CWE-1021— Improper Restriction of Rendered UI Layers or Frames (Clickjacking)
The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain.— MITRE CWE catalog
419 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-1021page 9 of 9
- CVE-2026-58595HIGHCVSS 8.1EG 8.12026-07-14
Improper restriction of rendered ui layers or frames in Microsoft Bing App for IOS allows an unauthorized attacker to perform spoofing over a network.
- CVE-2026-59791LOWCVSS 3.5EG 3.52026-07-10
In JetBrains YouTrack before 2026.2.17012 cSS injection via Mermaid diagram rendering was possible
- CVE-2026-60370HIGHCVSS 7.5EG 7.52026-07-22
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability a…
- CVE-2026-70486MEDIUMCVSS 5.4EG 5.42026-08-04
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, the terminal file-preview serveUrl iframe branch always granted allow-same-origin together with allow-scripts for HTML files ser…
- CVE-2026-70600LOWCVSS 3.1EG 3.12026-08-05
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, the native autofill popup could be positioned by a cross-origin iframe outside that…
- CVE-2026-70608HIGHCVSS 7.2EG 7.22026-08-05
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10, 41.10.3, and 42.0.1, a sandboxed iframe without the allow-popups keyword could still open a new window or trigger set…
- CVE-2026-74951MEDIUMCVSS 6.5EG 6.52026-08-18
Clickjacking issue in Firefox for Android. This vulnerability was fixed in Firefox 154.
- CVE-2026-74958HIGHCVSS 7.5EG 7.52026-08-18
Information disclosure in the WebRTC component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
- CVE-2026-74978HIGHCVSS 8.1EG 8.12026-08-18
Clickjacking issue in the Widget component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
- CVE-2026-74980MEDIUMCVSS 6.5EG 6.52026-08-18
Clickjacking issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 154.
- CVE-2026-75548MEDIUMCVSS 5.4EG 5.42026-08-27
The affected Ebyte device web management interface does not restrict the interface from being rendered within an external frame. An unauthenticated remote attacker could use a crafted webpage to mislead an authenticated administrator in…
- CVE-2026-8022LOWCVSS 3.1EG 3.12026-05-06
Inappropriate implementation in MHTML in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted MHTML page. (Chromium security severity:…
- CVE-2026-84139MEDIUMCVSS 6.1EG 6.12026-09-01
Clickjacking issue in the DOM: Events component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
- CVE-2026-86911MEDIUMCVSS 5.5EG 5.52026-09-14
This issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27. A malicious app may be able to bypass clickjacking protections for secure prompts.
- CVE-2026-87486MEDIUMCVSS 4.0EG 4.02026-09-09
Clickjacking in TrustedWebActivities in Google Chrome on on Android prior to 153.0.8010.36 allowed a local attacker to spoof address bar via a co-installed app. (Chromium security severity: Medium)
- CVE-2026-87538MEDIUMCVSS 4.2EG 4.22026-09-09
Clickjacking in Input in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Lo…
- CVE-2026-87655MEDIUMCVSS 5.4EG 5.42026-09-09
Clickjacking in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-87995HIGHCVSS 8.7EG 8.72026-09-09
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.11 until 0.11.1, src/lib/components/chat/FileNav/PortPreview.svelte rendered terminal port content in an iframe sandbox containing both allow-sc…
- CVE-2026-9396LOWCVSS 3.7EG 3.72026-05-24
A security flaw has been discovered in Besen BS20 EV Charging Station up to 20260426. Affected by this vulnerability is an unknown functionality of the component Firmware Version Check. The manipulation results in improper restriction of r…
Map vulnerabilities like CWE-1021 to your infrastructure
EchelonGraph correlates every CVE — across CWE-1021 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →