CWE-1021— Improper Restriction of Rendered UI Layers or Frames (Clickjacking)
The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain.— MITRE CWE catalog
424 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-1021page 8 of 9
- CVE-2025-1019MEDIUMCVSS 4.3EG 4.32025-02-04
The z-order of the browser windows could be manipulated to hide the fullscreen notification. This could potentially be leveraged to perform a spoofing attack. This vulnerability was fixed in Firefox 135 and Thunderbird 135.
- CVE-2023-42011MEDIUMCVSS 4.3EG 4.32024-06-27
IBM Sterling B2B Integrator Standard Edition 6.1 and 6.2 does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain, which can lead to user confusion about which interface the user is…
- CVE-2024-29981MEDIUMCVSS 4.3EG 4.32024-04-04
Microsoft Edge (Chromium-based) Spoofing Vulnerability
- CVE-2024-26167MEDIUMCVSS 4.3EG 4.32024-03-07
Microsoft Edge for Android Spoofing Vulnerability
- CVE-2023-2265MEDIUMCVSS 4.3EG 4.32023-11-30
An Improper Restriction of Rendered UI Layers or Frames in the Schweitzer Engineering Laboratories SEL-411L could allow an unauthenticated attacker to perform clickjacking based attacks against an authenticated and authorized user. See…
- CVE-2023-5721MEDIUMCVSS 4.3EG 4.32023-10-25
It was possible for certain browser prompts and dialogs to be activated or dismissed unintentionally by the user due to an insufficient activation-delay. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.…
- CVE-2023-5103MEDIUMCVSS 4.3EG 4.32023-10-09
Improper Restriction of Rendered UI Layers or Frames in RDT400 in SICK APU allows an unprivileged remote attacker to potentially reveal sensitive information via tricking a user into clicking on an actionable item using an iframe.
- CVE-2023-3140MEDIUMCVSS 4.3EG 4.32023-06-07
Missing HTTP headers (X-Frame-Options, Content-Security-Policy) in KNIME Business Hub before 1.4.0 has left users vulnerable to click jacking. Clickjacking is an attack that occurs when an attacker uses a transparent iframe in a window …
- CVE-2023-28159MEDIUMCVSS 4.3EG 4.32023-06-02
The fullscreen notification could have been hidden on Firefox for Android by using download popups, resulting in potential user confusion or spoofing attacks. <br>*This bug only affects Firefox for Android. Other operating systems are unaf…
- CVE-2023-25748MEDIUMCVSS 4.3EG 4.32023-06-02
By displaying a prompt with a long description, the fullscreen notification could have been hidden, resulting in potential user confusion or spoofing attacks. <br>*This bug only affects Firefox for Android. Other operating systems are unaf…
- CVE-2022-45417MEDIUMCVSS 4.3EG 4.32022-12-22
Service Workers did not detect Private Browsing Mode correctly in all cases, which could have led to Service Workers being written to disk for websites visited in Private Browsing Mode. This would not have persisted them in a state where t…
- CVE-2022-3034MEDIUMCVSS 4.3EG 4.32022-12-22
When receiving an HTML email that specified to load an <code>iframe</code> element from a remote location, a request to the remote document was sent. However, Thunderbird didn't display the document. This vulnerability affects Thunderbird …
- CVE-2022-2965MEDIUMCVSS 4.3EG 4.32022-08-23
Improper Restriction of Rendered UI Layers or Frames in GitHub repository notrinos/notrinoserp prior to 0.7.
- CVE-2022-28889MEDIUMCVSS 4.3EG 4.32022-07-07
In Apache Druid 0.22.1 and earlier, the server did not set appropriate headers to prevent clickjacking. Druid 0.23.0 and later prevent clickjacking using the Content-Security-Policy header.
- CVE-2022-27220MEDIUMCVSS 4.3EG 4.32022-06-14
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). Affected application is missing general HTTP security headers in the web server configured on port 6220. This could aid attackers by making the …
- CVE-2022-27219MEDIUMCVSS 4.3EG 4.32022-06-14
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). Affected application is missing general HTTP security headers in the web server configured on port 443. This could aid attackers by making the s…
- CVE-2021-3660MEDIUMCVSS 4.3EG 4.32022-03-10
Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a cockpit server via another website, inside an <iFrame> HTML entry. This may be used by a malicious website in clickjacking…
- CVE-2022-0110MEDIUMCVSS 4.3EG 4.32022-02-12
Incorrect security UI in Autofill in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
- CVE-2021-22819MEDIUMCVSS 4.3EG 4.32022-01-28
A CWE-1021 Improper Restriction of Rendered UI Layers or Frames vulnerability exists that could cause unintended modifications of the product settings or user accounts when deceiving the user to use the web interface rendered within iframe…
- CVE-2021-40834MEDIUMCVSS 4.3EG 4.32021-12-10
A user interface overlay vulnerability was discovered in F-secure SAFE Browser for Android. When user click on a specially crafted seemingly legitimate URL SAFE browser goes into full screen and hides the user interface. A remote attacker …
- CVE-2021-43546MEDIUMCVSS 4.3EG 4.32021-12-08
It was possible to recreate previous cursor spoofing attacks against users with a zoomed native cursor. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
- CVE-2021-38509MEDIUMCVSS 4.3EG 4.32021-12-08
Due to an unusual sequence of attacker-controlled events, a Javascript alert() dialog with arbitrary (although unstyled) contents could be displayed over top an uncontrolled webpage of the attacker's choosing. This vulnerability affects Fi…
- CVE-2021-38508MEDIUMCVSS 4.3EG 4.32021-12-08
By displaying a form validity message in the correct location at the same time as a permission prompt (such as for geolocation), the validity message could have obscured the prompt, resulting in the user potentially being tricked into gran…
- CVE-2021-38506MEDIUMCVSS 4.3EG 4.32021-12-08
Through a series of navigations, Firefox could have entered fullscreen mode without notification or warning to the user. This could lead to spoofing attacks on the browser UI including phishing. This vulnerability affects Firefox < 94, Thu…
- CVE-2021-37971MEDIUMCVSS 4.3EG 4.32021-10-08
Incorrect security UI in Web Browser UI in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
- CVE-2021-35300MEDIUMCVSS 4.3EG 4.32021-06-28
Text injection/Content Spoofing in 404 page in Zammad 1.0.x up to 4.0.0 could allow remote attackers to manipulate users into visiting the attackers' page.
- CVE-2020-10743MEDIUMCVSS 4.3EG 4.32021-06-02
It was discovered that OpenShift Container Platform's (OCP) distribution of Kibana could open in an iframe, which made it possible to intercept and manipulate requests. This flaw allows an attacker to trick a user into performing arbitrary…
- CVE-2020-16033MEDIUMCVSS 4.3EG 4.32021-01-08
Inappropriate implementation in WebUSB in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to spoof security UI via a crafted HTML page.
- CVE-2020-16032MEDIUMCVSS 4.3EG 4.32021-01-08
Insufficient data validation in sharing in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
- CVE-2020-16031MEDIUMCVSS 4.3EG 4.32021-01-08
Insufficient data validation in UI in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
- CVE-2020-26953MEDIUMCVSS 4.3EG 4.32020-12-09
It was possible to cause the browser to enter fullscreen mode without displaying the security UI; thus making it possible to attempt a phishing attack or otherwise confuse the user. This vulnerability affects Firefox < 83, Firefox ESR < 78…
- CVE-2020-9993MEDIUMCVSS 4.3EG 4.32020-12-08
The issue was addressed with improved UI handling. This issue is fixed in watchOS 7.0, Safari 14.0, iOS 14.0 and iPadOS 14.0. Visiting a malicious website may lead to address bar spoofing.
- CVE-2020-9987MEDIUMCVSS 4.3EG 4.32020-12-08
An inconsistent user interface issue was addressed with improved state management. This issue is fixed in Safari 14.0. Visiting a malicious website may lead to address bar spoofing.
- CVE-2020-9945MEDIUMCVSS 4.3EG 4.32020-12-08
A spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, Safari 14.0.1. Visiting a malicious website may lead to address bar spoofing.
- CVE-2020-9942MEDIUMCVSS 4.3EG 4.32020-12-08
An inconsistent user interface issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1, Safari 13.1.2. Visiting a malicious website may lead to address bar spoofing.
- CVE-2020-7371MEDIUMCVSS 4.3EG 4.32020-10-20
User Interface (UI) Misrepresentation of Critical Information vulnerability in the address bar of the Yandex Browser allows an attacker to obfuscate the true source of data as presented in the browser. This issue affects the RITS Browser v…
- CVE-2019-4323MEDIUMCVSS 4.3EG 4.32020-07-07
"HCL AppScan Enterprise advisory API documentation is susceptible to clickjacking, which could allow an attacker to embed the contents of untrusted web pages in a frame."
- CVE-2020-4322MEDIUMCVSS 4.3EG 4.32020-06-24
IBM Security Secret Server 10.7 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's clic…
- CVE-2013-5594MEDIUMCVSS 4.3EG 4.32020-02-18
Mozilla Firefox before 25 allows modification of anonymous content of pluginProblem.xml binding
- CVE-2013-2682MEDIUMCVSS 4.3EG 4.32020-02-05
Cisco Linksys E4200 1.0.05 Build 7 devices contain a Clickjacking Vulnerability which allows remote attackers to obtain sensitive information.
- CVE-2013-6772MEDIUMCVSS 4.3EG 4.32020-01-23
Splunk before 5.0.4 lacks X-Frame-Options which can allow Clickjacking
- CVE-2019-15930MEDIUMCVSS 4.3EG 4.32019-12-12
Intesync Solismed 3.3sp allows Clickjacking.
- CVE-2019-5861MEDIUMCVSS 4.3EG 4.32019-11-25
Insufficient data validation in Blink in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to bypass anti-clickjacking policy via a crafted HTML page.
- CVE-2019-17131MEDIUMCVSS 4.3EG 4.32019-10-04
vBulletin before 5.5.4 allows clickjacking.
- CVE-2019-16175MEDIUMCVSS 4.3EG 4.32019-09-09
A clickjacking vulnerability was found in Limesurvey before 3.17.14.
- CVE-2019-9147MEDIUMCVSS 4.3EG 4.32019-07-09
Mailvelope prior to 3.1.0 is vulnerable to a clickjacking attack against the settings page. As the settings page is intended to be accessible from web applications, the browser's extension isolation mechanisms are disabled (web_accessible_…
- CVE-2019-12880MEDIUMCVSS 4.3EG 4.32019-06-24
BCN Quark Quarking Password Manager 3.1.84 suffers from a clickjacking vulnerability caused by allowing * within web_accessible_resources. An attacker can take advantage of this vulnerability and cause significant harm.
- CVE-2019-0305MEDIUMCVSS 4.3EG 4.32019-06-12
Java Server Pages (JSPs) provided by the SAP NetWeaver Process Integration (SAP_XIESR and SAP_XITOOL: 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50) do not restrict or incorrectly restrict frame objects or UI layers that belong to another app…
- CVE-2019-5243MEDIUMCVSS 4.3EG 4.32019-06-10
There is a Clickjacking vulnerability in Huawei HG255s product. An attacker may trick user to click a link and affect the integrity of a device by exploiting this vulnerability.
- CVE-2019-7393MEDIUMCVSS 4.3EG 4.32019-05-28
A UI redress vulnerability in the administrative user interface of CA Technologies CA Strong Authentication 9.0.x, 8.2.x, 8.1.x, 8.0.x, 7.1.x and CA Risk Authentication 9.0.x, 8.2.x, 8.1.x, 8.0.x, 3.1.x may allow a remote attacker to gain …
Map vulnerabilities like CWE-1021 to your infrastructure
EchelonGraph correlates every CVE — across CWE-1021 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →