CWE-1021— Improper Restriction of Rendered UI Layers or Frames (Clickjacking)
The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain.— MITRE CWE catalog
401 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-1021page 8 of 9
- CVE-2025-54139MEDIUMCVSS 4.3EG 4.32025-07-23
HAX CMS allows users to manage their microsite universe with a NodeJS or PHP backend. In haxcms-nodejs versions 11.0.12 and below and in haxcms-php versions 11.0.7 and below, all pages within the HAX CMS application do not contain headers …
- CVE-2025-54527MEDIUMCVSS 6.1EG 6.12025-07-28
In JetBrains YouTrack before 2025.2.86935, 2025.2.87167, 2025.3.87341, 2025.3.87344 improper iframe configuration in widget sandbox allows popups to bypass security restrictions
- CVE-2025-57769MEDIUMCVSS 6.1EG 6.12025-09-29
FreshRSS is a free, self-hostable RSS aggregator. Versions 1.26.3 and below contain a vulnerability where a specially crafted page can trick a user into executing arbitrary JS code or promoting a user in FreshRSS by obscuring UI elements i…
- CVE-2025-58405MEDIUMCVSS 6.1EG 6.12026-03-02
The CGM CLININET application does not implement any mechanisms that prevent clickjacking attacks, neither HTTP security headers nor HTML-based frame‑busting protections were detected. As a result, an attacker can embed the application in…
- CVE-2025-59479MEDIUMCVSS 6.1EG 6.12025-12-16
CHOCO TEI WATCHER mini (IB-MCT001) contains an issue with improper restriction of rendered UI layers or frames. If a user clicks on content on a malicious web page while logged into the product, unintended operations may be performed on th…
- CVE-2025-59849MEDIUMCVSS 4.7EG 4.72025-12-17
Improper management of Content Security Policy in HCL BigFix Remote Control Lite Web Portal (versions 10.1.0.0326 and lower) may allow the execution of malicious code in web pages.
- CVE-2025-59950MEDIUMCVSS 6.7EG 6.72025-09-30
FreshRSS is a free, self-hostable RSS aggregator. In versions 1.26.3 and below, due to a bypass of double clickjacking protection (confirmation dialog), it is possible to trick the admin into clicking the Promote button in another user's m…
- CVE-2025-62316LOWCVSS 2.3EG 2.32026-05-14
HCL AION is affected by a vulnerability where certain security-related HTTP response headers are not properly configured. Absence of these headers may reduce the effectiveness of browser-based security controls and could expose the applica…
- CVE-2025-62328LOWCVSS 3.7EG 3.72026-03-11
HCL Nomad server on Domino did not configure the frame-ancestors directive in the Content-Security-Policy header by default which could allow an attacker to obtain sensitive information via unspecified vectors.
- CVE-2025-63522MEDIUMCVSS 4.6EG 4.62025-12-01
Reverse Tabnabbing vulnerability in FeehiCMS 2.1.1 in the Comments Management function
- CVE-2025-6434MEDIUMCVSS 4.3EG 4.32025-06-24
The exception page for the HTTPS-Only feature, displayed when a website is opened via HTTP, lacked an anti-clickjacking delay, potentially allowing an attacker to trick a user into granting an exception and loading a webpage over HTTP. Thi…
- CVE-2025-64387MEDIUMCVSS 5.1EG 5.12025-10-31
The web application is vulnerable to a so-called ‘clickjacking’ attack. In this type of attack, the vulnerable page is inserted into a page controlled by the attacker in order to deceive the victim. This deception can range from making…
- CVE-2025-6557MEDIUMCVSS 5.4EG 5.42025-06-24
Insufficient data validation in DevTools in Google Chrome on Windows prior to 138.0.7204.49 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium secur…
- CVE-2025-65922MEDIUMCVSS 4.3EG 4.32026-01-05
PLANKA 2.0.0 lacks X-Frame-Options and CSP frame-ancestors headers, allowing the application to be embedded within malicious iframes. While this does not lead to unintended modification of projects or tasks, it exposes users to Phishing at…
- CVE-2025-6983MEDIUMCVSS 5.1EG 5.12025-07-16
A Clickjacking vulnerability in TP-Link Archer C1200 web management page allows an attacker to trick users into performing unintended actions via rendered UI layers or frames.This issue affects Archer C1200 <= 1.1.5.
- CVE-2025-7903MEDIUMCVSS 5.4EG 5.42025-07-20
A vulnerability classified as problematic was found in yangzongzhuan RuoYi up to 4.8.1. Affected by this vulnerability is an unknown functionality of the component Image Source Handler. The manipulation leads to improper restriction of ren…
- CVE-2025-9108MEDIUMCVSS 4.3EG 4.32025-08-18
Affected is an unknown function of the component Login Page. The manipulation leads to improper restriction of rendered ui layers. It is possible to launch the attack remotely.
- CVE-2026-0007HIGHCVSS 8.6EG 8.62026-03-02
In writeToParcel of WindowInfo.cpp, there is a possible way to trick a user into accepting a permission due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. Us…
- CVE-2026-0036HIGHCVSS 7.8EG 7.82026-06-01
In startAnimation of StageCoordinator.java, there is a possible tapjacking issue due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not n…
- CVE-2026-0061MEDIUMCVSS 5.9EG 5.92026-06-01
In multiple functions of WindowState.java, there is a possible way to trick a user into accepting a permission due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges nee…
- CVE-2026-10733MEDIUMCVSS 4.3EG 4.32026-06-11
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.0 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that could have allowed an authenticated user to cause denial of service on the CI/CD Catalog page…
- CVE-2026-12322MEDIUMCVSS 5.4EG 5.42026-06-16
Clickjacking issue in the Widget: Gtk component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.
- CVE-2026-12323MEDIUMCVSS 5.4EG 5.42026-06-16
Spoofing issue in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.
- CVE-2026-12348HIGHCVSS 7.4EG 7.42026-06-17
Address bar spoofing in Arc Search for Android allows a remote attacker to display a trusted domain in the address bar while rendering attacker-controlled content, enabling phishing.
- CVE-2026-14110MEDIUMCVSS 4.3EG 4.32026-07-01
Inappropriate implementation in DarkMode in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
- CVE-2026-14142MEDIUMCVSS 5.4EG 5.42026-07-01
Inappropriate implementation in Extensions in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
- CVE-2026-16397MEDIUMCVSS 6.5EG 6.52026-07-21
Clickjacking issue in the WebExtensions component in Firefox for Android. This vulnerability was fixed in Firefox 153.
- CVE-2026-20645MEDIUMCVSS 4.6EG 4.62026-02-11
An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3. An attacker with physical access to a locked device may be able to view sensi…
- CVE-2026-21785MEDIUMCVSS 4.0EG 4.02026-05-27
A misconfigured Content Security Policy (CSP) in HCL BigFix Remote Control Server WebUI (versions 10.1.0.0442 and earlier) fails to define directives without fallbacks, allowing attackers to bypass intended security restrictions and load u…
- CVE-2026-22918MEDIUMCVSS 8.2EG 4.32026-01-15
An attacker may exploit missing protection against clickjacking by tricking users into performing unintended actions through maliciously crafted web pages, leading to the extraction of sensitive data.
- CVE-2026-23731MEDIUMCVSS 4.3EG 4.32026-01-16
WeGIA is a web manager for charitable institutions. Prior to 3.6.2, The web application is vulnerable to clickjacking attacks. The WeGIA application does not send any defensive HTTP headers related to framing protection. In particular, X-F…
- CVE-2026-2378HIGHCVSS 6.5EG 7.42026-03-20
ArcSearch for Android versions prior to 1.12.7 could display a different domain in the address bar than the content being shown, enabling address bar spoofing after user interaction via crafted web content.
- CVE-2026-24839MEDIUMCVSS 6.1EG 4.72026-01-28
Dokploy is a free, self-hostable Platform as a Service (PaaS). In versions prior to 0.26.6, the Dokploy web interface is vulnerable to Clickjacking attacks due to missing frame-busting headers. This allows attackers to embed Dokploy pages …
- CVE-2026-25681MEDIUMCVSS 6.1EG 6.12026-05-26
Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.
- CVE-2026-26000MEDIUMCVSS 6.1EG 6.12026-02-12
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Prior to 17.9.0, 17.4.6, and 16.10.13, it's possible using comments to inject CSS that would transform the full wiki in a link area le…
- CVE-2026-27136MEDIUMCVSS 6.1EG 6.12026-05-26
Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.
- CVE-2026-27511MEDIUMCVSS 4.3EG 4.32026-02-23
Shenzhen Tenda F3 Wireless Router firmware V12.01.01.55_multi contains a clickjacking vulnerability in the web-based administrative interface. The interface does not set the X-Frame-Options header, allowing attacker-controlled sites to em…
- CVE-2026-28577HIGHCVSS 7.8EG 7.82026-06-01
In addWindow of WindowManagerService.java, there is a possible tapjacking issue due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not ne…
- CVE-2026-28971MEDIUMCVSS 4.3EG 4.32026-05-11
The issue was addressed with improved UI handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, visionOS 26.5. A malicious iframe may use another website’s download settings.
- CVE-2026-3254LOWCVSS 3.5EG 3.52026-04-22
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.11 before 18.11.1 that under certain conditions could have allowed an authenticated user to load unauthorized content into another user's browser due to improper…
- CVE-2026-37470HIGHCVSS 7.3EG 7.32026-05-26
An issue in ClipBucket v5 v.5.5.2 allows an attacker to execute arbitrary code via the Authentication interface, login page endpoint and HTTP response security headers components
- CVE-2026-38979MEDIUMCVSS 5.4EG 5.42026-07-06
ajenti through v2.2.13 has a clickjacking weakness in the browser-facing login and administrative UI. In ajenti-core/aj/http.py, the core HTTP response path initializes an empty header list, forwards handler-added headers verbatim, and fin…
- CVE-2026-40957HIGHCVSS 7.5EG 7.52026-07-15
o CVE-2026-40957 is a frameable content vulnerability in the Secure Access server login page prior to 14.55. Attackers with control of a malicious web site could use it to potentially steal credentials from an unwary administrator.
- CVE-2026-42502MEDIUMCVSS 6.1EG 6.12026-05-26
Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.
- CVE-2026-44727MEDIUMCVSS 5.4EG 5.42026-06-18
Jupyter Server is the backend for Jupyter web applications. Prior to 2.20, the nbconvert HTTP handlers in jupyter_server render user-authored notebook HTML under the Jupyter origin without a sandbox directive in their Content-Security-Poli…
- CVE-2026-47723HIGHCVSS 7.1EG 7.12026-06-08
nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.1, none of the response paths in `internal/web/` or `internal/api/` set the standard browser-security headers. `grep` for `Conte…
- CVE-2026-58595HIGHCVSS 8.1EG 8.12026-07-14
Improper restriction of rendered ui layers or frames in Microsoft Bing App for IOS allows an unauthorized attacker to perform spoofing over a network.
- CVE-2026-59791LOWCVSS 3.5EG 3.52026-07-10
In JetBrains YouTrack before 2026.2.17012 cSS injection via Mermaid diagram rendering was possible
- CVE-2026-60370HIGHCVSS 7.5EG 7.52026-07-22
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability a…
- CVE-2026-8022LOWCVSS 3.1EG 3.12026-05-06
Inappropriate implementation in MHTML in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted MHTML page. (Chromium security severity:…
Map vulnerabilities like CWE-1021 to your infrastructure
EchelonGraph correlates every CVE — across CWE-1021 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →