CWE-1021
Improper Restriction of Rendered UI Layers or Frames
Description
The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-103 · CAPEC-181 · CAPEC-222 · CAPEC-504 · CAPEC-506 · CAPEC-587 · CAPEC-654
CVEs mapped to this weakness (406)
page 20 of 21| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-40957 | Hig | 0.00 | 7.5 | 0.00 | Jul 15, 2026 | o CVE-2026-40957 is a frameable content vulnerability in the Secure Access server login page prior to 14.55. Attackers with control of a malicious web site could use it to potentially steal credentials from an unwary administrator. | ||
| CVE-2026-58595 | Hig | 0.00 | 8.1 | 0.00 | Jul 14, 2026 | Improper restriction of rendered ui layers or frames in Microsoft Bing App for IOS allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2026-59791 | Low | 0.00 | 3.5 | 0.00 | Jul 10, 2026 | In JetBrains YouTrack before 2026.2.17012 cSS injection via Mermaid diagram rendering was possible | ||
| CVE-2026-38979 | Med | 0.00 | 5.4 | 0.00 | Jul 6, 2026 | ajenti through v2.2.13 has a clickjacking weakness in the browser-facing login and administrative UI. In ajenti-core/aj/http.py, the core HTTP response path initializes an empty header list, forwards handler-added headers verbatim, and finalizes responses through WSGI… | ||
| CVE-2026-24839 | Med | 0.00 | 4.7 | 0.00 | Jan 28, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). In versions prior to 0.26.6, the Dokploy web interface is vulnerable to Clickjacking attacks due to missing frame-busting headers. This allows attackers to embed Dokploy pages in malicious iframes and trick… | ||
| CVE-2026-23731 | Med | 0.00 | 4.3 | 0.00 | Jan 16, 2026 | WeGIA is a web manager for charitable institutions. Prior to 3.6.2, The web application is vulnerable to clickjacking attacks. The WeGIA application does not send any defensive HTTP headers related to framing protection. In particular, X-Frame-Options is missing… | ||
| CVE-2025-59950 | Med | 0.00 | 6.7 | 0.00 | Sep 30, 2025 | FreshRSS is a free, self-hostable RSS aggregator. In versions 1.26.3 and below, due to a bypass of double clickjacking protection (confirmation dialog), it is possible to trick the admin into clicking the Promote button in another user's management page after the admin double… | ||
| CVE-2025-57769 | Med | 0.00 | 6.1 | 0.00 | Sep 29, 2025 | FreshRSS is a free, self-hostable RSS aggregator. Versions 1.26.3 and below contain a vulnerability where a specially crafted page can trick a user into executing arbitrary JS code or promoting a user in FreshRSS by obscuring UI elements in iframes. If embedding an authenticated… | ||
| CVE-2025-53096 | Med | 0.00 | 5.4 | 0.00 | Jul 1, 2025 | Sunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.628.4510, the web UI of Sunshine lacks protection against Clickjacking attacks. This vulnerability allows an attacker to embed the Sunshine interface within a malicious website using an invisible or… | ||
| CVE-2025-43854 | Med | 0.00 | 6.1 | 0.00 | Apr 28, 2025 | DIFY is an open-source LLM app development platform. Prior to version 1.3.0, a clickjacking vulnerability was found in the default setup of the DIFY application, allowing malicious actors to trick users into clicking on elements of the web page without their knowledge or… | ||
| CVE-2023-1362 | Med | 0.00 | 6.1 | 0.01 | Mar 13, 2023 | Improper Restriction of Rendered UI Layers or Frames in GitHub repository unilogies/bumsys prior to v2.0.2. | ||
| CVE-2022-2965 | Med | 0.00 | 4.3 | 0.01 | Aug 23, 2022 | Improper Restriction of Rendered UI Layers or Frames in GitHub repository notrinos/notrinoserp prior to 0.7. | ||
| CVE-2022-2734 | Med | 0.00 | 5.4 | 0.01 | Aug 9, 2022 | Improper Restriction of Rendered UI Layers or Frames in GitHub repository openemr/openemr prior to 7.0.0.1. | ||
| CVE-2022-1803 | Med | 0.00 | 6.9 | 0.02 | May 20, 2022 | Improper Restriction of Rendered UI Layers or Frames in GitHub repository polonel/trudesk prior to 1.2.2. | ||
| CVE-2021-3660 | Med | 0.00 | 4.3 | 0.01 | Mar 10, 2022 | Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a cockpit server via another website, inside an HTML entry. This may be used by a malicious website in clickjacking or similar attacks. | ||
| CVE-2021-3799 | Med | 0.00 | 5.4 | 0.02 | Sep 27, 2021 | grav-plugin-admin is vulnerable to Improper Restriction of Rendered UI Layers or Frames | ||
| CVE-2021-27375 | Med | 0.00 | 5.3 | 0.01 | Feb 18, 2021 | Traefik before 2.4.5 allows the loading of IFRAME elements from other domains. | ||
| CVE-2020-24711 | Med | 0.00 | 6.5 | 0.02 | Oct 28, 2020 | The Reset button on the Account Settings page in Gophish before 0.11.0 allows attackers to cause a denial of service via a clickjacking attack | ||
| CVE-2019-16175 | Med | 0.00 | 4.3 | 0.01 | Sep 9, 2019 | A clickjacking vulnerability was found in Limesurvey before 3.17.14. | ||
| CVE-2018-7491 | Hig | 0.00 | 7.5 | 0.01 | Feb 26, 2018 | In PrestaShop through 1.7.2.5, a UI-Redressing/Clickjacking vulnerability was found that might lead to state-changing impact in the context of a user or an admin, because the generateHtaccess function in classes/Tools.php sets neither X-Frame-Options nor 'Content-Security-Policy… |
- risk 0.00cvss 7.5epss 0.00
o CVE-2026-40957 is a frameable content vulnerability in the Secure Access server login page prior to 14.55. Attackers with control of a malicious web site could use it to potentially steal credentials from an unwary administrator.
- risk 0.00cvss 8.1epss 0.00
Improper restriction of rendered ui layers or frames in Microsoft Bing App for IOS allows an unauthorized attacker to perform spoofing over a network.
- risk 0.00cvss 3.5epss 0.00
In JetBrains YouTrack before 2026.2.17012 cSS injection via Mermaid diagram rendering was possible
- risk 0.00cvss 5.4epss 0.00
ajenti through v2.2.13 has a clickjacking weakness in the browser-facing login and administrative UI. In ajenti-core/aj/http.py, the core HTTP response path initializes an empty header list, forwards handler-added headers verbatim, and finalizes responses through WSGI…
- risk 0.00cvss 4.7epss 0.00
Dokploy is a free, self-hostable Platform as a Service (PaaS). In versions prior to 0.26.6, the Dokploy web interface is vulnerable to Clickjacking attacks due to missing frame-busting headers. This allows attackers to embed Dokploy pages in malicious iframes and trick…
- risk 0.00cvss 4.3epss 0.00
WeGIA is a web manager for charitable institutions. Prior to 3.6.2, The web application is vulnerable to clickjacking attacks. The WeGIA application does not send any defensive HTTP headers related to framing protection. In particular, X-Frame-Options is missing…
- risk 0.00cvss 6.7epss 0.00
FreshRSS is a free, self-hostable RSS aggregator. In versions 1.26.3 and below, due to a bypass of double clickjacking protection (confirmation dialog), it is possible to trick the admin into clicking the Promote button in another user's management page after the admin double…
- risk 0.00cvss 6.1epss 0.00
FreshRSS is a free, self-hostable RSS aggregator. Versions 1.26.3 and below contain a vulnerability where a specially crafted page can trick a user into executing arbitrary JS code or promoting a user in FreshRSS by obscuring UI elements in iframes. If embedding an authenticated…
- risk 0.00cvss 5.4epss 0.00
Sunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.628.4510, the web UI of Sunshine lacks protection against Clickjacking attacks. This vulnerability allows an attacker to embed the Sunshine interface within a malicious website using an invisible or…
- risk 0.00cvss 6.1epss 0.00
DIFY is an open-source LLM app development platform. Prior to version 1.3.0, a clickjacking vulnerability was found in the default setup of the DIFY application, allowing malicious actors to trick users into clicking on elements of the web page without their knowledge or…
- risk 0.00cvss 6.1epss 0.01
Improper Restriction of Rendered UI Layers or Frames in GitHub repository unilogies/bumsys prior to v2.0.2.
- risk 0.00cvss 4.3epss 0.01
Improper Restriction of Rendered UI Layers or Frames in GitHub repository notrinos/notrinoserp prior to 0.7.
- risk 0.00cvss 5.4epss 0.01
Improper Restriction of Rendered UI Layers or Frames in GitHub repository openemr/openemr prior to 7.0.0.1.
- risk 0.00cvss 6.9epss 0.02
Improper Restriction of Rendered UI Layers or Frames in GitHub repository polonel/trudesk prior to 1.2.2.
- risk 0.00cvss 4.3epss 0.01
Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a cockpit server via another website, inside an HTML entry. This may be used by a malicious website in clickjacking or similar attacks.
- risk 0.00cvss 5.4epss 0.02
grav-plugin-admin is vulnerable to Improper Restriction of Rendered UI Layers or Frames
- risk 0.00cvss 5.3epss 0.01
Traefik before 2.4.5 allows the loading of IFRAME elements from other domains.
- risk 0.00cvss 6.5epss 0.02
The Reset button on the Account Settings page in Gophish before 0.11.0 allows attackers to cause a denial of service via a clickjacking attack
- risk 0.00cvss 4.3epss 0.01
A clickjacking vulnerability was found in Limesurvey before 3.17.14.
- risk 0.00cvss 7.5epss 0.01
In PrestaShop through 1.7.2.5, a UI-Redressing/Clickjacking vulnerability was found that might lead to state-changing impact in the context of a user or an admin, because the generateHtaccess function in classes/Tools.php sets neither X-Frame-Options nor 'Content-Security-Policy…