CWE-1021— Improper Restriction of Rendered UI Layers or Frames (Clickjacking)
The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain.— MITRE CWE catalog
424 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-1021page 9 of 9
- CVE-2018-6178MEDIUMCVSS 4.3EG 4.32019-01-09
Eliding from the wrong side in an infobar in DevTools in Google Chrome prior to 68.0.3440.75 allowed an attacker who convinced a user to install a malicious extension to Hide Chrome Security UI via a crafted Chrome Extension.
- CVE-2018-12576MEDIUMCVSS 4.3EG 4.32018-07-02
TP-Link TL-WR841N v13 00000001 0.9.1 4.16 v0001.0 Build 180119 Rel.65243n devices allow clickjacking.
- CVE-2017-5026MEDIUMCVSS 4.3EG 4.32017-02-17
Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, failed to prevent alerts from being displayed by swapped out frames, which allowed a remote attacker to show alerts on a page they don't control via a crafted HTML page.
- CVE-2021-27773MEDIUMCVSS 4.2EG 4.32022-05-12
This vulnerability allows users to execute a clickjacking attack in the meeting's chat.
- CVE-2014-1480MEDIUMCVSS v2 4.3EG 4.32014-02-06
The file-download implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 does not properly restrict the timing of button selections, which allows remote attackers to conduct clickjacking attacks, and trigger unintended lau…
- CVE-2013-5614MEDIUMCVSS v2 4.3EG 4.32013-12-11
Mozilla Firefox before 26.0 and SeaMonkey before 2.23 do not properly consider the sandbox attribute of an IFRAME element during processing of a contained OBJECT element, which allows remote attackers to bypass intended sandbox restriction…
- CVE-2026-87538MEDIUMCVSS 4.2EG 4.22026-09-09
Clickjacking in Input in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Lo…
- CVE-2026-87486MEDIUMCVSS 4.0EG 4.02026-09-09
Clickjacking in TrustedWebActivities in Google Chrome on on Android prior to 153.0.8010.36 allowed a local attacker to spoof address bar via a co-installed app. (Chromium security severity: Medium)
- CVE-2026-21785MEDIUMCVSS 4.0EG 4.02026-05-27
A misconfigured Content Security Policy (CSP) in HCL BigFix Remote Control Server WebUI (versions 10.1.0.0442 and earlier) fails to define directives without fallbacks, allowing attackers to bypass intended security restrictions and load u…
- CVE-2023-0654LOWCVSS 3.9EG 3.92023-08-29
Due to a misconfiguration, the WARP Mobile Client (< 6.29) for Android was susceptible to a tapjacking attack. In the event that an attacker built a malicious application and managed to install it on a victim's device, the attacker would b…
- CVE-2022-20226LOWCVSS 3.9EG 3.92022-07-13
In finishDrawingWindow of WindowManagerService.java, there is a possible tapjacking due to improper input validation. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for ex…
- CVE-2026-44762LOWCVSS 3.7EG 3.72026-08-11
SAP Data Services Management Console allows an overly permissive Content Security Policy (CSP) configuration and lacks certain restrictive directives, which could enable an authenticated malicious user to leverage this weakness in combinat…
- CVE-2026-9396LOWCVSS 3.7EG 3.72026-05-24
A security flaw has been discovered in Besen BS20 EV Charging Station up to 20260426. Affected by this vulnerability is an unknown functionality of the component Firmware Version Check. The manipulation results in improper restriction of r…
- CVE-2025-62328LOWCVSS 3.7EG 3.72026-03-11
HCL Nomad server on Domino did not configure the frame-ancestors directive in the Content-Security-Policy header by default which could allow an attacker to obtain sensitive information via unspecified vectors.
- CVE-2026-59791LOWCVSS 3.5EG 3.52026-07-10
In JetBrains YouTrack before 2026.2.17012 cSS injection via Mermaid diagram rendering was possible
- CVE-2026-3254LOWCVSS 3.5EG 3.52026-04-22
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.11 before 18.11.1 that under certain conditions could have allowed an authenticated user to load unauthorized content into another user's browser due to improper…
- CVE-2021-33596LOWCVSS 3.5EG 3.52021-08-05
Showing the legitimate URL in the address bar while loading the content from other domain. This makes the user believe that the content is served by a legit domain. Exploiting the vulnerability requires the user to click on a specially cra…
- CVE-2024-20810LOWCVSS 3.3EG 3.32024-02-06
Implicit intent hijacking vulnerability in Smart Suggestions prior to SMR Feb-2024 Release 1 allows local attackers to get sensitive information.
- CVE-2021-0992LOWCVSS 3.3EG 3.32021-12-15
In onCreate of PaymentDefaultDialog.java, there is a possible way to change a default payment app without user consent due to tapjack overlay. This could lead to local escalation of privilege with no additional execution privileges needed.…
- CVE-2026-8022LOWCVSS 3.1EG 3.12026-05-06
Inappropriate implementation in MHTML in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted MHTML page. (Chromium security severity:…
- CVE-2023-2013LOWCVSS 2.6EG 2.62023-06-07
An issue has been discovered in GitLab CE/EE affecting all versions starting from 1.2 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. An issue was found that allows someone to…
- CVE-2023-23343LOWCVSS 2.4EG 2.42023-06-22
A clickjacking vulnerability in the HCL BigFix OSD Bare Metal Server version 311.12 or lower allows attacker to use transparent or opaque layers to trick a user into clicking on a button or link on another page to perform a redirect to an …
- CVE-2025-62316LOWCVSS 2.3EG 2.32026-05-14
HCL AION is affected by a vulnerability where certain security-related HTTP response headers are not properly configured. Absence of these headers may reduce the effectiveness of browser-based security controls and could expose the applica…
- CVE-2025-41000LOWCVSS 2.1EG 2.12025-09-03
Cross-Frame Scripting (XFS) vulnerability in BoomCMS v9.1.4 from UXB London. XFS is a web attack technique that exploits specific browser bugs to spy on users via JavaScript. This type of attack is based on social engineering and depends e…
Map vulnerabilities like CWE-1021 to your infrastructure
EchelonGraph correlates every CVE — across CWE-1021 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →