CWE-451— User Interface Misrepresentation of Critical Information
The user interface (UI) does not properly represent critical information to the user, allowing the information - or its source - to be obscured or spoofed. This is often a component in phishing attacks.— MITRE CWE catalog
434 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-451page 5 of 9
- CVE-2026-8008MEDIUMCVSS 5.4EG 5.42026-05-06
Inappropriate implementation in DevTools in Google Chrome prior to 148.0.7778.96 allowed an attacker who convinced a user to install a malicious extension to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: …
- CVE-2026-8006MEDIUMCVSS 5.4EG 5.42026-05-06
Insufficient policy enforcement in DevTools in Google Chrome prior to 148.0.7778.96 allowed an attacker who convinced a user to install a malicious extension to perform UI spoofing via a crafted Chrome Extension. (Chromium security severit…
- CVE-2026-7935MEDIUMCVSS 5.4EG 5.42026-05-06
Inappropriate implementation in Speech in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-33119MEDIUMCVSS 5.4EG 5.42026-04-10
User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
- CVE-2026-5895MEDIUMCVSS 5.4EG 5.42026-04-08
Incorrect security UI in Omnibox in Google Chrome on iOS prior to 147.0.7727.55 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name. (Chromium security severity: Low)
- CVE-2026-2322MEDIUMCVSS 5.4EG 5.42026-02-11
Inappropriate implementation in File input in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity…
- CVE-2026-0901MEDIUMCVSS 5.4EG 5.42026-01-20
Inappropriate implementation in Blink in Google Chrome on Android prior to 144.0.7559.59 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: High)
- CVE-2025-12435MEDIUMCVSS 5.4EG 5.42025-11-10
Incorrect security UI in Omnibox in Google Chrome on Android prior to 142.0.7444.59 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2025-9867MEDIUMCVSS 5.4EG 5.42025-09-03
Inappropriate implementation in Downloads in Google Chrome on Android prior to 140.0.7339.80 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2025-9865MEDIUMCVSS 5.4EG 5.42025-09-03
Inappropriate implementation in Toolbar in Google Chrome on Android prior to 140.0.7339.80 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform domain spoofing via a crafted HTML page. (Chromium secur…
- CVE-2025-47964MEDIUMCVSS 5.4EG 5.42025-07-11
Microsoft Edge (Chromium-based) Spoofing Vulnerability
- CVE-2024-39730MEDIUMCVSS 5.4EG 5.42025-06-28
IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the…
- CVE-2025-3074MEDIUMCVSS 5.4EG 5.42025-04-02
Inappropriate implementation in Downloads in Google Chrome prior to 135.0.7049.52 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
- CVE-2025-3073MEDIUMCVSS 5.4EG 5.42025-04-02
Inappropriate implementation in Autofill in Google Chrome prior to 135.0.7049.52 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: …
- CVE-2025-3072MEDIUMCVSS 5.4EG 5.42025-04-02
Inappropriate implementation in Custom Tabs in Google Chrome prior to 135.0.7049.52 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severit…
- CVE-2024-49796MEDIUMCVSS 5.4EG 5.42025-02-06
IBM ApplinX 11.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and p…
- CVE-2025-21262MEDIUMCVSS 5.4EG 5.42025-01-24
User Interface (UI) Misrepresentation of Critical Information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network
- CVE-2024-55896MEDIUMCVSS 5.4EG 5.42025-01-03
IBM PowerHA SystemMirror for i 7.4 and 7.5 contains improper restrictions when rendering content via iFrames. This vulnerability could allow an attacker to gain improper access and perform unauthorized actions on the system.
- CVE-2024-30055MEDIUMCVSS 5.4EG 5.42024-05-14
Microsoft Edge (Chromium-based) Spoofing Vulnerability
- CVE-2025-14020MEDIUMCVSS 4.3EG 5.42025-12-15
LINE client for Android versions prior to 14.20 contains a UI spoofing vulnerability in the in-app browser where the full-screen security Toast notification is not properly re-displayed when users return from another application, potential…
- CVE-2026-14153MEDIUMCVSS 5.3EG 5.32026-07-01
Inappropriate implementation in Glic in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
- CVE-2026-1658MEDIUMCVSS 5.3EG 5.32026-02-19
User Interface (UI) Misrepresentation of Critical Information vulnerability in OpenText™ Directory Services allows Cache Poisoning. The vulnerability could be exploited by a bad actor to inject manipulated text into the OpenText appli…
- CVE-2025-64667MEDIUMCVSS 5.3EG 5.32025-12-09
User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
- CVE-2025-8041MEDIUMCVSS 5.3EG 5.32025-08-19
In the address bar, Firefox for Android truncated the display of URLs from the end instead of prioritizing the origin. This vulnerability was fixed in Firefox 141.
- CVE-2025-21259MEDIUMCVSS 5.3EG 5.32025-02-11
Microsoft Outlook Spoofing Vulnerability
- CVE-2025-21253MEDIUMCVSS 5.3EG 5.32025-02-06
Microsoft Edge for IOS and Android Spoofing Vulnerability
- CVE-2024-47044MEDIUMCVSS 5.3EG 5.32024-09-26
Multiple Home GateWay/Hikari Denwa routers provided by NIPPON TELEGRAPH AND TELEPHONE EAST CORPORATION are vulnerable to insufficient access restrictions for Device Setting pages. If this vulnerability is exploited, an attacker who identif…
- CVE-2022-20530MEDIUMCVSS 5.3EG 5.32022-12-16
In strings.xml, there is a possible permission bypass due to a misleading string. This could lead to remote information disclosure of call logs with no additional execution privileges needed. User interaction is not needed for exploitation…
- CVE-2021-33593MEDIUMCVSS 5.3EG 5.32021-11-02
Whale browser for iOS before 1.14.0 has an inconsistent user interface issue that allows an attacker to obfuscate the address bar which may lead to address bar spoofing.
- CVE-2020-10775MEDIUMCVSS 5.3EG 5.32020-08-24
An Open redirect vulnerability was found in ovirt-engine versions 4.4 and earlier, where it allows remote attackers to redirect users to arbitrary web sites and attempt phishing attacks. Once the target has opened the malicious URL in thei…
- CVE-2016-9468MEDIUMCVSS 5.3EG 5.32017-03-28
Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from content spoofing in the dav app. The exception message displayed on the DAV endpoints contained partially user-controllable input leading to a p…
- CVE-2016-9467MEDIUMCVSS 5.3EG 5.32017-03-28
Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from content spoofing in the files app. The location bar in the files app was not verifying the passed parameters. An attacker could craft an invalid…
- CVE-2016-9460MEDIUMCVSS 5.3EG 5.32017-03-28
Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are vulnerable to a content-spoofing attack in the files app. The location bar in the files app was not verifying the passed parameters. An attacker could craft an invalid link …
- CVE-2026-0385MEDIUMCVSS 5.0EG 5.02026-03-16
Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability
- CVE-2025-68277MEDIUMCVSS 5.0EG 5.02026-02-25
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 7.0.4, when a link is sent via Secure Messaging, clicking the link opens the website within the OpenEMR/Portal site. …
- CVE-2024-55889MEDIUMCVSS 4.9EG 4.92024-12-13
phpMyFAQ is an open source FAQ web application. Prior to version 3.2.10, a vulnerability exists in the FAQ Record component where a privileged attacker can trigger a file download on a victim's machine upon page visit by embedding it in an…
- CVE-2026-95305MEDIUMCVSS 4.8EG 4.82026-09-29
UI misrepresentation in Chromoting in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to spoof UI elements via crafted network traffic. (Chromium security severity: Low)
- CVE-2026-95346MEDIUMCVSS 4.8EG 4.82026-09-29
UI misrepresentation in Chromoting in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via crafted network traffic. (Chromium security severity: Medium)
- CVE-2026-87597MEDIUMCVSS 4.8EG 4.82026-09-09
UI misrepresentation in CustomTabs in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to spoof address bar via a co-installed app. (Chromium security severity: Low)
- CVE-2026-14154MEDIUMCVSS 4.8EG 4.82026-07-01
Inappropriate implementation in DevTools in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: …
- CVE-2026-8565MEDIUMCVSS 4.7EG 4.72026-05-14
Inappropriate implementation in Downloads in Google Chrome on Mac prior to 148.0.7778.168 allowed an attacker who convinced a user to install a malicious extension to perform UI spoofing via a crafted Chrome Extension. (Chromium security s…
- CVE-2026-34258MEDIUMCVSS 4.7EG 4.72026-05-12
SAPUI5 (Search UI) allows an unauthenticated attacker to manipulate specific URL parameters on the Search UI to include malicious content. Successful exploitation may mislead victim users into clicking and accessing attacker-controlled pag…
- CVE-2026-44659MEDIUMCVSS 4.7EG 4.72026-05-11
Zen is a firefox-based browser. Prior to 1.19.12b, the ZEN Browser incorrectly truncates long hostnames in the address bar and shows only the attacker-controlled prefix of the subdomain, hiding the actual registrable domain (eTLD+1). As a …
- CVE-2025-14019MEDIUMCVSS 4.7EG 4.72025-12-15
LINE client for Android versions from 13.8 to 15.5 is vulnerable to UI spoofing in the in-app browser where a specific layout could obscure the full-screen warning prompt, potentially allowing attackers to conduct phishing attacks.
- CVE-2025-29796MEDIUMCVSS 4.7EG 4.72025-04-04
User interface (ui) misrepresentation of critical information in Microsoft Edge for iOS allows an unauthorized attacker to perform spoofing over a network.
- CVE-2024-38082MEDIUMCVSS 4.7EG 4.72024-06-20
Microsoft Edge (Chromium-based) Spoofing Vulnerability
- CVE-2016-9473MEDIUMCVSS 4.7EG 4.72017-03-28
Brave Browser iOS before 1.2.18 and Brave Browser Android 1.9.56 and earlier suffer from Full Address Bar Spoofing, allowing attackers to trick a victim by displaying a malicious page for legitimate domain names.
- CVE-2024-22455MEDIUMCVSS 4.4EG 4.62024-02-14
Dell Mobility - E-Lab Navigator, version(s) 3.1.9, 3.2.0, contain(s) an Authorization Bypass Through User-Controlled Key vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to …
- CVE-2026-102312MEDIUMCVSS 4.3EG 4.32026-09-29
UI misrepresentation in Omnibox in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-87567MEDIUMCVSS 4.3EG 4.32026-09-09
UI misrepresentation in UrlFormatting in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof address bar via a crafted domain name. (Chromium security severity: Medium)
Map vulnerabilities like CWE-451 to your infrastructure
EchelonGraph correlates every CVE — across CWE-451 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →