CWE-1021— Improper Restriction of Rendered UI Layers or Frames (Clickjacking)
The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain.— MITRE CWE catalog
424 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-1021page 4 of 9
- CVE-2017-5016MEDIUMCVSS 6.5EG 6.52017-02-17
Blink in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, failed to prevent certain UI elements from being displayed by non-visible pages, which allowed a remote attacker to show certain UI elem…
- CVE-2021-41657MEDIUMCVSS 6.1EG 6.52022-03-10
SmartBear CodeCollaborator v6.1.6102 was discovered to contain a vulnerability in the web UI which would allow an attacker to conduct a clickjacking attack.
- CVE-2022-45096MEDIUMCVSS 5.4EG 6.52023-02-01
Dell PowerScale OneFS, 8.2.0 through 9.3.0, contain an User Interface Security Issue. An unauthenticated remote user could unintentionally lead an administrator to enable this vulnerability, leading to disclosure of information.
- CVE-2022-20852MEDIUMCVSS 5.4EG 6.52022-08-10
Multiple vulnerabilities in the web interface of Cisco Webex Meetings could allow a remote attacker to conduct a cross-site scripting (XSS) attack or a frame hijacking attack against a user of the web interface. For more information about …
- CVE-2017-20041MEDIUMCVSS 5.4EG 6.52022-06-13
A vulnerability was found in Ucweb UC Browser 11.2.5.932. It has been classified as critical. Affected is an unknown function of the component HTML Handler. The manipulation of the argument title leads to improper restriction of rendered u…
- CVE-2023-4956MEDIUMCVSS 4.3EG 6.52023-11-07
A flaw was found in Quay. Clickjacking is when an attacker uses multiple transparent or opaque layers to trick a user into clicking on a button or link on another page when they intend to click on the top-level page. During the pentest, it…
- CVE-2025-0362MEDIUMCVSS 6.4EG 6.42025-04-10
An issue has been discovered in GitLab CE/EE affecting all versions from 7.7 before 17.8.7, 17.9 before 17.9.6, and 17.10 before 17.10.4. Under certain conditions, an attacker could potentially trick users into unintentionally authorizing …
- CVE-2024-57369MEDIUMCVSS 6.4EG 6.42025-01-17
Clickjacking vulnerability in typecho v1.2.1.
- CVE-2024-1890MEDIUMCVSS 6.4EG 6.42024-02-26
Vulnerability whereby an attacker could send a malicious link to an authenticated operator, which could allow remote attackers to perform a clickjacking attack on Sunny WebBox firmware version 1.6.1 and earlier.
- CVE-2024-0669MEDIUMCVSS 6.3EG 6.32024-01-18
A Cross-Frame Scripting vulnerability has been found on Plone CMS affecting verssion below 6.0.5. An attacker could store a malicious URL to be opened by an administrator and execute a malicios iframe element.
- CVE-2025-36149MEDIUMCVSS 5.4EG 6.32025-11-21
IBM Concert Software 1.0.0 through 2.0.0 could allow a remote attacker to hijack the clicking action of the victim.
- CVE-2024-56435MEDIUMCVSS 6.2EG 6.22025-01-08
Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2024-54110MEDIUMCVSS 6.2EG 6.22024-12-12
Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2024-43084MEDIUMCVSS 5.5EG 6.22024-11-13
In visitUris of multiple files, there is a possible information disclosure due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploit…
- CVE-2026-84139MEDIUMCVSS 6.1EG 6.12026-09-01
Clickjacking issue in the DOM: Events component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
- CVE-2026-42502MEDIUMCVSS 6.1EG 6.12026-05-26
Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.
- CVE-2026-25681MEDIUMCVSS 6.1EG 6.12026-05-26
Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.
- CVE-2026-27136MEDIUMCVSS 6.1EG 6.12026-05-26
Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.
- CVE-2025-58405MEDIUMCVSS 6.1EG 6.12026-03-02
The CGM CLININET application does not implement any mechanisms that prevent clickjacking attacks, neither HTTP security headers nor HTML-based frame‑busting protections were detected. As a result, an attacker can embed the application in…
- CVE-2026-26000MEDIUMCVSS 6.1EG 6.12026-02-12
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Prior to 17.9.0, 17.4.6, and 16.10.13, it's possible using comments to inject CSS that would transform the full wiki in a link area le…
- CVE-2026-24839MEDIUMCVSS 6.1EG 6.12026-01-28
Dokploy is a free, self-hostable Platform as a Service (PaaS). In versions prior to 0.26.6, the Dokploy web interface is vulnerable to Clickjacking attacks due to missing frame-busting headers. This allows attackers to embed Dokploy pages …
- CVE-2025-52987MEDIUMCVSS 6.1EG 6.12026-01-15
A clickjacking vulnerability exists in the web portal of Juniper Networks Paragon Automation (Pathfinder, Planner, Insights) due to the application's failure to set appropriate X-Frame-Options and X-Content-Type HTTP headers. This vulnerab…
- CVE-2025-59849MEDIUMCVSS 6.1EG 6.12025-12-17
Improper management of Content Security Policy in HCL BigFix Remote Control Lite Web Portal (versions 10.1.0.0326 and lower) may allow the execution of malicious code in web pages.
- CVE-2025-59479MEDIUMCVSS 6.1EG 6.12025-12-16
CHOCO TEI WATCHER mini (IB-MCT001) contains an issue with improper restriction of rendered UI layers or frames. If a user clicks on content on a malicious web page while logged into the product, unintended operations may be performed on th…
- CVE-2025-57769MEDIUMCVSS 6.1EG 6.12025-09-29
FreshRSS is a free, self-hostable RSS aggregator. Versions 1.26.3 and below contain a vulnerability where a specially crafted page can trick a user into executing arbitrary JS code or promoting a user in FreshRSS by obscuring UI elements i…
- CVE-2025-1494MEDIUMCVSS 6.1EG 6.12025-08-26
IBM Cognos Command Center 10.2.4.1 and 10.2.5 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the…
- CVE-2025-54527MEDIUMCVSS 6.1EG 6.12025-07-28
In JetBrains YouTrack before 2025.2.86935, 2025.2.87167, 2025.3.87341, 2025.3.87344 improper iframe configuration in widget sandbox allows popups to bypass security restrictions
- CVE-2025-43854MEDIUMCVSS 6.1EG 6.12025-04-28
DIFY is an open-source LLM app development platform. Prior to version 1.3.0, a clickjacking vulnerability was found in the default setup of the DIFY application, allowing malicious actors to trick users into clicking on elements of the web…
- CVE-2024-10454MEDIUMCVSS 6.1EG 6.12024-10-31
Clickjacking vulnerability in Clibo Manager v1.1.9.12 in the '/public/login' directory, a login panel. This vulnerability occurs due to the absence of an X-Frame-Options server-side header. An attacker could overlay a transparent iframe to…
- CVE-2024-9397MEDIUMCVSS 6.1EG 6.12024-10-01
A missing delay in directory upload UI could have made it possible for an attacker to trick a user into granting permission via clickjacking. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbi…
- CVE-2024-39320MEDIUMCVSS 6.1EG 6.12024-07-30
Discourse is an open source discussion platform. Prior to 3.2.5 and 3.3.0.beta5, the vulnerability allows an attacker to inject iframes from any domain, bypassing the intended restrictions enforced by the allowed_iframes setting. This vuln…
- CVE-2024-40817MEDIUMCVSS 6.1EG 6.12024-07-29
The issue was addressed with improved UI handling. This issue is fixed in Safari 17.6, macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. Visiting a website that frames malicious content may lead to UI spoofing.
- CVE-2024-5698MEDIUMCVSS 6.1EG 6.12024-06-11
By manipulating the fullscreen feature while opening a data-list, an attacker could have overlaid a text box over the address bar. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 12…
- CVE-2024-2383MEDIUMCVSS 6.1EG 6.12024-06-06
A clickjacking vulnerability exists in zenml-io/zenml versions up to and including 0.55.5 due to the application's failure to set appropriate X-Frame-Options or Content-Security-Policy HTTP headers. This vulnerability allows an attacker to…
- CVE-2024-1550MEDIUMCVSS 6.1EG 6.12024-02-20
A malicious website could have used a combination of exiting fullscreen mode and `requestPointerLock` to cause the user's mouse to be re-positioned unexpectedly, which could have led to user confusion and inadvertently granting permissions…
- CVE-2023-6093MEDIUMCVSS 6.1EG 6.12023-12-31
A clickjacking vulnerability has been identified in OnCell G3150A-LTE Series firmware versions v1.3 and prior. This vulnerability is caused by incorrectly restricts frame objects, which can lead to user confusion about which interface the…
- CVE-2023-6867MEDIUMCVSS 6.1EG 6.12023-12-19
The timing of a button click causing a popup to disappear was approximately the same length as the anti-clickjacking delay on permission prompts. It was possible to use this fact to surprise users by luring them to click where the permissi…
- CVE-2023-4958MEDIUMCVSS 6.1EG 6.12023-12-12
In Red Hat Advanced Cluster Security (RHACS), it was found that some security related HTTP headers were missing, allowing an attacker to exploit this with a clickjacking attack. An attacker could exploit this by convincing a valid RHACS us…
- CVE-2023-47311MEDIUMCVSS 6.1EG 6.12023-11-20
An issue in Yamcs 5.8.6 allows attackers to send aribitrary telelcommands in a Command Stack via Clickjacking.
- CVE-2023-36920MEDIUMCVSS 6.1EG 6.12023-10-30
In SAP Enable Now - versions WPB_MANAGER 1.0, WPB_MANAGER_CE 10, WPB_MANAGER_HANA 10, ENABLE_NOW_CONSUMP_DEL 1704, the X-FRAME-OPTIONS response header is not implemented, allowing an unauthenticated attacker to attempt clickjacking, which …
- CVE-2023-1362MEDIUMCVSS 6.1EG 6.12023-03-13
Improper Restriction of Rendered UI Layers or Frames in GitHub repository unilogies/bumsys prior to v2.0.2.
- CVE-2022-32891MEDIUMCVSS 6.1EG 6.12023-02-27
The issue was addressed with improved UI handling. This issue is fixed in Safari 16, tvOS 16, watchOS 9, iOS 16. Visiting a website that frames malicious content may lead to UI spoofing.
- CVE-2022-40268MEDIUMCVSS 6.1EG 6.12023-02-02
Improper Restriction of Rendered UI Layers or Frames vulnerability in Mitsubishi Electric Corporation GOT2000 Series GT27 model versions 01.14.000 to 01.47.000, Mitsubishi Electric Corporation GOT2000 Series GT25 model versions 01.14.000 t…
- CVE-2023-23126MEDIUMCVSS 6.1EG 6.12023-02-01
Connectwise Automate 2022.11 is vulnerable to Clickjacking. The login screen can be iframed and used to manipulate users to perform unintended actions. NOTE: the vendor's position is that a Content-Security-Policy HTTP response header is p…
- CVE-2023-0057MEDIUMCVSS 6.1EG 6.12023-01-05
Improper Restriction of Rendered UI Layers or Frames in GitHub repository pyload/pyload prior to 0.5.0b3.dev33.
- CVE-2022-45418MEDIUMCVSS 6.1EG 6.12022-12-22
If a custom mouse cursor is specified in CSS, under certain circumstances the cursor could have been drawn over the browser UI, resulting in potential user confusion or spoofing attacks. This vulnerability affects Firefox ESR < 102.5, Thun…
- CVE-2022-29911MEDIUMCVSS 6.1EG 6.12022-12-22
An improper implementation of the new iframe sandbox keyword <code>allow-top-navigation-by-user-activation</code> could lead to script execution without <code>allow-scripts</code> being present. This vulnerability affects Thunderbird < 91.…
- CVE-2022-46061MEDIUMCVSS 6.1EG 6.12022-12-13
AeroCMS v0.0.1 is vulnerable to ClickJacking.
- CVE-2022-42799MEDIUMCVSS 6.1EG 6.12022-11-01
The issue was addressed with improved UI handling. This issue is fixed in tvOS 16.1, macOS Ventura 13, watchOS 9.1, Safari 16.1, iOS 16.1 and iPadOS 16. Visiting a malicious website may lead to user interface spoofing.
- CVE-2022-36182MEDIUMCVSS 6.1EG 6.12022-10-27
Hashicorp Boundary v0.8.0 is vulnerable to Clickjacking which allow for the interception of login credentials, re-direction of users to malicious sites, or causing users to perform malicious actions on the site.
Map vulnerabilities like CWE-1021 to your infrastructure
EchelonGraph correlates every CVE — across CWE-1021 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →