CWE-1021— Improper Restriction of Rendered UI Layers or Frames (Clickjacking)
The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain.— MITRE CWE catalog
424 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-1021page 7 of 9
- CVE-2024-8388MEDIUMCVSS 5.3EG 5.32024-09-03
Multiple prompts and panels from both Firefox and the Android OS could be used to obscure the notification announcing the transition to fullscreen mode after the fix for CVE-2023-6870 in Firefox 121. This could lead to spoofing the browser…
- CVE-2023-34658MEDIUMCVSS 5.3EG 5.32023-06-29
Telegram v9.6.3 on iOS allows attackers to hide critical information on the User Interface via calling the function SFSafariViewController.
- CVE-2021-27375MEDIUMCVSS 5.3EG 5.32021-02-18
Traefik before 2.4.5 allows the loading of IFRAME elements from other domains.
- CVE-2021-29827MEDIUMCVSS 5.2EG 5.22024-12-19
IBM InfoSphere Information Server 11.7 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim…
- CVE-2025-64387MEDIUMCVSS 5.1EG 5.12025-10-31
The web application is vulnerable to a so-called ‘clickjacking’ attack. In this type of attack, the vulnerable page is inserted into a page controlled by the attacker in order to deceive the victim. This deception can range from making…
- CVE-2025-6983MEDIUMCVSS 5.1EG 5.12025-07-16
A Clickjacking vulnerability in TP-Link Archer C1200 web management page allows an attacker to trick users into performing unintended actions via rendered UI layers or frames.This issue affects Archer C1200 <= 1.1.5.
- CVE-2005-2407MEDIUMCVSS v2 5.1EG 5.12005-08-01
A design error in Opera 8.01 and earlier allows user-assisted attackers to execute arbitrary code by overlaying a malicious new window above a file download dialog box, then tricking the user into double-clicking on the "Run" button, aka "…
- CVE-2021-35237MEDIUMCVSS 5.0EG 5.02021-10-29
A missing HTTP header (X-Frame-Options) in Kiwi Syslog Server has left customers vulnerable to click jacking. Clickjacking is an attack that occurs when an attacker uses a transparent iframe in a window to trick a user into clicking on an …
- CVE-2021-0569MEDIUMCVSS 5.0EG 5.02021-06-22
In onStart of ContactsDumpActivity.java, there is possible access to contacts due to a tapjacking/overlay attack. This could lead to local information disclosure with User execution privileges needed. User interaction is needed for exploit…
- CVE-2014-1483MEDIUMCVSS v2 5.0EG 5.02014-02-06
Mozilla Firefox before 27.0 and SeaMonkey before 2.24 allow remote attackers to bypass the Same Origin Policy and obtain sensitive information by using an IFRAME element in conjunction with certain timing measurements involving the documen…
- CVE-2008-2716MEDIUMCVSS v2 5.0EG 5.02008-06-16
Unspecified vulnerability in Opera before 9.5 allows remote attackers to spoof the contents of trusted frames on the same parent page by modifying the location, which can facilitate phishing attacks.
- CVE-2025-52658MEDIUMCVSS 4.8EG 4.82025-10-03
HCL MyXalytics is affected by the use of vulnerable/outdated versions which can expose the application to known security risks that could be exploited.
- CVE-2025-49191MEDIUMCVSS 4.8EG 4.82025-06-12
Linked URLs during the creation of iFrame widgets and dashboards are vulnerable to code execution. The URLs get embedded as iFrame widgets, making it possible to attack other users that access the dashboard by including malicious code. The…
- CVE-2023-45698MEDIUMCVSS 4.8EG 4.82024-02-10
Sametime is impacted by lack of clickjacking protection in Outlook add-in. The application is not implementing appropriate protections in order to protect users from clickjacking attacks.
- CVE-2022-3260MEDIUMCVSS 4.8EG 4.82022-12-08
The response header has not enabled X-FRAME-OPTIONS, Which helps prevents against Clickjacking attack.. Some browsers would interpret these results incorrectly, allowing clickjacking attacks.
- CVE-2020-1728MEDIUMCVSS 4.8EG 4.82020-04-06
A vulnerability was found in all versions of Keycloak where, the pages on the Admin Console area of the application are completely missing general HTTP security headers in HTTP-responses. This does not directly lead to a security issue, ye…
- CVE-2025-0421MEDIUMCVSS 4.7EG 4.72025-11-19
Improper Restriction of Rendered UI Layers or Frames vulnerability in Shopside Software Technologies Inc. Shopside allows iFrame Overlay. This issue affects Shopside: through 05022025.
- CVE-2025-0546MEDIUMCVSS 4.7EG 4.72025-09-17
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting'), Improper Restriction of Rendered UI Layers or Frames vulnerability in Mevzuattr Software MevzuatTR allows Phishing, iFrame Overlay, Clickjacking, …
- CVE-2023-7013MEDIUMCVSS 4.7EG 4.72024-07-16
Inappropriate implementation in Compositing in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to potentially spoof security UI via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2022-32919MEDIUMCVSS 4.7EG 4.72024-01-10
The issue was addressed with improved UI handling. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1. Visiting a website that frames malicious content may lead to UI spoofing.
- CVE-2023-4229MEDIUMCVSS 4.7EG 4.72023-08-24
A vulnerability has been identified in ioLogik 4000 Series (ioLogik E4200) firmware versions v1.6 and prior, potentially exposing users to security risks. This vulnerability may allow attackers to trick users into interacting with maliciou…
- CVE-2022-20214MEDIUMCVSS 4.7EG 4.72023-01-26
In Car Settings app, the toggle button in Modify system settings is vulnerable to tapjacking attack. Attackers can overlay the toggle button to enable apps to modify system settings without user consent.Product: AndroidVersions: Android-10…
- CVE-2021-38472MEDIUMCVSS 4.7EG 4.72021-10-19
InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 management portal does not contain an X-FRAME-OPTIONS header, which an attacker may take advantage of by sending a link to an administrator that frames the router’s mana…
- CVE-2021-27003MEDIUMCVSS 4.7EG 4.72021-10-12
Clustered Data ONTAP versions prior to 9.5P18, 9.6P15, 9.7P14, 9.8P5 and 9.9.1 are missing an X-Frame-Options header which could allow a clickjacking attack.
- CVE-2020-35735MEDIUMCVSS 4.7EG 4.72020-12-29
Vidyo 02-09-/D allows clickjacking via the portal/ URI.
- CVE-2020-6827MEDIUMCVSS 4.7EG 4.72020-04-24
When following a link that opened an intent://-schemed URL, causing a custom tab to be opened, Firefox for Android could be tricked into displaying the incorrect URI. <br> *Note: This issue only affects Firefox for Android. Other operating…
- CVE-2020-10951MEDIUMCVSS 4.7EG 4.72020-04-15
Western Digital My Cloud Home and ibi devices before 2.2.0 allow clickjacking on sign-in pages.
- CVE-2018-15423MEDIUMCVSS 4.7EG 4.72018-10-05
A vulnerability in the web UI of Cisco HyperFlex Software could allow an unauthenticated, remote attacker to affect the integrity of a device via a clickjacking attack. The vulnerability is due to insufficient input validation of iFrame da…
- CVE-2026-20645MEDIUMCVSS 4.6EG 4.62026-02-11
An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3. An attacker with physical access to a locked device may be able to view sensi…
- CVE-2025-63522MEDIUMCVSS 4.6EG 4.62025-12-01
Reverse Tabnabbing vulnerability in FeehiCMS 2.1.1 in the Comments Management function
- CVE-2016-5710MEDIUMCVSS 4.6EG 4.62020-02-11
NetApp Snap Creator Framework before 4.3P1 allows remote authenticated users to conduct clickjacking attacks via unspecified vectors.
- CVE-2017-4015MEDIUMCVSS 4.5EG 4.52017-05-17
Clickjacking vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote authenticated users to inject arbitrary web script or HTML via HTTP response header.
- CVE-2021-1006MEDIUMCVSS 4.4EG 4.42021-12-15
In several functions of DatabaseManager.java, there is a possible leak of Bluetooth MAC addresses due to log information disclosure. This could lead to local information disclosure with System execution privileges needed. User interaction …
- CVE-2026-70600MEDIUMCVSS 4.3EG 4.32026-08-05
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, the native autofill popup could be positioned by a cross-origin iframe outside that…
- CVE-2026-14110MEDIUMCVSS 4.3EG 4.32026-07-01
Inappropriate implementation in DarkMode in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
- CVE-2026-10733MEDIUMCVSS 4.3EG 4.32026-06-11
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.0 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that could have allowed an authenticated user to cause denial of service on the CI/CD Catalog page…
- CVE-2026-28971MEDIUMCVSS 4.3EG 4.32026-05-11
The issue was addressed with improved UI handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, visionOS 26.5. A malicious iframe may use another website’s download settings.
- CVE-2026-27511MEDIUMCVSS 4.3EG 4.32026-02-23
Shenzhen Tenda F3 Wireless Router firmware V12.01.01.55_multi contains a clickjacking vulnerability in the web-based administrative interface. The interface does not set the X-Frame-Options header, allowing attacker-controlled sites to em…
- CVE-2026-23731MEDIUMCVSS 4.3EG 4.32026-01-16
WeGIA is a web manager for charitable institutions. Prior to 3.6.2, The web application is vulnerable to clickjacking attacks. The WeGIA application does not send any defensive HTTP headers related to framing protection. In particular, X-F…
- CVE-2025-65922MEDIUMCVSS 4.3EG 4.32026-01-05
PLANKA 2.0.0 lacks X-Frame-Options and CSP frame-ancestors headers, allowing the application to be embedded within malicious iframes. While this does not lead to unintended modification of projects or tasks, it exposes users to Phishing at…
- CVE-2025-14373MEDIUMCVSS 4.3EG 4.32025-12-12
Inappropriate implementation in Toolbar in Google Chrome on Android prior to 143.0.7499.110 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2024-13066MEDIUMCVSS 4.3EG 4.32025-09-03
Improper Restriction of Rendered UI Layers or Frames vulnerability in Akinsoft LimonDesk allows iFrame Overlay, CAPEC - 103 - Clickjacking. This issue affects LimonDesk: from s1.02.14 before v1.02.17.
- CVE-2025-9108MEDIUMCVSS 4.3EG 4.32025-08-18
Affected is an unknown function of the component Login Page. The manipulation leads to improper restriction of rendered ui layers. It is possible to launch the attack remotely.
- CVE-2025-54139MEDIUMCVSS 4.3EG 4.32025-07-23
HAX CMS allows users to manage their microsite universe with a NodeJS or PHP backend. In haxcms-nodejs versions 11.0.12 and below and in haxcms-php versions 11.0.7 and below, all pages within the HAX CMS application do not contain headers …
- CVE-2025-27455MEDIUMCVSS 4.3EG 4.32025-07-03
The web application is vulnerable to clickjacking attacks. The site can be embedded into another frame, allowing an attacker to trick a user into clicking on something different from what the user perceives, thus potentially revealing conf…
- CVE-2025-6434MEDIUMCVSS 4.3EG 4.32025-06-24
The exception page for the HTTPS-Only feature, displayed when a website is opened via HTTP, lacked an anti-clickjacking delay, potentially allowing an attacker to trick a user into granting an exception and loading a webpage over HTTP. Thi…
- CVE-2025-49192MEDIUMCVSS 4.3EG 4.32025-06-12
The web application is vulnerable to clickjacking attacks. The site can be embedded into another frame, allowing an attacker to trick a user into clicking on something different from what the user perceives. This could potentially reveal c…
- CVE-2025-24310MEDIUMCVSS 4.3EG 4.32025-04-04
Improper restriction of rendered UI layers or frames issue exists in HMI ViewJet C-more series, which may allow a remote unauthenticated attacker to trick the product user to perform operations on the product's web pages.
- CVE-2025-1923MEDIUMCVSS 4.3EG 4.32025-03-05
Inappropriate implementation in Permission Prompts in Google Chrome prior to 134.0.6998.35 allowed an attacker who convinced a user to install a malicious extension to perform UI spoofing via a crafted Chrome Extension. (Chromium security …
- CVE-2025-1917MEDIUMCVSS 4.3EG 4.32025-03-05
Inappropriate implementation in Browser UI in Google Chrome on Android prior to 134.0.6998.35 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Map vulnerabilities like CWE-1021 to your infrastructure
EchelonGraph correlates every CVE — across CWE-1021 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →