VYPR

CWE-1021

Improper Restriction of Rendered UI Layers or Frames

BaseIncomplete

Description

The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain.

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-103 · CAPEC-181 · CAPEC-222 · CAPEC-504 · CAPEC-506 · CAPEC-587 · CAPEC-654

CVEs mapped to this weakness (420)

page 21 of 21
  • CVE-2025-59950MedSep 30, 2025
    risk 0.00cvss 6.7epss 0.00

    FreshRSS is a free, self-hostable RSS aggregator. In versions 1.26.3 and below, due to a bypass of double clickjacking protection (confirmation dialog), it is possible to trick the admin into clicking the Promote button in another user's management page after the admin double…

  • CVE-2025-57769MedSep 29, 2025
    risk 0.00cvss 6.1epss 0.00

    FreshRSS is a free, self-hostable RSS aggregator. Versions 1.26.3 and below contain a vulnerability where a specially crafted page can trick a user into executing arbitrary JS code or promoting a user in FreshRSS by obscuring UI elements in iframes. If embedding an authenticated…

  • CVE-2025-53096MedJul 1, 2025
    risk 0.00cvss 5.4epss 0.00

    Sunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.628.4510, the web UI of Sunshine lacks protection against Clickjacking attacks. This vulnerability allows an attacker to embed the Sunshine interface within a malicious website using an invisible or…

  • CVE-2025-43854MedApr 28, 2025
    risk 0.00cvss 6.1epss 0.00

    DIFY is an open-source LLM app development platform. Prior to version 1.3.0, a clickjacking vulnerability was found in the default setup of the DIFY application, allowing malicious actors to trick users into clicking on elements of the web page without their knowledge or…

  • CVE-2023-1362MedMar 13, 2023
    risk 0.00cvss 6.1epss 0.01

    Improper Restriction of Rendered UI Layers or Frames in GitHub repository unilogies/bumsys prior to v2.0.2.

  • CVE-2022-2965MedAug 23, 2022
    risk 0.00cvss 4.3epss 0.01

    Improper Restriction of Rendered UI Layers or Frames in GitHub repository notrinos/notrinoserp prior to 0.7.

  • CVE-2022-2734MedAug 9, 2022
    risk 0.00cvss 5.4epss 0.01

    Improper Restriction of Rendered UI Layers or Frames in GitHub repository openemr/openemr prior to 7.0.0.1.

  • CVE-2022-1803MedMay 20, 2022
    risk 0.00cvss 6.9epss 0.02

    Improper Restriction of Rendered UI Layers or Frames in GitHub repository polonel/trudesk prior to 1.2.2.

  • CVE-2021-3660MedMar 10, 2022
    risk 0.00cvss 4.3epss 0.01

    Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a cockpit server via another website, inside an HTML entry. This may be used by a malicious website in clickjacking or similar attacks.

  • CVE-2021-3799MedSep 27, 2021
    risk 0.00cvss 5.4epss 0.02

    grav-plugin-admin is vulnerable to Improper Restriction of Rendered UI Layers or Frames

  • CVE-2021-27375MedFeb 18, 2021
    risk 0.00cvss 5.3epss 0.01

    Traefik before 2.4.5 allows the loading of IFRAME elements from other domains.

  • CVE-2020-24711MedOct 28, 2020
    risk 0.00cvss 6.5epss 0.02

    The Reset button on the Account Settings page in Gophish before 0.11.0 allows attackers to cause a denial of service via a clickjacking attack

  • CVE-2019-16175MedSep 9, 2019
    risk 0.00cvss 4.3epss 0.01

    A clickjacking vulnerability was found in Limesurvey before 3.17.14.

  • CVE-2018-7491HigFeb 26, 2018
    risk 0.00cvss 7.5epss 0.01

    In PrestaShop through 1.7.2.5, a UI-Redressing/Clickjacking vulnerability was found that might lead to state-changing impact in the context of a user or an admin, because the generateHtaccess function in classes/Tools.php sets neither X-Frame-Options nor 'Content-Security-Policy…

  • CVE-2015-1241Apr 19, 2015
    risk 0.00cvss —epss 0.02

    Google Chrome before 42.0.2311.90 does not properly consider the interaction of page navigation with the handling of touch events and gesture events, which allows remote attackers to trigger unintended UI actions via a crafted web site that conducts a "tapjacking" attack.

  • CVE-2014-1483Feb 6, 2014
    risk 0.00cvss —epss 0.02

    Mozilla Firefox before 27.0 and SeaMonkey before 2.24 allow remote attackers to bypass the Same Origin Policy and obtain sensitive information by using an IFRAME element in conjunction with certain timing measurements involving the document.caretPositionFromPoint and…

  • CVE-2014-1480Feb 6, 2014
    risk 0.00cvss —epss 0.03

    The file-download implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 does not properly restrict the timing of button selections, which allows remote attackers to conduct clickjacking attacks, and trigger unintended launching of a downloaded file, via a…

  • CVE-2013-5614Dec 11, 2013
    risk 0.00cvss —epss 0.02

    Mozilla Firefox before 26.0 and SeaMonkey before 2.23 do not properly consider the sandbox attribute of an IFRAME element during processing of a contained OBJECT element, which allows remote attackers to bypass intended sandbox restrictions via a crafted web site.

  • CVE-2008-2716Jun 16, 2008
    risk 0.00cvss —epss 0.03

    Unspecified vulnerability in Opera before 9.5 allows remote attackers to spoof the contents of trusted frames on the same parent page by modifying the location, which can facilitate phishing attacks.

  • CVE-2005-2407Aug 1, 2005
    risk 0.00cvss —epss 0.03

    A design error in Opera 8.01 and earlier allows user-assisted attackers to execute arbitrary code by overlaying a malicious new window above a file download dialog box, then tricking the user into double-clicking on the "Run" button, aka "link hijacking".