CWE-1021— Improper Restriction of Rendered UI Layers or Frames (Clickjacking)
The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain.— MITRE CWE catalog
424 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-1021page 5 of 9
- CVE-2022-22503MEDIUMCVSS 6.1EG 6.12022-10-06
IBM Robotic Process Automation 21.0.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim'…
- CVE-2022-36736MEDIUMCVSS 6.1EG 6.12022-09-08
Jitsi-2.10.5550 was discovered to contain a vulnerability in its web UI which allows attackers to perform a clickjacking attack via a crafted HTTP request. NOTE: this is disputed by the vendor
- CVE-2022-34162MEDIUMCVSS 6.1EG 6.12022-08-01
IBM CICS TX 11.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and p…
- CVE-2022-24733MEDIUMCVSS 6.1EG 6.12022-03-14
Sylius is an open source eCommerce platform. Prior to versions 1.9.10, 1.10.11, and 1.11.2, it is possible for a page controlled by an attacker to load the website within an iframe. This will enable a clickjacking attack, in which the atta…
- CVE-2021-46708MEDIUMCVSS 6.1EG 6.12022-03-11
The swagger-ui-dist package before 4.1.3 for Node.js could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hij…
- CVE-2018-19957MEDIUMCVSS 6.1EG 6.12021-09-10
A vulnerability involving insufficient HTTP security headers has been reported to affect QNAP NAS running QTS, QuTS hero, and QuTScloud. This vulnerability allows remote attackers to launch privacy and security attacks. We have already fix…
- CVE-2021-27467MEDIUMCVSS 6.1EG 6.12021-05-20
A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The affected product’s web interface allows an attacker to route click or keystroke to another page provided by the attacker to gain unautho…
- CVE-2021-23955MEDIUMCVSS 6.1EG 6.12021-02-26
The browser could have been confused into transferring a pointer lock state into another tab, which could have lead to clickjacking attacks. This vulnerability affects Firefox < 85.
- CVE-2021-21444MEDIUMCVSS 6.1EG 6.12021-02-09
SAP Business Objects BI Platform, versions - 410, 420, 430, allows multiple X-Frame-Options headers entries in the response headers, which may not be predictably treated by all user agents. This could, as a result, nullify the added X-Fram…
- CVE-2020-5020MEDIUMCVSS 6.1EG 6.12021-01-08
IBM Spectrum Protect Plus 10.1.0 through 10.1.6 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack t…
- CVE-2020-26962MEDIUMCVSS 6.1EG 6.12020-12-09
Cross-origin iframes that contained a login form could have been recognized by the login autofill service, and populated. This could have been used in clickjacking attacks, as well as be read across partitions in dynamic first party isolat…
- CVE-2020-5679MEDIUMCVSS 6.1EG 6.12020-12-03
Improper restriction of rendered UI layers or frames in EC-CUBE versions from 3.0.0 to 3.0.18 leads to clickjacking attacks. If a user accesses a specially crafted page while logged into the administrative page, unintended operations may b…
- CVE-2019-8771MEDIUMCVSS 6.1EG 6.12020-10-27
This issue was addressed with improved iframe sandbox enforcement. This issue is fixed in Safari 13.0.1, iOS 13. Maliciously crafted web content may violate iframe sandboxing policy.
- CVE-2020-4727MEDIUMCVSS 6.1EG 6.12020-09-25
IBM InfoSphere Information Server 11.7 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim…
- CVE-2020-13174MEDIUMCVSS 6.1EG 6.12020-08-11
The web server in the Teradici Managament console versions 20.04 and 20.01.1 did not properly set the X-Frame-Options HTTP header, which could allow an attacker to trick a user into clicking a malicious link via clickjacking.
- CVE-2020-9444MEDIUMCVSS 6.1EG 6.12020-04-20
Zulip Server before 2.1.3 allows reverse tabnabbing via the Markdown functionality.
- CVE-2019-4548MEDIUMCVSS 6.1EG 6.12020-02-04
IBM Security Directory Server 6.4.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's …
- CVE-2019-4742MEDIUMCVSS 6.1EG 6.12019-12-20
IBM Financial Transaction Manager 3.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim'…
- CVE-2019-4215MEDIUMCVSS 6.1EG 6.12019-11-22
IBM SmartCloud Analytics 1.3.1 through 1.3.5 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the …
- CVE-2019-4109MEDIUMCVSS 6.1EG 6.12019-09-30
IBM WebSphere eXtreme Scale 8.6 Admin Console could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the…
- CVE-2019-1975MEDIUMCVSS 6.1EG 6.12019-09-18
A vulnerability in the web-based interface of Cisco HyperFlex Software could allow an unauthenticated, remote attacker to execute a cross-frame scripting (XFS) attack on an affected device. This vulnerability is due to insufficient HTML if…
- CVE-2019-4086MEDIUMCVSS 6.1EG 6.12019-09-17
IBM Cloud Application Performance Management 8.1.4 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijac…
- CVE-2019-4217MEDIUMCVSS 6.1EG 6.12019-06-06
IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, and 1.0.2 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerabili…
- CVE-2018-1853MEDIUMCVSS 6.1EG 6.12019-04-08
IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerabili…
- CVE-2018-1803MEDIUMCVSS 6.1EG 6.12018-12-13
IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could …
- CVE-2018-0355MEDIUMCVSS 6.1EG 6.12018-06-07
A vulnerability in the web UI of Cisco Unified Communications Manager (Unified CM) could allow an unauthenticated, remote attacker to conduct a cross-frame scripting (XFS) attack against the user of the web UI of an affected system. The vu…
- CVE-2018-1432MEDIUMCVSS 6.1EG 6.12018-06-05
IBM InfoSphere Information Server 9.1, 11.3, 11.5, and 11.7 is vulnerable to cross-frame scripting which is a vulnerability that allows an attacker to load Information Server components inside an HTML iframe tag on a malicious page. The at…
- CVE-2017-11290MEDIUMCVSS 6.1EG 6.12017-12-09
An issue was discovered in Adobe Connect 9.6.2 and earlier versions. A UI Redress (or Clickjacking) vulnerability exists. This issue has been resolved by adding a feature that enables Connect administrators to protect users from UI redress…
- CVE-2021-27414MEDIUMCVSS 5.5EG 6.12022-03-11
An attacker could trick a user of Hitachi ABB Power Grids Ellipse Enterprise Asset Management (EAM) versions prior to and including 9.0.25 into visiting a malicious website posing as a login page for the Ellipse application and gather auth…
- CVE-2022-34318MEDIUMCVSS 5.4EG 6.12022-12-12
IBM CICS TX 11.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and …
- CVE-2022-33727MEDIUMCVSS 4.8EG 6.12022-08-05
A vulnerable code in onCreate of SecDevicePickerDialog prior to SMR Aug-2022 Release 1, allows attackers to trick the user to select an unwanted bluetooth device via tapjacking/overlay attack.
- CVE-2022-33723MEDIUMCVSS 4.8EG 6.12022-08-05
A vulnerable code in onCreate of BluetoothScanDialog prior to SMR Aug-2022 Release 1, allows attackers to trick the user to select an unwanted bluetooth device via tapjacking/overlay attack.
- CVE-2022-2800MEDIUMCVSS 4.3EG 6.12022-08-12
A vulnerability, which was classified as problematic, has been found in SourceCodester Gym Management System. Affected by this issue is some unknown functionality. The manipulation leads to clickjacking. The attack may be launched remotely…
- CVE-2024-30109MEDIUMCVSS 3.7EG 6.12024-06-28
HCL DRYiCE AEX is impacted by a lack of clickjacking protection in the AEX web application. An attacker can use multiple transparent or opaque layers to trick a user into clicking on a button or link on another page than the one intended.
- CVE-2026-0061MEDIUMCVSS 5.9EG 5.92026-06-01
In multiple functions of WindowState.java, there is a possible way to trick a user into accepting a permission due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges nee…
- CVE-2021-3731MEDIUMCVSS 5.9EG 5.92021-08-23
LedgerSMB does not sufficiently guard against being wrapped by other sites, making it vulnerable to 'clickjacking'. This allows an attacker to trick a targetted user to execute unintended actions.
- CVE-2011-1244MEDIUMCVSS v2 5.8EG 5.82011-04-13
Microsoft Internet Explorer 6, 7, and 8 does not enforce intended domain restrictions on content access, which allows remote attackers to obtain sensitive information or conduct clickjacking attacks via a crafted web site, aka "Frame Tag I…
- CVE-2026-86911MEDIUMCVSS 5.5EG 5.52026-09-14
This issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27. A malicious app may be able to bypass clickjacking protections for secure prompts.
- CVE-2025-31138MEDIUMCVSS 5.5EG 5.52025-04-07
tarteaucitron.js is a compliant and accessible cookie banner. A vulnerability was identified in tarteaucitron.js prior to 1.20.1, where user-controlled inputs for element dimensions (width and height) were not properly validated. This allo…
- CVE-2024-56436MEDIUMCVSS 5.5EG 5.52025-01-08
Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2024-54112MEDIUMCVSS 5.5EG 5.52024-12-12
Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2022-20215MEDIUMCVSS 5.5EG 5.52023-01-26
In onCreate of MasterClearConfirmFragment.java, there is a possible factory reset due to a tapjacking/overlay attack. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for…
- CVE-2022-20213MEDIUMCVSS 5.5EG 5.52023-01-26
In ApplicationsDetailsActivity of AndroidManifest.xml, there is a possible DoS due to a tapjacking/overlay attack. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for ex…
- CVE-2021-1038MEDIUMCVSS 5.5EG 5.52021-12-15
In UserDetailsActivity of AndroidManifest.xml, there is a possible DoS due to a tapjacking/overlay attack. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for exploitati…
- CVE-2020-0386MEDIUMCVSS 5.5EG 5.52020-09-17
In onCreate of RequestPermissionActivity.java, there is a possible tapjacking vector due to an insecure default value. This could lead to local escalation of privilege allowing an attacker to set Bluetooth discoverability with User executi…
- CVE-2020-0014MEDIUMCVSS 5.5EG 5.52020-02-13
It is possible for a malicious application to construct a TYPE_TOAST window manually and make that window clickable. This could lead to a local escalation of privilege with no additional execution privileges needed. User action is needed f…
- CVE-2017-0492MEDIUMCVSS 5.5EG 5.52017-03-08
An elevation of privilege vulnerability in the System UI could enable a local malicious application to create a UI overlay covering the entire screen. This issue is rated as Moderate because it is a local bypass of user interaction require…
- CVE-2026-106400MEDIUMCVSS 5.4EG 5.42026-10-06
Clickjacking in Messages in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-106356MEDIUMCVSS 5.4EG 5.42026-10-06
Clickjacking in EVP in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-106311MEDIUMCVSS 5.4EG 5.42026-10-06
Clickjacking in PermissionElement in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Map vulnerabilities like CWE-1021 to your infrastructure
EchelonGraph correlates every CVE — across CWE-1021 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →