- CVE-2023-20913HIGHCVSS 7.8EG 7.82023-01-26
In onCreate of PhoneAccountSettingsActivity.java and related files, there is a possible way to mislead the user into enabling a malicious phone account due to a tapjacking/overlay attack. This could lead to local escalation of privilege wi…
- CVE-2022-20520HIGHCVSS 7.8EG 7.82022-12-16
In onCreate of various files, there is a possible tapjacking/overlay attack. This could lead to local escalation of privilege or denial of server with User execution privileges needed. User interaction is not needed for exploitation.Produc…
- CVE-2022-20331HIGHCVSS 7.8EG 7.82022-08-12
In the Framework, there is a possible way to enable a work profile without user consent due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction i…
- CVE-2022-20212HIGHCVSS 7.8EG 7.82022-07-13
In wifi.RequestToggleWifiActivity of AndroidManifest.xml, there is a possible EoP due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is need…
- CVE-2021-39702HIGHCVSS 7.8EG 7.82022-03-16
In onCreate of RequestManageCredentials.java, there is a possible way for a third party app to install certificates without user approval due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execut…
- CVE-2021-39692HIGHCVSS 7.8EG 7.82022-03-16
In onCreate of SetupLayoutActivity.java, there is a possible way to setup a work profile bypassing user consent due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. Use…
- CVE-2021-39669HIGHCVSS 7.8EG 7.82022-02-11
In onCreate of InstallCaCertificateWarning.java, there is a possible way to mislead an user about CA installation circumstances due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional executi…
- CVE-2021-1036HIGHCVSS 7.8EG 7.82022-01-14
In LocationSettingsActivity of AndroidManifest.xml, there is a possible EoP due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for…
- CVE-2021-1040HIGHCVSS 7.8EG 7.82021-12-15
In onCreate of BluetoothPairingSelectionFragment.java, there is a possible EoP due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed …
- CVE-2021-1039HIGHCVSS 7.8EG 7.82021-12-15
In NotificationAccessActivity of AndroidManifest.xml, there is a possible EoP due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed f…
- CVE-2021-0603HIGHCVSS 7.8EG 7.82021-07-14
In onCreate of ContactSelectionActivity.java, there is a possible way to get access to contacts without permission due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. …
- CVE-2021-0586HIGHCVSS 7.8EG 7.82021-07-14
In onCreate of DevicePickerFragment.java, there is a possible way to trick the user to select an unwanted bluetooth device due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution pr…
- CVE-2021-0487HIGHCVSS 7.8EG 7.82021-06-11
In onCreate of CalendarDebugActivity.java, there is a possible way to export calendar data to the sdcard without user consent due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileg…
Map vulnerabilities like CWE-1021 to your infrastructure
EchelonGraph correlates every CVE — across CWE-1021 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →