CWE-1021— Improper Restriction of Rendered UI Layers or Frames (Clickjacking)
The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain.— MITRE CWE catalog
424 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-1021page 3 of 9
- CVE-2019-2125HIGHCVSS 7.3EG 7.32019-08-20
In ChangeDefaultDialerDialog.java, there is a possible escalation of privilege due to an overlay attack. This could lead to local escalation of privilege, granting privileges to a local app without the user's informed consent, with no addi…
- CVE-2025-1018HIGHCVSS 5.3EG 7.32025-02-04
The fullscreen notification is prematurely hidden when fullscreen is re-requested quickly by the user. This could have been leveraged to perform a potential spoofing attack. This vulnerability was fixed in Firefox 135 and Thunderbird 135.
- CVE-2026-70608HIGHCVSS 7.2EG 7.22026-08-05
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10, 41.10.3, and 42.0.1, a sandboxed iframe without the allow-popups keyword could still open a new window or trigger set…
- CVE-2026-47723HIGHCVSS 7.1EG 7.12026-06-08
nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.1, none of the response paths in `internal/web/` or `internal/api/` set the standard browser-security headers. `grep` for `Conte…
- CVE-2025-1940HIGHCVSS 7.1EG 7.12025-03-04
A select option could partially obscure the confirmation prompt shown before launching external apps. This could be used to trick a user in to launching an external app unexpectedly. *This issue only affects Android versions of Firefox.*.…
- CVE-2024-55888HIGHCVSS 7.1EG 7.12024-12-12
Hush Line is an open-source whistleblower management system. Starting in version 0.1.0 and prior to version 0.3.5, the productions server appeared to have been misconfigured and missed providing any content security policy or security head…
- CVE-2021-34087HIGHCVSS 7.1EG 7.12022-01-10
In Ultimaker S3 3D printer, Ultimaker S5 3D printer, Ultimaker 3 3D printer S-line through 6.3 and Ultimaker 3 through 5.2.16, the local webserver can be used for clickjacking. This includes the settings page.
- CVE-2021-0963HIGHCVSS 7.1EG 7.12021-12-15
In onCreate of KeyChainActivity.java, there is a possible way to use an app certificate stored in keychain due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed.…
- CVE-2019-3639HIGHCVSS 7.1EG 7.12019-08-14
Clickjack vulnerability in Adminstrator web console in McAfee Web Gateway (MWG) 7.8.2.x prior to 7.8.2.12 allows remote attackers to conduct clickjacking attacks via a crafted web page that contains an iframe via does not send an X-Frame-O…
- CVE-2017-16775HIGHCVSS 7.1EG 7.12019-04-01
Improper restriction of rendered UI layers or frames vulnerability in SSOOauth.cgi in Synology SSO Server before 2.1.3-0129 allows remote attackers to conduct clickjacking attacks via unspecified vectors.
- CVE-2022-1803MEDIUMCVSS 6.9EG 6.92022-05-20
Improper Restriction of Rendered UI Layers or Frames in GitHub repository polonel/trudesk prior to 1.2.2.
- CVE-2022-22552MEDIUMCVSS 6.9EG 6.92022-01-21
Dell EMC AppSync versions 3.9 to 4.3 contain a clickjacking vulnerability in AppSync. A remote unauthenticated attacker could potentially exploit this vulnerability to trick the victim into executing state changing operations.
- CVE-2025-24874MEDIUMCVSS 6.8EG 6.82025-02-11
SAP Commerce (Backoffice) uses the deprecated X-FRAME-OPTIONS header to protect against clickjacking. While this protection remains effective now, it may not be the case in the future as browsers might discontinue support for this header i…
- CVE-2024-7404MEDIUMCVSS 6.8EG 6.82024-11-14
An issue was discovered in GitLab CE/EE affecting all versions starting from 17.2 prior to 17.3.7, starting from 17.4 prior to 17.4.4 and starting from 17.5 prior to 17.5.2, which could have allowed an attacker gaining full API access as t…
- CVE-2024-2177MEDIUMCVSS 6.8EG 6.82024-07-09
A Cross Window Forgery vulnerability exists within GitLab CE/EE affecting all versions from 16.3 prior to 16.11.5, 17.0 prior to 17.0.3, and 17.1 prior to 17.1.1. This condition allows for an attacker to abuse the OAuth authentication flow…
- CVE-2025-59950MEDIUMCVSS 6.7EG 6.72025-09-30
FreshRSS is a free, self-hostable RSS aggregator. In versions 1.26.3 and below, due to a bypass of double clickjacking protection (confirmation dialog), it is possible to trick the admin into clicking the Promote button in another user's m…
- CVE-2026-74980MEDIUMCVSS 6.5EG 6.52026-08-18
Clickjacking issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 154.
- CVE-2026-74951MEDIUMCVSS 6.5EG 6.52026-08-18
Clickjacking issue in Firefox for Android. This vulnerability was fixed in Firefox 154.
- CVE-2026-16397MEDIUMCVSS 6.5EG 6.52026-07-21
Clickjacking issue in the WebExtensions component in Firefox for Android. This vulnerability was fixed in Firefox 153.
- CVE-2025-25213MEDIUMCVSS 6.5EG 6.52025-04-09
Improper restriction of rendered UI layers or frames issue exists in Wi-Fi AP UNIT 'AC-WPS-11ac series'. If a user views and clicks on the content on the malicious page while logged in, unintended operations may be performed.
- CVE-2024-7518MEDIUMCVSS 6.5EG 6.52024-08-06
Select options could obscure the fullscreen notification dialog. This could be used by a malicious site to perform a spoofing attack. This vulnerability affects Firefox < 129, Firefox ESR < 128.1, and Thunderbird < 128.1.
- CVE-2024-4950MEDIUMCVSS 6.5EG 6.52024-05-15
Inappropriate implementation in Downloads in Google Chrome prior to 125.0.6422.60 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity:…
- CVE-2024-3911MEDIUMCVSS 6.5EG 6.52024-04-23
An unauthenticated remote attacker can deceive users into performing unintended actions due to improper restriction of rendered UI layers or frames.
- CVE-2024-28196MEDIUMCVSS 6.5EG 6.52024-03-13
your_spotify is an open source, self hosted Spotify tracking dashboard. YourSpotify version < 1.9.0 does not prevent other pages from displaying it in an iframe and is thus vulnerable to clickjacking. Clickjacking can be used to trick an e…
- CVE-2023-6211MEDIUMCVSS 6.5EG 6.52023-11-21
If an attacker needed a user to load an insecure http: page and knew that user had enabled HTTPS-only mode, the attacker could have tricked the user into clicking to grant an HTTPS-only exception if they could get the user to participate i…
- CVE-2023-38873MEDIUMCVSS 6.5EG 6.52023-09-28
The commit 3730880 (April 2023) and v.0.9-beta1 of gugoan Economizzer is vulnerable to Clickjacking. Clickjacking, also known as a "UI redress attack", is when an attacker uses multiple transparent or opaque layers to trick a user into cli…
- CVE-2023-30961MEDIUMCVSS 6.5EG 6.52023-09-27
Palantir Gotham was found to be vulnerable to a bug where under certain circumstances, the frontend could have applied an incorrect classification to a newly created property or link.
- CVE-2022-43378MEDIUMCVSS 6.5EG 6.52023-04-18
A CWE-1021: Improper Restriction of Rendered UI Layers or Frames vulnerability exists that could cause the user to be tricked into performing unintended actions when external address frames are not properly restricted. Affecte…
- CVE-2022-32517MEDIUMCVSS 6.5EG 6.52023-01-30
A CWE-1021: Improper Restriction of Rendered UI Layers or Frames vulnerability exists that could cause an adversary to trick the interface user/admin into interacting with the application in an unintended way when the product does not impl…
- CVE-2022-45420MEDIUMCVSS 6.5EG 6.52022-12-22
Use tables inside of an iframe, an attacker could have caused iframe contents to be rendered outside the boundaries of the iframe, resulting in potential user confusion or spoofing attacks. This vulnerability affects Firefox ESR < 102.5, T…
- CVE-2022-29914MEDIUMCVSS 6.5EG 6.52022-12-22
When reusing existing popups Firefox would have allowed them to cover the fullscreen notification UI, which could have enabled browser spoofing attacks. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100.
- CVE-2022-20553MEDIUMCVSS 6.5EG 6.52022-12-16
In onCreate of LogAccessDialogActivity.java, there is a possible way to bypass a permission check due to a tapjacking/overlay attack. This could lead to local escalation of privilege with System execution privileges needed. User interactio…
- CVE-2022-46695MEDIUMCVSS 6.5EG 6.52022-12-15
A spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation. This issue is fixed in tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Visiting …
- CVE-2022-1138MEDIUMCVSS 6.5EG 6.52022-07-23
Inappropriate implementation in Web Cursor in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who had compromised the renderer process to obscure the contents of the Omnibox (URL bar) via a crafted HTML page.
- CVE-2022-2179MEDIUMCVSS 6.5EG 6.52022-07-20
The X-Frame-Options header in Rockwell Automation MicroLogix 1100/1400 Versions 21.007 and prior is not configured in the HTTP response, which could allow clickjacking attacks.
- CVE-2022-0455MEDIUMCVSS 6.5EG 6.52022-04-05
Inappropriate implementation in Full Screen Mode in Google Chrome on Android prior to 98.0.4758.80 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
- CVE-2021-21139MEDIUMCVSS 6.5EG 6.52021-02-09
Inappropriate implementation in iframe sandbox in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
- CVE-2020-28218MEDIUMCVSS 6.5EG 6.52020-12-11
A CWE-1021: Improper Restriction of Rendered UI Layers or Frames vulnerability exists in Easergy T300 (firmware 2.7 and older), that would allow an attacker to trick a user into initiating an unintended action.
- CVE-2020-24711MEDIUMCVSS 6.5EG 6.52020-10-28
The Reset button on the Account Settings page in Gophish before 0.11.0 allows attackers to cause a denial of service via a clickjacking attack
- CVE-2020-6547MEDIUMCVSS 6.5EG 6.52020-09-21
Incorrect security UI in media in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially obtain sensitive information via a crafted HTML page.
- CVE-2020-15648MEDIUMCVSS 6.5EG 6.52020-08-10
Using object or embed tags, it was possible to frame other websites, even if they disallowed framing using the X-Frame-Options header. This vulnerability affects Thunderbird < 78 and Firefox < 78.0.2.
- CVE-2019-19001MEDIUMCVSS 6.5EG 6.52020-04-02
For ABB eSOMS versions 4.0 to 6.0.2, the X-Frame-Options header is not configured in HTTP response. This can potentially allow 'ClickJacking' attacks where an attacker can frame parts of the application on a malicious web site, revealing s…
- CVE-2013-2675MEDIUMCVSS 6.5EG 6.52020-02-05
Brother MFC-9970CDW 1.10 devices with Firmware L contain a Frameable response (Clickjacking) vulnerability which could allow remote attackers to obtain sensitive information.
- CVE-2019-4058MEDIUMCVSS 6.5EG 6.52019-05-20
IBM BigFix Platform 9.2 and 9.5 could allow a low-privilege user to manipulate the UI into exposing interface elements and information normally restricted to administrators. IBM X-Force ID: 156570.
- CVE-2019-5767MEDIUMCVSS 6.5EG 6.52019-02-19
Insufficient protection of permission UI in WebAPKs in Google Chrome on Android prior to 72.0.3626.81 allowed an attacker who convinced the user to install a malicious application to access privacy/security sensitive web APIs via a crafted…
- CVE-2018-16172MEDIUMCVSS 6.5EG 6.52019-01-09
Improper countermeasure against clickjacking attack in client certificates management screen was discovered in Cybozu Remote Service 3.0.0 to 3.1.8, that allows remote attackers to trick a user to delete the registered client certificate.
- CVE-2018-17192MEDIUMCVSS 6.5EG 6.52018-12-19
The X-Frame-Options headers were applied inconsistently on some HTTP responses, resulting in duplicate or missing security headers. Some browsers would interpret these results incorrectly, allowing clickjacking attacks. Mitigation: The fix…
- CVE-2018-6909MEDIUMCVSS 6.5EG 6.52018-11-01
A missing X-Frame-Options header in the Green Electronics RainMachine Mini-8 (2nd Generation) and Touch HD 12 web application could be used by a remote attacker for clickjacking, as demonstrated by triggering an API page request.
- CVE-2017-5697MEDIUMCVSS 6.5EG 6.52017-06-14
Insufficient clickjacking protection in the Web User Interface of Intel AMT firmware versions before 9.1.40.1000, 9.5.60.1952, 10.0.50.1004, 11.0.0.1205, and 11.6.25.1129 potentially allowing a remote attacker to hijack users web clicks vi…
- CVE-2017-7440MEDIUMCVSS 6.5EG 6.52017-05-02
Kerio Connect 8.0.0 through 9.2.2, and Kerio Connect Client desktop application for Windows and Mac 9.2.0 through 9.2.2, when e-mail preview is enabled, allows remote attackers to conduct clickjacking attacks via a crafted e-mail message.
Map vulnerabilities like CWE-1021 to your infrastructure
EchelonGraph correlates every CVE — across CWE-1021 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →