VYPR

CWE-1021

Improper Restriction of Rendered UI Layers or Frames

BaseIncomplete

Description

The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain.

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-103 · CAPEC-181 · CAPEC-222 · CAPEC-504 · CAPEC-506 · CAPEC-587 · CAPEC-654

CVEs mapped to this weakness (406)

page 16 of 21
  • CVE-2025-24310MedApr 4, 2025
    risk 0.28cvss 4.3epss 0.00

    Improper restriction of rendered UI layers or frames issue exists in HMI ViewJet C-more series, which may allow a remote unauthenticated attacker to trick the product user to perform operations on the product's web pages.

  • CVE-2025-1923MedMar 5, 2025
    risk 0.28cvss 4.3epss 0.00

    Inappropriate implementation in Permission Prompts in Google Chrome prior to 134.0.6998.35 allowed an attacker who convinced a user to install a malicious extension to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Low)

  • CVE-2025-1917MedMar 5, 2025
    risk 0.28cvss 4.3epss 0.00

    Inappropriate implementation in Browser UI in Google Chrome on Android prior to 134.0.6998.35 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2025-1019MedFeb 4, 2025
    risk 0.28cvss 4.3epss 0.00

    The z-order of the browser windows could be manipulated to hide the fullscreen notification. This could potentially be leveraged to perform a spoofing attack. This vulnerability was fixed in Firefox 135 and Thunderbird 135.

  • CVE-2023-42011MedJun 27, 2024
    risk 0.28cvss 4.3epss 0.00

    IBM Sterling B2B Integrator Standard Edition 6.1 and 6.2 does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain, which can lead to user confusion about which interface the user is interacting with. IBM X-Force ID: …

  • CVE-2023-47774MedApr 24, 2024
    risk 0.28cvss 5.4epss 0.00

    Improper Restriction of Rendered UI Layers or Frames vulnerability in Automattic Jetpack allows Clickjacking.This issue affects Jetpack: from n/a before 12.7.

  • CVE-2024-29981MedApr 4, 2024
    risk 0.28cvss 4.3epss 0.01

    Microsoft Edge (Chromium-based) Spoofing Vulnerability

  • CVE-2024-26167MedMar 7, 2024
    risk 0.28cvss 4.3epss 0.01

    Microsoft Edge for Android Spoofing Vulnerability

  • CVE-2023-2265MedNov 30, 2023
    risk 0.28cvss 4.3epss 0.00

    An Improper Restriction of Rendered UI Layers or Frames in the Schweitzer Engineering Laboratories SEL-411L could allow an unauthenticated attacker to perform clickjacking based attacks against an authenticated and authorized user. See product Instruction Manual Appendix A…

  • CVE-2023-5721MedOct 25, 2023
    risk 0.28cvss 4.3epss 0.01

    It was possible for certain browser prompts and dialogs to be activated or dismissed unintentionally by the user due to an insufficient activation-delay. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.

  • CVE-2023-5103MedOct 9, 2023
    risk 0.28cvss 4.3epss 0.00

    Improper Restriction of Rendered UI Layers or Frames in RDT400 in SICK APU allows an unprivileged remote attacker to potentially reveal sensitive information via tricking a user into clicking on an actionable item using an iframe.

  • CVE-2023-4229MedAug 24, 2023
    risk 0.28cvss 4.3epss 0.00

    A vulnerability has been identified in ioLogik 4000 Series (ioLogik E4200) firmware versions v1.6 and prior, potentially exposing users to security risks. This vulnerability may allow attackers to trick users into interacting with malicious content, leading to unintended actions…

  • CVE-2023-3140MedJun 7, 2023
    risk 0.28cvss 4.3epss 0.00

    Missing HTTP headers (X-Frame-Options, Content-Security-Policy) in KNIME Business Hub before 1.4.0 has left users vulnerable to click jacking. Clickjacking is an attack that occurs when an attacker uses a transparent iframe in a window to trick a user into clicking on an …

  • CVE-2023-28159MedJun 2, 2023
    risk 0.28cvss 4.3epss 0.00

    The fullscreen notification could have been hidden on Firefox for Android by using download popups, resulting in potential user confusion or spoofing attacks. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects…

  • CVE-2023-25748MedJun 2, 2023
    risk 0.28cvss 4.3epss 0.00

    By displaying a prompt with a long description, the fullscreen notification could have been hidden, resulting in potential user confusion or spoofing attacks. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects…

  • CVE-2023-0780MedFeb 11, 2023
    risk 0.28cvss 5.4epss 0.00

    Improper Restriction of Rendered UI Layers or Frames in GitHub repository cockpit-hq/cockpit prior to 2.3.9-dev.

  • CVE-2022-45417MedDec 22, 2022
    risk 0.28cvss 4.3epss 0.00

    Service Workers did not detect Private Browsing Mode correctly in all cases, which could have led to Service Workers being written to disk for websites visited in Private Browsing Mode. This would not have persisted them in a state where they would run again, but it would have…

  • CVE-2022-3034MedDec 22, 2022
    risk 0.28cvss 4.3epss 0.01

    When receiving an HTML email that specified to load an iframe element from a remote location, a request to the remote document was sent. However, Thunderbird didn't display the document. This vulnerability affects Thunderbird < 102.2.1 and Thunderbird < 91.13.1.

  • CVE-2022-2800MedAug 12, 2022
    risk 0.28cvss 4.3epss 0.01

    A vulnerability, which was classified as problematic, has been found in SourceCodester Gym Management System. Affected by this issue is some unknown functionality. The manipulation leads to clickjacking. The attack may be launched remotely. The exploit has been disclosed to the…

  • CVE-2022-28889MedJul 7, 2022
    risk 0.28cvss 4.3epss 0.02

    In Apache Druid 0.22.1 and earlier, the server did not set appropriate headers to prevent clickjacking. Druid 0.23.0 and later prevent clickjacking using the Content-Security-Policy header.