VYPR

CWE-1021

Improper Restriction of Rendered UI Layers or Frames

BaseIncomplete

Description

The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain.

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-103 · CAPEC-181 · CAPEC-222 · CAPEC-504 · CAPEC-506 · CAPEC-587 · CAPEC-654

CVEs mapped to this weakness (406)

page 6 of 21
  • CVE-2025-0362MedApr 10, 2025
    risk 0.42cvss 6.4epss 0.00

    An issue has been discovered in GitLab CE/EE affecting all versions from 7.7 before 17.8.7, 17.9 before 17.9.6, and 17.10 before 17.10.4. Under certain conditions, an attacker could potentially trick users into unintentionally authorizing sensitive actions on their behalf.

  • CVE-2025-25213MedApr 9, 2025
    risk 0.42cvss 6.5epss 0.00

    Improper restriction of rendered UI layers or frames issue exists in Wi-Fi AP UNIT 'AC-WPS-11ac series'. If a user views and clicks on the content on the malicious page while logged in, unintended operations may be performed.

  • CVE-2024-57369MedJan 17, 2025
    risk 0.42cvss 6.4epss 0.00

    Clickjacking vulnerability in typecho v1.2.1.

  • CVE-2024-7518MedAug 6, 2024
    risk 0.42cvss 6.5epss 0.01

    Select options could obscure the fullscreen notification dialog. This could be used by a malicious site to perform a spoofing attack. This vulnerability affects Firefox < 129, Firefox ESR < 128.1, and Thunderbird < 128.1.

  • CVE-2024-4950MedMay 15, 2024
    risk 0.42cvss 6.5epss 0.01

    Inappropriate implementation in Downloads in Google Chrome prior to 125.0.6422.60 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2024-3911MedApr 23, 2024
    risk 0.42cvss 6.5epss 0.00

    An unauthenticated remote attacker can deceive users into performing unintended actions due to improper restriction of rendered UI layers or frames. 

  • CVE-2024-28196MedMar 13, 2024
    risk 0.42cvss 6.5epss 0.00

    your_spotify is an open source, self hosted Spotify tracking dashboard. YourSpotify version < 1.9.0 does not prevent other pages from displaying it in an iframe and is thus vulnerable to clickjacking. Clickjacking can be used to trick an existing user of YourSpotify to trigger…

  • CVE-2024-1890MedFeb 26, 2024
    risk 0.42cvss 6.4epss 0.00

    Vulnerability whereby an attacker could send a malicious link to an authenticated operator, which could allow remote attackers to perform a clickjacking attack on Sunny WebBox firmware version 1.6.1 and earlier.

  • CVE-2023-6211MedNov 21, 2023
    risk 0.42cvss 6.5epss 0.00

    If an attacker needed a user to load an insecure http: page and knew that user had enabled HTTPS-only mode, the attacker could have tricked the user into clicking to grant an HTTPS-only exception if they could get the user to participate in a clicking game. This vulnerability…

  • CVE-2023-4956MedNov 7, 2023
    risk 0.42cvss 6.5epss 0.00

    A flaw was found in Quay. Clickjacking is when an attacker uses multiple transparent or opaque layers to trick a user into clicking on a button or link on another page when they intend to click on the top-level page. During the pentest, it has been detected that the…

  • CVE-2023-30961MedSep 27, 2023
    risk 0.42cvss 6.5epss 0.00

    Palantir Gotham was found to be vulnerable to a bug where under certain circumstances, the frontend could have applied an incorrect classification to a newly created property or link.

  • CVE-2022-43378MedApr 18, 2023
    risk 0.42cvss 6.5epss 0.00

    A CWE-1021: Improper Restriction of Rendered UI Layers or Frames vulnerability exists that could cause the user to be tricked into performing unintended actions when external address frames are not properly restricted. Affected Products: NetBotz 4 -…

  • CVE-2022-32517MedJan 30, 2023
    risk 0.42cvss 6.5epss 0.00

    A CWE-1021: Improper Restriction of Rendered UI Layers or Frames vulnerability exists that could cause an adversary to trick the interface user/admin into interacting with the application in an unintended way when the product does not implement restrictions on the ability to…

  • CVE-2022-45420MedDec 22, 2022
    risk 0.42cvss 6.5epss 0.01

    Use tables inside of an iframe, an attacker could have caused iframe contents to be rendered outside the boundaries of the iframe, resulting in potential user confusion or spoofing attacks. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.

  • CVE-2022-29914MedDec 22, 2022
    risk 0.42cvss 6.5epss 0.01

    When reusing existing popups Firefox would have allowed them to cover the fullscreen notification UI, which could have enabled browser spoofing attacks. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100.

  • CVE-2022-20553MedDec 16, 2022
    risk 0.42cvss 6.5epss 0.00

    In onCreate of LogAccessDialogActivity.java, there is a possible way to bypass a permission check due to a tapjacking/overlay attack. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation.Product:…

  • CVE-2022-46695MedDec 15, 2022
    risk 0.42cvss 6.5epss 0.01

    A spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation. This issue is fixed in tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Visiting a website that frames malicious content…

  • CVE-2022-1138MedJul 23, 2022
    risk 0.42cvss 6.5epss 0.01

    Inappropriate implementation in Web Cursor in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who had compromised the renderer process to obscure the contents of the Omnibox (URL bar) via a crafted HTML page.

  • CVE-2022-2179MedJul 20, 2022
    risk 0.42cvss 6.5epss 0.01

    The X-Frame-Options header in Rockwell Automation MicroLogix 1100/1400 Versions 21.007 and prior is not configured in the HTTP response, which could allow clickjacking attacks.

  • CVE-2022-0455MedApr 5, 2022
    risk 0.42cvss 6.5epss 0.01

    Inappropriate implementation in Full Screen Mode in Google Chrome on Android prior to 98.0.4758.80 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.