VYPR

CWE-1021

Improper Restriction of Rendered UI Layers or Frames

BaseIncomplete

Description

The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain.

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-103 · CAPEC-181 · CAPEC-222 · CAPEC-504 · CAPEC-506 · CAPEC-587 · CAPEC-654

CVEs mapped to this weakness (406)

page 15 of 21
  • CVE-2025-63522MedDec 1, 2025
    risk 0.30cvss 4.6epss 0.00

    Reverse Tabnabbing vulnerability in FeehiCMS 2.1.1 in the Comments Management function

  • CVE-2022-28649MedApr 5, 2022
    risk 0.30cvss 4.6epss 0.00

    In JetBrains YouTrack before 2022.1.43563 it was possible to include an iframe from a third-party domain in the issue description

  • CVE-2016-5710MedFeb 11, 2020
    risk 0.30cvss 4.6epss 0.01

    NetApp Snap Creator Framework before 4.3P1 allows remote authenticated users to conduct clickjacking attacks via unspecified vectors.

  • CVE-2025-31138MedApr 7, 2025
    risk 0.29cvss 5.5epss 0.00

    tarteaucitron.js is a compliant and accessible cookie banner. A vulnerability was identified in tarteaucitron.js prior to 1.20.1, where user-controlled inputs for element dimensions (width and height) were not properly validated. This allowed an attacker with direct access to…

  • CVE-2021-1006MedDec 15, 2021
    risk 0.29cvss 4.4epss 0.00

    In several functions of DatabaseManager.java, there is a possible leak of Bluetooth MAC addresses due to log information disclosure. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2017-4015MedMay 17, 2017
    risk 0.29cvss 4.5epss 0.01

    Clickjacking vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote authenticated users to inject arbitrary web script or HTML via HTTP response header.

  • CVE-2026-14110MedJun 30, 2026
    risk 0.28cvss 4.3epss 0.00

    Inappropriate implementation in DarkMode in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-44727MedJun 22, 2026
    risk 0.28cvss 5.4epss 0.00

    Jupyter Server is the backend for Jupyter web applications. Prior to 2.20, the nbconvert HTTP handlers in jupyter_server render user-authored notebook HTML under the Jupyter origin without a sandbox directive in their Content-Security-Policy. Combined with…

  • CVE-2026-10733MedJun 11, 2026
    risk 0.28cvss 4.3epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.0 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that could have allowed an authenticated user to cause denial of service on the CI/CD Catalog page due to improper sanitization.

  • CVE-2026-28971MedMay 11, 2026
    risk 0.28cvss 4.3epss 0.00

    The issue was addressed with improved UI handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, visionOS 26.5. A malicious iframe may use another website’s download settings.

  • CVE-2026-27511MedFeb 23, 2026
    risk 0.28cvss 4.3epss 0.00

    Shenzhen Tenda F3 Wireless Router firmware V12.01.01.55_multi contains a clickjacking vulnerability in the web-based administrative interface. The interface does not set the X-Frame-Options header, allowing attacker-controlled sites to embed administrative pages in an iframe…

  • CVE-2026-22918MedJan 15, 2026
    risk 0.28cvss 4.3epss 0.00

    An attacker may exploit missing protection against clickjacking by tricking users into performing unintended actions through maliciously crafted web pages, leading to the extraction of sensitive data.

  • CVE-2025-65922MedJan 5, 2026
    risk 0.28cvss 4.3epss 0.00

    PLANKA 2.0.0 lacks X-Frame-Options and CSP frame-ancestors headers, allowing the application to be embedded within malicious iframes. While this does not lead to unintended modification of projects or tasks, it exposes users to Phishing attacks. Attackers can frame the…

  • CVE-2025-14373MedDec 12, 2025
    risk 0.28cvss 4.3epss 0.00

    Inappropriate implementation in Toolbar in Google Chrome on Android prior to 143.0.7499.110 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2024-13066MedSep 3, 2025
    risk 0.28cvss 4.3epss 0.00

    Improper Restriction of Rendered UI Layers or Frames vulnerability in Akinsoft LimonDesk allows iFrame Overlay, CAPEC - 103 - Clickjacking. This issue affects LimonDesk: from s1.02.14 before v1.02.17.

  • CVE-2025-9108MedAug 18, 2025
    risk 0.28cvss 4.3epss 0.00

    Affected is an unknown function of the component Login Page. The manipulation leads to improper restriction of rendered ui layers. It is possible to launch the attack remotely.

  • CVE-2025-7903MedJul 20, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability classified as problematic was found in yangzongzhuan RuoYi up to 4.8.1. Affected by this vulnerability is an unknown functionality of the component Image Source Handler. The manipulation leads to improper restriction of rendered ui layers. The attack can be…

  • CVE-2025-27455MedJul 3, 2025
    risk 0.28cvss 4.3epss 0.00

    The web application is vulnerable to clickjacking attacks. The site can be embedded into another frame, allowing an attacker to trick a user into clicking on something different from what the user perceives, thus potentially revealing confidential information or allowing others…

  • CVE-2025-6434MedJun 24, 2025
    risk 0.28cvss 4.3epss 0.00

    The exception page for the HTTPS-Only feature, displayed when a website is opened via HTTP, lacked an anti-clickjacking delay, potentially allowing an attacker to trick a user into granting an exception and loading a webpage over HTTP. This vulnerability was fixed in Firefox 140…

  • CVE-2025-49192MedJun 12, 2025
    risk 0.28cvss 4.3epss 0.00

    The web application is vulnerable to clickjacking attacks. The site can be embedded into another frame, allowing an attacker to trick a user into clicking on something different from what the user perceives. This could potentially reveal confidential information or allow others…