CWE-1021— Improper Restriction of Rendered UI Layers or Frames (Clickjacking)
The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain.— MITRE CWE catalog
424 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-1021page 6 of 9
- CVE-2026-71177MEDIUMCVSS 5.4EG 5.42026-09-23
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Restriction of Rendered UI Layers or Frames vulnerability. A low privileged attacker with remote access could potentially exploit this vul…
- CVE-2026-87655MEDIUMCVSS 5.4EG 5.42026-09-09
Clickjacking in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-75548MEDIUMCVSS 5.4EG 5.42026-08-27
The affected Ebyte device web management interface does not restrict the interface from being rendered within an external frame. An unauthenticated remote attacker could use a crafted webpage to mislead an authenticated administrator in…
- CVE-2026-70486MEDIUMCVSS 5.4EG 5.42026-08-04
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, the terminal file-preview serveUrl iframe branch always granted allow-same-origin together with allow-scripts for HTML files ser…
- CVE-2026-38979MEDIUMCVSS 5.4EG 5.42026-07-06
ajenti through v2.2.13 has a clickjacking weakness in the browser-facing login and administrative UI. In ajenti-core/aj/http.py, the core HTTP response path initializes an empty header list, forwards handler-added headers verbatim, and fin…
- CVE-2026-14142MEDIUMCVSS 5.4EG 5.42026-07-01
Inappropriate implementation in Extensions in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
- CVE-2026-44727MEDIUMCVSS 5.4EG 5.42026-06-18
Jupyter Server is the backend for Jupyter web applications. Prior to 2.20, the nbconvert HTTP handlers in jupyter_server render user-authored notebook HTML under the Jupyter origin without a sandbox directive in their Content-Security-Poli…
- CVE-2026-12323MEDIUMCVSS 5.4EG 5.42026-06-16
Spoofing issue in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.
- CVE-2026-12322MEDIUMCVSS 5.4EG 5.42026-06-16
Clickjacking issue in the Widget: Gtk component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.
- CVE-2025-30191MEDIUMCVSS 5.4EG 5.42025-10-31
Malicious content from E-Mail can be used to perform a redressing attack. Users can be tricked to perform unintended actions or provide sensitive information to a third party which would enable further threats. Attribute values containing …
- CVE-2025-28129MEDIUMCVSS 5.4EG 5.42025-10-06
Phpgurukul Hostel Management System 2.1 is vulnerable to clickjacking.
- CVE-2025-7903MEDIUMCVSS 5.4EG 5.42025-07-20
A vulnerability classified as problematic was found in yangzongzhuan RuoYi up to 4.8.1. Affected by this vulnerability is an unknown functionality of the component Image Source Handler. The manipulation leads to improper restriction of ren…
- CVE-2025-53096MEDIUMCVSS 5.4EG 5.42025-07-01
Sunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.628.4510, the web UI of Sunshine lacks protection against Clickjacking attacks. This vulnerability allows an attacker to embed the Sunshine interface within a …
- CVE-2025-36027MEDIUMCVSS 5.4EG 5.42025-06-28
IBM Datacap 9.1.7, 9.1.8, and 9.1.9 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victi…
- CVE-2025-6557MEDIUMCVSS 5.4EG 5.42025-06-24
Insufficient data validation in DevTools in Google Chrome on Windows prior to 138.0.7204.49 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium secur…
- CVE-2025-5267MEDIUMCVSS 5.4EG 5.42025-05-27
A clickjacking vulnerability could have been used to trick a user into leaking saved payment card details to a malicious page. This vulnerability was fixed in Firefox 139, Firefox ESR 128.11, Thunderbird 139, and Thunderbird 128.11.
- CVE-2024-49796MEDIUMCVSS 5.4EG 5.42025-02-06
IBM ApplinX 11.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and p…
- CVE-2024-53976MEDIUMCVSS 5.4EG 5.42024-11-26
Under certain circumstances, navigating to a webpage would result in the address missing from the location URL bar, making it unclear what the URL was for the loaded webpage. This vulnerability affects Firefox for iOS < 133.
- CVE-2024-11695MEDIUMCVSS 5.4EG 5.42024-11-26
A crafted URL containing Arabic script and whitespace characters could have hidden the true origin of the page, resulting in a potential spoofing attack. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and…
- CVE-2023-47774MEDIUMCVSS 5.4EG 5.42024-04-24
Improper Restriction of Rendered UI Layers or Frames vulnerability in Automattic Jetpack allows Clickjacking.This issue affects Jetpack: from n/a before 12.7.
- CVE-2023-6206MEDIUMCVSS 5.4EG 5.42023-11-21
The black fade animation when exiting fullscreen is roughly the length of the anti-clickjacking delay on permission prompts. It was possible to use this fact to surprise users by luring them to click where the permission grant button would…
- CVE-2023-37455MEDIUMCVSS 5.4EG 5.42023-07-12
The permission request prompt from the site in the background tab was overlaid on top of the site in the foreground tab. This vulnerability affects Firefox for iOS < 115.
- CVE-2023-25730MEDIUMCVSS 5.4EG 5.42023-06-02
A background script invoking <code>requestFullscreen</code> and then blocking the main thread could force the browser into fullscreen mode indefinitely, resulting in potential user confusion or spoofing attacks. This vulnerability affects …
- CVE-2023-0780MEDIUMCVSS 5.4EG 5.42023-02-11
Improper Restriction of Rendered UI Layers or Frames in GitHub repository cockpit-hq/cockpit prior to 2.3.9-dev.
- CVE-2022-28286MEDIUMCVSS 5.4EG 5.42022-12-22
Due to a layout change, iframe contents could have been rendered outside of its border. This could have led to user confusion or spoofing attacks. This vulnerability affects Thunderbird < 91.8, Firefox < 99, and Firefox ESR < 91.8.
- CVE-2022-20820MEDIUMCVSS 5.4EG 5.42022-08-10
Multiple vulnerabilities in the web interface of Cisco Webex Meetings could allow a remote attacker to conduct a cross-site scripting (XSS) attack or a frame hijacking attack against a user of the web interface. For more information about …
- CVE-2022-2734MEDIUMCVSS 5.4EG 5.42022-08-09
Improper Restriction of Rendered UI Layers or Frames in GitHub repository openemr/openemr prior to 7.0.0.1.
- CVE-2021-29865MEDIUMCVSS 5.4EG 5.42022-06-24
IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability …
- CVE-2021-39038MEDIUMCVSS 5.4EG 5.42022-02-24
IBM WebSphere Application Server 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.2 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a …
- CVE-2021-39054MEDIUMCVSS 5.4EG 5.42021-12-13
IBM Spectrum Copy Data Management 2.2.13 and earlier could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hij…
- CVE-2021-3799MEDIUMCVSS 5.4EG 5.42021-09-27
grav-plugin-admin is vulnerable to Improper Restriction of Rendered UI Layers or Frames
- CVE-2021-32070MEDIUMCVSS 5.4EG 5.42021-08-13
The MiCollab Client Service component in Mitel MiCollab before 9.3 could allow an attacker to perform a clickjacking attack due to an insecure header response. A successful exploit could allow an attacker to modify the browser header and r…
- CVE-2021-37788MEDIUMCVSS 5.4EG 5.42021-08-09
A vulnerability in the web UI of Gurock TestRail v5.3.0.3603 could allow an unauthenticated, remote attacker to affect the integrity of a device via a clickjacking attack. The vulnerability is due to insufficient input validation of iFrame…
- CVE-2021-20560MEDIUMCVSS 5.4EG 5.42021-07-26
IBM Sterling Connect:Direct Browser User Interface 1.4.1.1 and 1.5.0.2 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vu…
- CVE-2020-4547MEDIUMCVSS 5.4EG 5.42021-01-27
IBM Jazz Foundation products could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click a…
- CVE-2020-4785MEDIUMCVSS 5.4EG 5.42020-11-03
IBM App Connect Enterprise Certified Container 1.0.0, 1.0.1, 1.0.2, 1.0.3, and 1.0.4 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could e…
- CVE-2020-15793MEDIUMCVSS 5.4EG 5.42020-10-15
A vulnerability has been identified in Desigo Insight (All versions). The device does not properly set the X-Frame-Options HTTP Header which makes it vulnerable to Clickjacking attacks. This could allow an unauthenticated attacker to retri…
- CVE-2020-4165MEDIUMCVSS 5.4EG 5.42020-08-24
IBM Security Guardium Insights 2.0.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's…
- CVE-2020-4644MEDIUMCVSS 5.4EG 5.42020-07-29
IBM Planning Analytics Local 2.0.0 through 2.0.9.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijac…
- CVE-2020-4406MEDIUMCVSS 5.4EG 5.42020-06-15
IBM Spectrum Protect Client 8.1.7.0 through 8.1.9.1 (Linux and Windows), 8.1.9.0 trough 8.1.9.1 (AIX) and IBM Spectrum Protect for Space Management 8.1.7.0 through 8.1.9.1 (Linux), 8.1.9.0 through 8.1.9.1 (AIX) web user interfaces could al…
- CVE-2020-4195MEDIUMCVSS 5.4EG 5.42020-05-12
IBM API Connect V2018.4.1.0 through 2018.4.1.10 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack t…
- CVE-2020-9517MEDIUMCVSS 5.4EG 5.42020-03-09
There is an improper restriction of rendered UI layers or frames vulnerability in Micro Focus Service Manager Release Control versions 9.50 and 9.60. The vulnerability may result in the ability of malicious users to perform UI redress atta…
- CVE-2019-13924MEDIUMCVSS 5.4EG 5.42020-02-11
A vulnerability has been identified in SCALANCE S602 (All versions < V4.1), SCALANCE S612 (All versions < V4.1), SCALANCE S623 (All versions < V4.1), SCALANCE S627-2M (All versions < V4.1), SCALANCE X-200 switch family (incl. SIPLUS NET va…
- CVE-2020-2105MEDIUMCVSS 5.4EG 5.42020-01-29
REST API endpoints in Jenkins 2.218 and earlier, LTS 2.204.1 and earlier were vulnerable to clickjacking attacks.
- CVE-2019-4285MEDIUMCVSS 5.4EG 5.42019-07-30
IBM WebSphere Application Server - Liberty Admin Center could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could send a specially-crafted HTTP …
- CVE-2019-3794MEDIUMCVSS 5.4EG 5.42019-07-18
Cloud Foundry UAA, versions prior to v73.4.0, does not set an X-FRAME-OPTIONS header on various endpoints. A remote user can perform clickjacking attacks on UAA's frontend sites.
- CVE-2022-28649MEDIUMCVSS 4.6EG 5.42022-04-05
In JetBrains YouTrack before 2022.1.43563 it was possible to include an iframe from a third-party domain in the issue description
- CVE-2025-49139MEDIUMCVSS 5.3EG 5.32025-06-09
HAX CMS PHP allows users to manage their microsite universe with a PHP backend. Prior to version 11.0.0, in the HAX site editor, users can create a website block to load another site in an iframe. The application allows users to supply a t…
- CVE-2025-32385MEDIUMCVSS 5.3EG 5.32025-04-16
EspoCRM is an Open Source Customer Relationship Management software. Prior to 9.0.5, Iframe dashlet allows user to display iframes with arbitrary URLs. As the sandbox attribute is not included in the iframe, the remote page can open popups…
- CVE-2024-6466MEDIUMCVSS 5.3EG 5.32025-01-21
NEC Corporation's WebSAM DeploymentManager v6.0 to v6.80 allows an attacker to reset configurations or restart products via network with X-FRAME-OPTIONS is not specified.
Map vulnerabilities like CWE-1021 to your infrastructure
EchelonGraph correlates every CVE — across CWE-1021 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →