CWE-1021
Improper Restriction of Rendered UI Layers or Frames
Description
The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-103 · CAPEC-181 · CAPEC-222 · CAPEC-504 · CAPEC-506 · CAPEC-587 · CAPEC-654
CVEs mapped to this weakness (406)
page 18 of 21| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-7371 | Med | 0.28 | 4.3 | 0.01 | Oct 20, 2020 | User Interface (UI) Misrepresentation of Critical Information vulnerability in the address bar of the Yandex Browser allows an attacker to obfuscate the true source of data as presented in the browser. This issue affects the RITS Browser version 3.3.9 and prior versions. | ||
| CVE-2019-4323 | Med | 0.28 | 4.3 | 0.01 | Jul 7, 2020 | "HCL AppScan Enterprise advisory API documentation is susceptible to clickjacking, which could allow an attacker to embed the contents of untrusted web pages in a frame." | ||
| CVE-2020-4322 | Med | 0.28 | 4.3 | 0.01 | Jun 24, 2020 | IBM Security Secret Server 10.7 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further… | ||
| CVE-2013-5594 | Med | 0.28 | 4.3 | 0.01 | Feb 18, 2020 | Mozilla Firefox before 25 allows modification of anonymous content of pluginProblem.xml binding | ||
| CVE-2020-2105 | Med | 0.28 | 5.4 | 0.02 | Jan 29, 2020 | REST API endpoints in Jenkins 2.218 and earlier, LTS 2.204.1 and earlier were vulnerable to clickjacking attacks. | ||
| CVE-2013-6772 | Med | 0.28 | 4.3 | 0.01 | Jan 23, 2020 | Splunk before 5.0.4 lacks X-Frame-Options which can allow Clickjacking | ||
| CVE-2019-15930 | Med | 0.28 | 4.3 | 0.01 | Dec 12, 2019 | Intesync Solismed 3.3sp allows Clickjacking. | ||
| CVE-2019-5861 | Med | 0.28 | 4.3 | 0.01 | Nov 25, 2019 | Insufficient data validation in Blink in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to bypass anti-clickjacking policy via a crafted HTML page. | ||
| CVE-2019-17131 | Med | 0.28 | 4.3 | 0.01 | Oct 4, 2019 | vBulletin before 5.5.4 allows clickjacking. | ||
| CVE-2019-9147 | Med | 0.28 | 4.3 | 0.01 | Jul 9, 2019 | Mailvelope prior to 3.1.0 is vulnerable to a clickjacking attack against the settings page. As the settings page is intended to be accessible from web applications, the browser's extension isolation mechanisms are disabled (web_accessible_resources). Mailvelope implements… | ||
| CVE-2019-12880 | Med | 0.28 | 4.3 | 0.01 | Jun 24, 2019 | BCN Quark Quarking Password Manager 3.1.84 suffers from a clickjacking vulnerability caused by allowing * within web_accessible_resources. An attacker can take advantage of this vulnerability and cause significant harm. | ||
| CVE-2019-0305 | Med | 0.28 | 4.3 | 0.01 | Jun 12, 2019 | Java Server Pages (JSPs) provided by the SAP NetWeaver Process Integration (SAP_XIESR and SAP_XITOOL: 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50) do not restrict or incorrectly restrict frame objects or UI layers that belong to another application or domain, resulting in… | ||
| CVE-2019-5243 | Med | 0.28 | 4.3 | 0.01 | Jun 10, 2019 | There is a Clickjacking vulnerability in Huawei HG255s product. An attacker may trick user to click a link and affect the integrity of a device by exploiting this vulnerability. | ||
| CVE-2019-7393 | Med | 0.28 | 4.3 | 0.02 | May 28, 2019 | A UI redress vulnerability in the administrative user interface of CA Technologies CA Strong Authentication 9.0.x, 8.2.x, 8.1.x, 8.0.x, 7.1.x and CA Risk Authentication 9.0.x, 8.2.x, 8.1.x, 8.0.x, 3.1.x may allow a remote attacker to gain sensitive information in some cases. | ||
| CVE-2018-6178 | Med | 0.28 | 4.3 | 0.01 | Jan 9, 2019 | Eliding from the wrong side in an infobar in DevTools in Google Chrome prior to 68.0.3440.75 allowed an attacker who convinced a user to install a malicious extension to Hide Chrome Security UI via a crafted Chrome Extension. | ||
| CVE-2018-12576 | Med | 0.28 | 4.3 | 0.01 | Jul 2, 2018 | TP-Link TL-WR841N v13 00000001 0.9.1 4.16 v0001.0 Build 180119 Rel.65243n devices allow clickjacking. | ||
| CVE-2017-5026 | Med | 0.28 | 4.3 | 0.01 | Feb 17, 2017 | Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, failed to prevent alerts from being displayed by swapped out frames, which allowed a remote attacker to show alerts on a page they don't control via a crafted HTML page. | ||
| CVE-2025-49139 | Med | 0.27 | 5.3 | 0.00 | Jun 9, 2025 | HAX CMS PHP allows users to manage their microsite universe with a PHP backend. Prior to version 11.0.0, in the HAX site editor, users can create a website block to load another site in an iframe. The application allows users to supply a target URL in the website block. When the… | ||
| CVE-2021-27773 | Med | 0.27 | 4.2 | 0.00 | May 12, 2022 | This vulnerability allows users to execute a clickjacking attack in the meeting's chat. | ||
| CVE-2026-21785 | Med | 0.26 | 4.0 | 0.00 | May 27, 2026 | A misconfigured Content Security Policy (CSP) in HCL BigFix Remote Control Server WebUI (versions 10.1.0.0442 and earlier) fails to define directives without fallbacks, allowing attackers to bypass intended security restrictions and load unauthorized resources. |
- risk 0.28cvss 4.3epss 0.01
User Interface (UI) Misrepresentation of Critical Information vulnerability in the address bar of the Yandex Browser allows an attacker to obfuscate the true source of data as presented in the browser. This issue affects the RITS Browser version 3.3.9 and prior versions.
- risk 0.28cvss 4.3epss 0.01
"HCL AppScan Enterprise advisory API documentation is susceptible to clickjacking, which could allow an attacker to embed the contents of untrusted web pages in a frame."
- risk 0.28cvss 4.3epss 0.01
IBM Security Secret Server 10.7 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further…
- risk 0.28cvss 4.3epss 0.01
Mozilla Firefox before 25 allows modification of anonymous content of pluginProblem.xml binding
- risk 0.28cvss 5.4epss 0.02
REST API endpoints in Jenkins 2.218 and earlier, LTS 2.204.1 and earlier were vulnerable to clickjacking attacks.
- risk 0.28cvss 4.3epss 0.01
Splunk before 5.0.4 lacks X-Frame-Options which can allow Clickjacking
- risk 0.28cvss 4.3epss 0.01
Intesync Solismed 3.3sp allows Clickjacking.
- risk 0.28cvss 4.3epss 0.01
Insufficient data validation in Blink in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to bypass anti-clickjacking policy via a crafted HTML page.
- risk 0.28cvss 4.3epss 0.01
vBulletin before 5.5.4 allows clickjacking.
- risk 0.28cvss 4.3epss 0.01
Mailvelope prior to 3.1.0 is vulnerable to a clickjacking attack against the settings page. As the settings page is intended to be accessible from web applications, the browser's extension isolation mechanisms are disabled (web_accessible_resources). Mailvelope implements…
- risk 0.28cvss 4.3epss 0.01
BCN Quark Quarking Password Manager 3.1.84 suffers from a clickjacking vulnerability caused by allowing * within web_accessible_resources. An attacker can take advantage of this vulnerability and cause significant harm.
- risk 0.28cvss 4.3epss 0.01
Java Server Pages (JSPs) provided by the SAP NetWeaver Process Integration (SAP_XIESR and SAP_XITOOL: 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50) do not restrict or incorrectly restrict frame objects or UI layers that belong to another application or domain, resulting in…
- risk 0.28cvss 4.3epss 0.01
There is a Clickjacking vulnerability in Huawei HG255s product. An attacker may trick user to click a link and affect the integrity of a device by exploiting this vulnerability.
- risk 0.28cvss 4.3epss 0.02
A UI redress vulnerability in the administrative user interface of CA Technologies CA Strong Authentication 9.0.x, 8.2.x, 8.1.x, 8.0.x, 7.1.x and CA Risk Authentication 9.0.x, 8.2.x, 8.1.x, 8.0.x, 3.1.x may allow a remote attacker to gain sensitive information in some cases.
- risk 0.28cvss 4.3epss 0.01
Eliding from the wrong side in an infobar in DevTools in Google Chrome prior to 68.0.3440.75 allowed an attacker who convinced a user to install a malicious extension to Hide Chrome Security UI via a crafted Chrome Extension.
- risk 0.28cvss 4.3epss 0.01
TP-Link TL-WR841N v13 00000001 0.9.1 4.16 v0001.0 Build 180119 Rel.65243n devices allow clickjacking.
- risk 0.28cvss 4.3epss 0.01
Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, failed to prevent alerts from being displayed by swapped out frames, which allowed a remote attacker to show alerts on a page they don't control via a crafted HTML page.
- risk 0.27cvss 5.3epss 0.00
HAX CMS PHP allows users to manage their microsite universe with a PHP backend. Prior to version 11.0.0, in the HAX site editor, users can create a website block to load another site in an iframe. The application allows users to supply a target URL in the website block. When the…
- risk 0.27cvss 4.2epss 0.00
This vulnerability allows users to execute a clickjacking attack in the meeting's chat.
- risk 0.26cvss 4.0epss 0.00
A misconfigured Content Security Policy (CSP) in HCL BigFix Remote Control Server WebUI (versions 10.1.0.0442 and earlier) fails to define directives without fallbacks, allowing attackers to bypass intended security restrictions and load unauthorized resources.