VYPR

CWE-1021

Improper Restriction of Rendered UI Layers or Frames

BaseIncomplete

Description

The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain.

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-103 · CAPEC-181 · CAPEC-222 · CAPEC-504 · CAPEC-506 · CAPEC-587 · CAPEC-654

CVEs mapped to this weakness (406)

page 18 of 21
  • CVE-2020-7371MedOct 20, 2020
    risk 0.28cvss 4.3epss 0.01

    User Interface (UI) Misrepresentation of Critical Information vulnerability in the address bar of the Yandex Browser allows an attacker to obfuscate the true source of data as presented in the browser. This issue affects the RITS Browser version 3.3.9 and prior versions.

  • CVE-2019-4323MedJul 7, 2020
    risk 0.28cvss 4.3epss 0.01

    "HCL AppScan Enterprise advisory API documentation is susceptible to clickjacking, which could allow an attacker to embed the contents of untrusted web pages in a frame."

  • CVE-2020-4322MedJun 24, 2020
    risk 0.28cvss 4.3epss 0.01

    IBM Security Secret Server 10.7 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further…

  • CVE-2013-5594MedFeb 18, 2020
    risk 0.28cvss 4.3epss 0.01

    Mozilla Firefox before 25 allows modification of anonymous content of pluginProblem.xml binding

  • CVE-2020-2105MedJan 29, 2020
    risk 0.28cvss 5.4epss 0.02

    REST API endpoints in Jenkins 2.218 and earlier, LTS 2.204.1 and earlier were vulnerable to clickjacking attacks.

  • CVE-2013-6772MedJan 23, 2020
    risk 0.28cvss 4.3epss 0.01

    Splunk before 5.0.4 lacks X-Frame-Options which can allow Clickjacking

  • CVE-2019-15930MedDec 12, 2019
    risk 0.28cvss 4.3epss 0.01

    Intesync Solismed 3.3sp allows Clickjacking.

  • CVE-2019-5861MedNov 25, 2019
    risk 0.28cvss 4.3epss 0.01

    Insufficient data validation in Blink in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to bypass anti-clickjacking policy via a crafted HTML page.

  • CVE-2019-17131MedOct 4, 2019
    risk 0.28cvss 4.3epss 0.01

    vBulletin before 5.5.4 allows clickjacking.

  • CVE-2019-9147MedJul 9, 2019
    risk 0.28cvss 4.3epss 0.01

    Mailvelope prior to 3.1.0 is vulnerable to a clickjacking attack against the settings page. As the settings page is intended to be accessible from web applications, the browser's extension isolation mechanisms are disabled (web_accessible_resources). Mailvelope implements…

  • CVE-2019-12880MedJun 24, 2019
    risk 0.28cvss 4.3epss 0.01

    BCN Quark Quarking Password Manager 3.1.84 suffers from a clickjacking vulnerability caused by allowing * within web_accessible_resources. An attacker can take advantage of this vulnerability and cause significant harm.

  • CVE-2019-0305MedJun 12, 2019
    risk 0.28cvss 4.3epss 0.01

    Java Server Pages (JSPs) provided by the SAP NetWeaver Process Integration (SAP_XIESR and SAP_XITOOL: 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50) do not restrict or incorrectly restrict frame objects or UI layers that belong to another application or domain, resulting in…

  • CVE-2019-5243MedJun 10, 2019
    risk 0.28cvss 4.3epss 0.01

    There is a Clickjacking vulnerability in Huawei HG255s product. An attacker may trick user to click a link and affect the integrity of a device by exploiting this vulnerability.

  • CVE-2019-7393MedMay 28, 2019
    risk 0.28cvss 4.3epss 0.02

    A UI redress vulnerability in the administrative user interface of CA Technologies CA Strong Authentication 9.0.x, 8.2.x, 8.1.x, 8.0.x, 7.1.x and CA Risk Authentication 9.0.x, 8.2.x, 8.1.x, 8.0.x, 3.1.x may allow a remote attacker to gain sensitive information in some cases.

  • CVE-2018-6178MedJan 9, 2019
    risk 0.28cvss 4.3epss 0.01

    Eliding from the wrong side in an infobar in DevTools in Google Chrome prior to 68.0.3440.75 allowed an attacker who convinced a user to install a malicious extension to Hide Chrome Security UI via a crafted Chrome Extension.

  • CVE-2018-12576MedJul 2, 2018
    risk 0.28cvss 4.3epss 0.01

    TP-Link TL-WR841N v13 00000001 0.9.1 4.16 v0001.0 Build 180119 Rel.65243n devices allow clickjacking.

  • CVE-2017-5026MedFeb 17, 2017
    risk 0.28cvss 4.3epss 0.01

    Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, failed to prevent alerts from being displayed by swapped out frames, which allowed a remote attacker to show alerts on a page they don't control via a crafted HTML page.

  • CVE-2025-49139MedJun 9, 2025
    risk 0.27cvss 5.3epss 0.00

    HAX CMS PHP allows users to manage their microsite universe with a PHP backend. Prior to version 11.0.0, in the HAX site editor, users can create a website block to load another site in an iframe. The application allows users to supply a target URL in the website block. When the…

  • CVE-2021-27773MedMay 12, 2022
    risk 0.27cvss 4.2epss 0.00

    This vulnerability allows users to execute a clickjacking attack in the meeting's chat.

  • CVE-2026-21785MedMay 27, 2026
    risk 0.26cvss 4.0epss 0.00

    A misconfigured Content Security Policy (CSP) in HCL BigFix Remote Control Server WebUI (versions 10.1.0.0442 and earlier) fails to define directives without fallbacks, allowing attackers to bypass intended security restrictions and load unauthorized resources.