VYPR

CWE-1021

Improper Restriction of Rendered UI Layers or Frames

BaseIncomplete

Description

The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain.

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-103 · CAPEC-181 · CAPEC-222 · CAPEC-504 · CAPEC-506 · CAPEC-587 · CAPEC-654

CVEs mapped to this weakness (406)

page 14 of 21
  • CVE-2025-59849MedDec 17, 2025
    risk 0.31cvss 4.7epss 0.00

    Improper management of Content Security Policy in HCL BigFix Remote Control Lite Web Portal (versions 10.1.0.0326 and lower) may allow the execution of malicious code in web pages.

  • CVE-2025-0421MedNov 19, 2025
    risk 0.31cvss 4.7epss 0.00

    Improper Restriction of Rendered UI Layers or Frames vulnerability in Shopside Software Technologies Inc. Shopside allows iFrame Overlay. This issue affects Shopside: through 05022025.

  • CVE-2025-0546MedSep 17, 2025
    risk 0.31cvss 4.7epss 0.00

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting'), Improper Restriction of Rendered UI Layers or Frames vulnerability in Mevzuattr Software MevzuatTR allows Phishing, iFrame Overlay, Clickjacking, Forceful Browsing. This issue needs high…

  • CVE-2025-49191MedJun 12, 2025
    risk 0.31cvss 4.8epss 0.00

    Linked URLs during the creation of iFrame widgets and dashboards are vulnerable to code execution. The URLs get embedded as iFrame widgets, making it possible to attack other users that access the dashboard by including malicious code. The attack is only possible if the attacker…

  • CVE-2023-7013MedJul 16, 2024
    risk 0.31cvss 4.7epss 0.00

    Inappropriate implementation in Compositing in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to potentially spoof security UI via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2023-45698MedFeb 10, 2024
    risk 0.31cvss 4.8epss 0.00

    Sametime is impacted by lack of clickjacking protection in Outlook add-in. The application is not implementing appropriate protections in order to protect users from clickjacking attacks.

  • CVE-2022-32919MedJan 10, 2024
    risk 0.31cvss 4.7epss 0.01

    The issue was addressed with improved UI handling. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1. Visiting a website that frames malicious content may lead to UI spoofing.

  • CVE-2022-20214MedJan 26, 2023
    risk 0.31cvss 4.7epss 0.00

    In Car Settings app, the toggle button in Modify system settings is vulnerable to tapjacking attack. Attackers can overlay the toggle button to enable apps to modify system settings without user consent.Product: AndroidVersions: Android-10 Android-11 Android-12Android ID:…

  • CVE-2022-3260MedDec 8, 2022
    risk 0.31cvss 4.8epss 0.00

    The response header has not enabled X-FRAME-OPTIONS, Which helps prevents against Clickjacking attack.. Some browsers would interpret these results incorrectly, allowing clickjacking attacks.

  • CVE-2022-33727MedAug 5, 2022
    risk 0.31cvss 4.8epss 0.00

    A vulnerable code in onCreate of SecDevicePickerDialog prior to SMR Aug-2022 Release 1, allows attackers to trick the user to select an unwanted bluetooth device via tapjacking/overlay attack.

  • CVE-2022-33723MedAug 5, 2022
    risk 0.31cvss 4.8epss 0.00

    A vulnerable code in onCreate of BluetoothScanDialog prior to SMR Aug-2022 Release 1, allows attackers to trick the user to select an unwanted bluetooth device via tapjacking/overlay attack.

  • CVE-2021-38472MedOct 19, 2021
    risk 0.31cvss 4.7epss 0.01

    InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 management portal does not contain an X-FRAME-OPTIONS header, which an attacker may take advantage of by sending a link to an administrator that frames the router’s management portal and could lure the…

  • CVE-2021-27003MedOct 12, 2021
    risk 0.31cvss 4.7epss 0.01

    Clustered Data ONTAP versions prior to 9.5P18, 9.6P15, 9.7P14, 9.8P5 and 9.9.1 are missing an X-Frame-Options header which could allow a clickjacking attack.

  • CVE-2020-35735MedDec 29, 2020
    risk 0.31cvss 4.7epss 0.01

    Vidyo 02-09-/D allows clickjacking via the portal/ URI.

  • CVE-2020-6827MedApr 24, 2020
    risk 0.31cvss 4.7epss 0.01

    When following a link that opened an intent://-schemed URL, causing a custom tab to be opened, Firefox for Android could be tricked into displaying the incorrect URI. *Note: This issue only affects Firefox for Android. Other operating systems are unaffected.*. This…

  • CVE-2020-10951MedApr 15, 2020
    risk 0.31cvss 4.7epss 0.01

    Western Digital My Cloud Home and ibi devices before 2.2.0 allow clickjacking on sign-in pages.

  • CVE-2020-1728MedApr 6, 2020
    risk 0.31cvss 4.8epss 0.01

    A vulnerability was found in all versions of Keycloak where, the pages on the Admin Console area of the application are completely missing general HTTP security headers in HTTP-responses. This does not directly lead to a security issue, yet it might aid attackers in their…

  • CVE-2013-2682MedFeb 5, 2020
    risk 0.31cvss 4.3epss 0.06

    Cisco Linksys E4200 1.0.05 Build 7 devices contain a Clickjacking Vulnerability which allows remote attackers to obtain sensitive information.

  • CVE-2018-15423MedOct 5, 2018
    risk 0.31cvss 4.7epss 0.01

    A vulnerability in the web UI of Cisco HyperFlex Software could allow an unauthenticated, remote attacker to affect the integrity of a device via a clickjacking attack. The vulnerability is due to insufficient input validation of iFrame data in HTTP requests that are sent to an…

  • CVE-2026-20645MedFeb 11, 2026
    risk 0.30cvss 4.6epss 0.00

    An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3. An attacker with physical access to a locked device may be able to view sensitive user information.