CWE-1021— Improper Restriction of Rendered UI Layers or Frames (Clickjacking)
374 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-1021page 8 of 8
- CVE-2025-6434MEDIUMCVSS 4.3EG 4.32025-06-24
The exception page for the HTTPS-Only feature, displayed when a website is opened via HTTP, lacked an anti-clickjacking delay, potentially allowing an attacker to trick a user into granting an exception and loading a webpage over HTTP. Thi…
- CVE-2025-64387MEDIUMCVSS 5.1EG 0.02025-10-31
The web application is vulnerable to a so-called ‘clickjacking’ attack. In this type of attack, the vulnerable page is inserted into a page controlled by the attacker in order to deceive the victim. This deception can range from making…
- CVE-2025-6557MEDIUMCVSS 5.4EG 5.42025-06-24
Insufficient data validation in DevTools in Google Chrome on Windows prior to 138.0.7204.49 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium secur…
- CVE-2025-65922MEDIUMCVSS 4.3EG 4.32026-01-05
PLANKA 2.0.0 lacks X-Frame-Options and CSP frame-ancestors headers, allowing the application to be embedded within malicious iframes. While this does not lead to unintended modification of projects or tasks, it exposes users to Phishing at…
- CVE-2025-6983MEDIUMCVSS 5.1EG 0.02025-07-16
A Clickjacking vulnerability in TP-Link Archer C1200 web management page allows an attacker to trick users into performing unintended actions via rendered UI layers or frames.This issue affects Archer C1200 <= 1.1.5.
- CVE-2025-7903MEDIUMCVSS 4.3EG 4.32025-07-20
A vulnerability classified as problematic was found in yangzongzhuan RuoYi up to 4.8.1. Affected by this vulnerability is an unknown functionality of the component Image Source Handler. The manipulation leads to improper restriction of ren…
- CVE-2025-9108MEDIUMCVSS 4.3EG 4.32025-08-18
Affected is an unknown function of the component Login Page. The manipulation leads to improper restriction of rendered ui layers. It is possible to launch the attack remotely.
- CVE-2026-0036HIGHCVSS 7.8EG 0.02026-06-01
In startAnimation of StageCoordinator.java, there is a possible tapjacking issue due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not n…
- CVE-2026-0061MEDIUMCVSS 5.9EG 0.02026-06-01
In multiple functions of WindowState.java, there is a possible way to trick a user into accepting a permission due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges nee…
- CVE-2026-20645MEDIUMCVSS 4.6EG 4.62026-02-11
An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3. An attacker with physical access to a locked device may be able to view sensi…
- CVE-2026-21785MEDIUMCVSS 4.0EG 4.02026-05-27
A misconfigured Content Security Policy (CSP) in HCL BigFix Remote Control Server WebUI (versions 10.1.0.0442 and earlier) fails to define directives without fallbacks, allowing attackers to bypass intended security restrictions and load u…
- CVE-2026-22918MEDIUMCVSS 4.3EG 4.32026-01-15
An attacker may exploit missing protection against clickjacking by tricking users into performing unintended actions through maliciously crafted web pages, leading to the extraction of sensitive data.
- CVE-2026-23731MEDIUMCVSS 4.3EG 4.32026-01-16
WeGIA is a web manager for charitable institutions. Prior to 3.6.2, The web application is vulnerable to clickjacking attacks. The WeGIA application does not send any defensive HTTP headers related to framing protection. In particular, X-F…
- CVE-2026-24839MEDIUMCVSS 4.7EG 4.72026-01-28
Dokploy is a free, self-hostable Platform as a Service (PaaS). In versions prior to 0.26.6, the Dokploy web interface is vulnerable to Clickjacking attacks due to missing frame-busting headers. This allows attackers to embed Dokploy pages …
- CVE-2026-25681MEDIUMCVSS 6.1EG 6.12026-05-26
Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.
- CVE-2026-26000MEDIUMCVSS 6.1EG 6.12026-02-12
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Prior to 17.9.0, 17.4.6, and 16.10.13, it's possible using comments to inject CSS that would transform the full wiki in a link area le…
- CVE-2026-27136MEDIUMCVSS 6.1EG 6.12026-05-26
Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.
- CVE-2026-28577HIGHCVSS 7.8EG 0.02026-06-01
In addWindow of WindowManagerService.java, there is a possible tapjacking issue due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not ne…
- CVE-2026-28971MEDIUMCVSS 4.3EG 4.32026-05-11
The issue was addressed with improved UI handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, visionOS 26.5. A malicious iframe may use another website’s download settings.
- CVE-2026-3254LOWCVSS 3.5EG 3.52026-04-22
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.11 before 18.11.1 that under certain conditions could have allowed an authenticated user to load unauthorized content into another user's browser due to improper…
- CVE-2026-37470HIGHCVSS 7.3EG 7.32026-05-26
An issue in ClipBucket v5 v.5.5.2 allows an attacker to execute arbitrary code via the... An issue in ClipBucket v5 v.5.5.2 allows an attacker to execute arbitrary code via the Authentication interface, login page endpoint and HTTP respon…
- CVE-2026-42502MEDIUMCVSS 6.1EG 6.12026-05-26
Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.
- CVE-2026-8022LOWCVSS 3.1EG 3.12026-05-06
Inappropriate implementation in MHTML in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted MHTML page. (Chromium security severity:…
- CVE-2026-9396LOWCVSS 3.7EG 3.72026-05-24
A security flaw has been discovered in Besen BS20 EV Charging Station up to 20260426. Affected by this vulnerability is an unknown functionality of the component Firmware Version Check. The manipulation results in improper restriction of r…
Map vulnerabilities like CWE-1021 to your infrastructure
EchelonGraph correlates every CVE — across CWE-1021 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →