CWE-451— User Interface Misrepresentation of Critical Information
The user interface (UI) does not properly represent critical information to the user, allowing the information - or its source - to be obscured or spoofed. This is often a component in phishing attacks.— MITRE CWE catalog
434 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-451page 3 of 9
- CVE-2023-0130MEDIUMCVSS 6.5EG 6.52023-01-10
Inappropriate implementation in in Fullscreen API in Google Chrome on Android prior to 109.0.5414.74 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2022-45404MEDIUMCVSS 6.5EG 6.52022-12-22
Through a series of popup and <code>window.print()</code> calls, an attacker can cause a window to go fullscreen without the user seeing the notification prompt, resulting in potential user confusion or spoofing attacks. This vulnerability…
- CVE-2022-34479MEDIUMCVSS 6.5EG 6.52022-12-22
A malicious website that could create a popup could have resized the popup to overlay the address bar with its own content, resulting in potential user confusion or spoofing attacks. <br>*This bug only affects Thunderbird for Linux. Other …
- CVE-2022-3313MEDIUMCVSS 6.5EG 6.52022-11-01
Incorrect security UI in full screen in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2022-32816MEDIUMCVSS 6.5EG 6.52022-09-23
The issue was addressed with improved UI handling. This issue is fixed in watchOS 8.7, tvOS 15.6, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. Visiting a website that frames malicious content may lead to UI spoofing.
- CVE-2026-13989MEDIUMCVSS 5.3EG 6.52026-06-30
Inappropriate implementation in PageInfo in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2023-4956MEDIUMCVSS 4.3EG 6.52023-11-07
A flaw was found in Quay. Clickjacking is when an attacker uses multiple transparent or opaque layers to trick a user into clicking on a button or link on another page when they intend to click on the top-level page. During the pentest, it…
- CVE-2025-3523MEDIUMCVSS 6.4EG 6.42025-04-15
When an email contains multiple attachments with external links via the X-Mozilla-External-Attachment-URL header, only the last link is shown when hovering over any attachment. Although the correct link is used on click, the misleading hov…
- CVE-2026-45150MEDIUMCVSS 6.3EG 6.32026-07-15
Zen is a firefox-based browser. Prior to 1.19.13b, Zen Browser did not provide a persistent, clearly visible security notification when a webpage entered fullscreen mode, allowing an attacker-controlled page to hide the real browser UI and…
- CVE-2026-13356MEDIUMCVSS 6.3EG 6.32026-07-06
A malicious webpage could interrupt a pending navigation by enqueuing a synchronous JavaScript dialog, causing the browser UI to display the destination origin in the address bar while continuing to render attacker-controlled content. This…
- CVE-2025-11213MEDIUMCVSS 6.3EG 6.32025-11-06
Inappropriate implementation in Omnibox in Google Chrome on Android prior to 141.0.7390.54 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform domain spoofing via a crafted HTML page. (Chromium secur…
- CVE-2025-11212MEDIUMCVSS 6.3EG 6.32025-11-06
Inappropriate implementation in Media in Google Chrome on Windows prior to 141.0.7390.54 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform domain spoofing via a crafted HTML page. (Chromium securit…
- CVE-2025-11208MEDIUMCVSS 6.3EG 6.32025-11-06
Inappropriate implementation in Media in Google Chrome prior to 141.0.7390.54 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Med…
- CVE-2025-47963MEDIUMCVSS 6.3EG 6.32025-07-11
No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
- CVE-2025-0451MEDIUMCVSS 6.3EG 6.32025-02-04
Inappropriate implementation in Extensions API in Google Chrome prior to 133.0.6943.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted Chrome Extension. (Chromium securi…
- CVE-2026-48760MEDIUMCVSS 6.1EG 6.12026-06-15
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0 until 6.4.41, 7.4.13, and 8.0.13, UrlSanitizer::parse() rejected raw BiDi formatting characters but not percent-encoded forms and …
- CVE-2026-45064MEDIUMCVSS 6.1EG 6.12026-05-27
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0-BETA1 until 6.4.40, 7.4.12, and 8.0.12, UrlSanitizer::parse() passes Unicode explicit-direction BiDi formatting characters through…
- CVE-2025-3859MEDIUMCVSS 6.1EG 6.12025-04-30
Websites directing users to long URLs that caused eliding to occur in the location view could leverage the truncating behavior to potentially trick users into thinking they were on a different webpage. This vulnerability was fixed in Focus…
- CVE-2024-5698MEDIUMCVSS 6.1EG 6.12024-06-11
By manipulating the fullscreen feature while opening a data-list, an attacker could have overlaid a text box over the address bar. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 12…
- CVE-2021-27414MEDIUMCVSS 5.5EG 6.12022-03-11
An attacker could trick a user of Hitachi ABB Power Grids Ellipse Enterprise Asset Management (EAM) versions prior to and including 9.0.25 into visiting a malicious website posing as a login page for the Ellipse application and gather auth…
- CVE-2022-2800MEDIUMCVSS 4.3EG 6.12022-08-12
A vulnerability, which was classified as problematic, has been found in SourceCodester Gym Management System. Affected by this issue is some unknown functionality. The manipulation leads to clickjacking. The attack may be launched remotely…
- CVE-2026-32318MEDIUMCVSS 5.9EG 5.92026-03-20
Cryptomator for IOS offers multi-platform transparent client-side encryption for files in the cloud. Prior to version 2.8.3, an integrity check vulnerability allows an attacker tamper with the vault configuration file leading to a man-in-t…
- CVE-2026-32317MEDIUMCVSS 5.9EG 5.92026-03-20
Cryptomator for Android offers multi-platform transparent client-side encryption for files in the cloud. Prior to version 1.12.3, an integrity check vulnerability allows an attacker tamper with the vault configuration file leading to a man…
- CVE-2026-32303MEDIUMCVSS 5.9EG 5.92026-03-20
Cryptomator encrypts data being stored on cloud infrastructure. Prior to version 1.19.1, an integrity check vulnerability allows an attacker to tamper with the vault configuration file leading to a man-in-the-middle vulnerability in Hub ke…
- CVE-2022-23646MEDIUMCVSS 5.9EG 5.92022-02-17
Next.js is a React framework. Starting with version 10.0.0 and prior to version 12.1.0, Next.js is vulnerable to User Interface (UI) Misrepresentation of Critical Information. In order to be affected, the `next.config.js` file must have an…
- CVE-2026-18622MEDIUMCVSS 5.5EG 5.52026-08-13
Foxit PDF Editor/Reader inconsistently alerts users when signature fields are abnormally modified, including alterations to appearance, coordinates, or field duplication. This may mislead users into trusting tampered documents, since the U…
- CVE-2026-9106MEDIUMCVSS 5.5EG 5.52026-06-30
A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed an OAuth application to gain unintended access to an organization's runner management. An attacker could exploit this by creating an OAuth applica…
- CVE-2026-39309MEDIUMCVSS 5.5EG 5.52026-05-20
Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. In versions 0.102.1 and prior, the Electron configuration is vulnerable to TCC Bypass via Prompt Spoofing, allowing…
- CVE-2025-62224MEDIUMCVSS 3.5EG 5.52026-01-07
User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an authorized attacker to perform spoofing over a network.
- CVE-2026-106272MEDIUMCVSS 5.4EG 5.42026-10-06
UI misrepresentation in Chromoting in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially spoof UI elements via crafted network traffic. (Chromium security severity: Low)
- CVE-2026-106251MEDIUMCVSS 5.4EG 5.42026-10-06
UI misrepresentation in Chromoting in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via crafted network traffic. (Chromium security severity: Low)
- CVE-2026-106236MEDIUMCVSS 5.4EG 5.42026-10-06
UI misrepresentation in Chromoting in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via crafted network traffic. (Chromium security severity: Low)
- CVE-2026-106316MEDIUMCVSS 5.4EG 5.42026-10-06
UI misrepresentation in Chromoting in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via crafted network traffic. (Chromium security severity: Low)
- CVE-2026-106305MEDIUMCVSS 5.4EG 5.42026-10-06
UI misrepresentation in Mobile in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
- CVE-2026-106368MEDIUMCVSS 5.4EG 5.42026-10-06
UI misrepresentation in UI in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
- CVE-2026-106179MEDIUMCVSS 5.4EG 5.42026-10-06
UI misrepresentation in WebAppInstalls in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
- CVE-2026-106380MEDIUMCVSS 5.4EG 5.42026-10-06
UI misrepresentation in UI in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
- CVE-2026-106285MEDIUMCVSS 5.4EG 5.42026-10-06
UI misrepresentation in WebAppInstalls in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)
- CVE-2026-106317MEDIUMCVSS 5.4EG 5.42026-10-06
UI misrepresentation in FullScreen in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Low)
- CVE-2026-106338MEDIUMCVSS 5.4EG 5.42026-10-06
UI misrepresentation in PictureInPicture in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Low)
- CVE-2026-106276MEDIUMCVSS 5.4EG 5.42026-10-06
UI misrepresentation in Payments in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
- CVE-2026-106337MEDIUMCVSS 5.4EG 5.42026-10-06
UI misrepresentation in UI in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-106232MEDIUMCVSS 5.4EG 5.42026-10-06
UI misrepresentation in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-106229MEDIUMCVSS 5.4EG 5.42026-10-06
UI misrepresentation in FileSystem in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-106209MEDIUMCVSS 5.4EG 5.42026-10-06
UI misrepresentation in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof address bar via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-106282MEDIUMCVSS 5.4EG 5.42026-10-06
UI misrepresentation in WebOTP in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-106182MEDIUMCVSS 5.4EG 5.42026-10-06
UI misrepresentation in Paint in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-106302MEDIUMCVSS 5.4EG 5.42026-10-06
UI misrepresentation in PermissionElement in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-106265MEDIUMCVSS 5.4EG 5.42026-10-06
UI misrepresentation in File in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-102305MEDIUMCVSS 5.4EG 5.42026-09-29
UI misrepresentation in SignIn in Google Chrome on on iOS prior to 154.0.8037.92 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
Map vulnerabilities like CWE-451 to your infrastructure
EchelonGraph correlates every CVE — across CWE-451 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →