VYPR

CWE-1021

Improper Restriction of Rendered UI Layers or Frames

BaseIncomplete

Description

The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain.

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-103 · CAPEC-181 · CAPEC-222 · CAPEC-504 · CAPEC-506 · CAPEC-587 · CAPEC-654

CVEs mapped to this weakness (406)

page 20 of 21
  • CVE-2026-40957HigJul 15, 2026
    risk 0.00cvss 7.5epss 0.00

    o   CVE-2026-40957 is a frameable content vulnerability in the Secure Access server login page prior to 14.55. Attackers with control of a malicious web site could use it to potentially steal credentials from an unwary administrator.

  • CVE-2026-58595HigJul 14, 2026
    risk 0.00cvss 8.1epss 0.00

    Improper restriction of rendered ui layers or frames in Microsoft Bing App for IOS allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2026-59791LowJul 10, 2026
    risk 0.00cvss 3.5epss 0.00

    In JetBrains YouTrack before 2026.2.17012 cSS injection via Mermaid diagram rendering was possible

  • CVE-2026-38979MedJul 6, 2026
    risk 0.00cvss 5.4epss 0.00

    ajenti through v2.2.13 has a clickjacking weakness in the browser-facing login and administrative UI. In ajenti-core/aj/http.py, the core HTTP response path initializes an empty header list, forwards handler-added headers verbatim, and finalizes responses through WSGI…

  • CVE-2026-24839MedJan 28, 2026
    risk 0.00cvss 4.7epss 0.00

    Dokploy is a free, self-hostable Platform as a Service (PaaS). In versions prior to 0.26.6, the Dokploy web interface is vulnerable to Clickjacking attacks due to missing frame-busting headers. This allows attackers to embed Dokploy pages in malicious iframes and trick…

  • CVE-2026-23731MedJan 16, 2026
    risk 0.00cvss 4.3epss 0.00

    WeGIA is a web manager for charitable institutions. Prior to 3.6.2, The web application is vulnerable to clickjacking attacks. The WeGIA application does not send any defensive HTTP headers related to framing protection. In particular, X-Frame-Options is missing…

  • CVE-2025-59950MedSep 30, 2025
    risk 0.00cvss 6.7epss 0.00

    FreshRSS is a free, self-hostable RSS aggregator. In versions 1.26.3 and below, due to a bypass of double clickjacking protection (confirmation dialog), it is possible to trick the admin into clicking the Promote button in another user's management page after the admin double…

  • CVE-2025-57769MedSep 29, 2025
    risk 0.00cvss 6.1epss 0.00

    FreshRSS is a free, self-hostable RSS aggregator. Versions 1.26.3 and below contain a vulnerability where a specially crafted page can trick a user into executing arbitrary JS code or promoting a user in FreshRSS by obscuring UI elements in iframes. If embedding an authenticated…

  • CVE-2025-53096MedJul 1, 2025
    risk 0.00cvss 5.4epss 0.00

    Sunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.628.4510, the web UI of Sunshine lacks protection against Clickjacking attacks. This vulnerability allows an attacker to embed the Sunshine interface within a malicious website using an invisible or…

  • CVE-2025-43854MedApr 28, 2025
    risk 0.00cvss 6.1epss 0.00

    DIFY is an open-source LLM app development platform. Prior to version 1.3.0, a clickjacking vulnerability was found in the default setup of the DIFY application, allowing malicious actors to trick users into clicking on elements of the web page without their knowledge or…

  • CVE-2023-1362MedMar 13, 2023
    risk 0.00cvss 6.1epss 0.01

    Improper Restriction of Rendered UI Layers or Frames in GitHub repository unilogies/bumsys prior to v2.0.2.

  • CVE-2022-2965MedAug 23, 2022
    risk 0.00cvss 4.3epss 0.01

    Improper Restriction of Rendered UI Layers or Frames in GitHub repository notrinos/notrinoserp prior to 0.7.

  • CVE-2022-2734MedAug 9, 2022
    risk 0.00cvss 5.4epss 0.01

    Improper Restriction of Rendered UI Layers or Frames in GitHub repository openemr/openemr prior to 7.0.0.1.

  • CVE-2022-1803MedMay 20, 2022
    risk 0.00cvss 6.9epss 0.02

    Improper Restriction of Rendered UI Layers or Frames in GitHub repository polonel/trudesk prior to 1.2.2.

  • CVE-2021-3660MedMar 10, 2022
    risk 0.00cvss 4.3epss 0.01

    Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a cockpit server via another website, inside an HTML entry. This may be used by a malicious website in clickjacking or similar attacks.

  • CVE-2021-3799MedSep 27, 2021
    risk 0.00cvss 5.4epss 0.02

    grav-plugin-admin is vulnerable to Improper Restriction of Rendered UI Layers or Frames

  • CVE-2021-27375MedFeb 18, 2021
    risk 0.00cvss 5.3epss 0.01

    Traefik before 2.4.5 allows the loading of IFRAME elements from other domains.

  • CVE-2020-24711MedOct 28, 2020
    risk 0.00cvss 6.5epss 0.02

    The Reset button on the Account Settings page in Gophish before 0.11.0 allows attackers to cause a denial of service via a clickjacking attack

  • CVE-2019-16175MedSep 9, 2019
    risk 0.00cvss 4.3epss 0.01

    A clickjacking vulnerability was found in Limesurvey before 3.17.14.

  • CVE-2018-7491HigFeb 26, 2018
    risk 0.00cvss 7.5epss 0.01

    In PrestaShop through 1.7.2.5, a UI-Redressing/Clickjacking vulnerability was found that might lead to state-changing impact in the context of a user or an admin, because the generateHtaccess function in classes/Tools.php sets neither X-Frame-Options nor 'Content-Security-Policy…