VYPR

CWE-1021

Improper Restriction of Rendered UI Layers or Frames

BaseIncomplete

Description

The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain.

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-103 · CAPEC-181 · CAPEC-222 · CAPEC-504 · CAPEC-506 · CAPEC-587 · CAPEC-654

CVEs mapped to this weakness (406)

page 7 of 21
  • CVE-2020-28218MedDec 11, 2020
    risk 0.42cvss 6.5epss 0.01

    A CWE-1021: Improper Restriction of Rendered UI Layers or Frames vulnerability exists in Easergy T300 (firmware 2.7 and older), that would allow an attacker to trick a user into initiating an unintended action.

  • CVE-2020-6547MedSep 21, 2020
    risk 0.42cvss 6.5epss 0.01

    Incorrect security UI in media in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially obtain sensitive information via a crafted HTML page.

  • CVE-2020-15648MedAug 10, 2020
    risk 0.42cvss 6.5epss 0.01

    Using object or embed tags, it was possible to frame other websites, even if they disallowed framing using the X-Frame-Options header. This vulnerability affects Thunderbird < 78 and Firefox < 78.0.2.

  • CVE-2019-19001MedApr 2, 2020
    risk 0.42cvss 6.5epss 0.02

    For ABB eSOMS versions 4.0 to 6.0.2, the X-Frame-Options header is not configured in HTTP response. This can potentially allow 'ClickJacking' attacks where an attacker can frame parts of the application on a malicious web site, revealing sensitive user information such as…

  • CVE-2013-2675MedFeb 5, 2020
    risk 0.42cvss 6.5epss 0.02

    Brother MFC-9970CDW 1.10 devices with Firmware L contain a Frameable response (Clickjacking) vulnerability which could allow remote attackers to obtain sensitive information.

  • CVE-2019-4058MedMay 20, 2019
    risk 0.42cvss 6.5epss 0.01

    IBM BigFix Platform 9.2 and 9.5 could allow a low-privilege user to manipulate the UI into exposing interface elements and information normally restricted to administrators. IBM X-Force ID: 156570.

  • CVE-2019-5767MedFeb 19, 2019
    risk 0.42cvss 6.5epss 0.01

    Insufficient protection of permission UI in WebAPKs in Google Chrome on Android prior to 72.0.3626.81 allowed an attacker who convinced the user to install a malicious application to access privacy/security sensitive web APIs via a crafted APK.

  • CVE-2018-16172MedJan 9, 2019
    risk 0.42cvss 6.5epss 0.01

    Improper countermeasure against clickjacking attack in client certificates management screen was discovered in Cybozu Remote Service 3.0.0 to 3.1.8, that allows remote attackers to trick a user to delete the registered client certificate.

  • CVE-2018-6909MedNov 1, 2018
    risk 0.42cvss 6.5epss 0.01

    A missing X-Frame-Options header in the Green Electronics RainMachine Mini-8 (2nd Generation) and Touch HD 12 web application could be used by a remote attacker for clickjacking, as demonstrated by triggering an API page request.

  • CVE-2017-5697MedJun 14, 2017
    risk 0.42cvss 6.5epss 0.01

    Insufficient clickjacking protection in the Web User Interface of Intel AMT firmware versions before 9.1.40.1000, 9.5.60.1952, 10.0.50.1004, 11.0.0.1205, and 11.6.25.1129 potentially allowing a remote attacker to hijack users web clicks via attacker's crafted web page.

  • CVE-2017-7440MedMay 2, 2017
    risk 0.42cvss 6.5epss 0.01

    Kerio Connect 8.0.0 through 9.2.2, and Kerio Connect Client desktop application for Windows and Mac 9.2.0 through 9.2.2, when e-mail preview is enabled, allows remote attackers to conduct clickjacking attacks via a crafted e-mail message.

  • CVE-2017-5016MedFeb 17, 2017
    risk 0.42cvss 6.5epss 0.01

    Blink in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, failed to prevent certain UI elements from being displayed by non-visible pages, which allowed a remote attacker to show certain UI elements on a page they don't control via a…

  • CVE-2025-36149MedNov 21, 2025
    risk 0.41cvss 6.3epss 0.00

    IBM Concert Software 1.0.0 through 2.0.0 could allow a remote attacker to hijack the clicking action of the victim.

  • CVE-2024-0669MedJan 18, 2024
    risk 0.41cvss 6.3epss 0.00

    A Cross-Frame Scripting vulnerability has been found on Plone CMS affecting verssion below 6.0.5. An attacker could store a malicious URL to be opened by an administrator and execute a malicios iframe element.

  • CVE-2026-70608HigAug 5, 2026
    risk 0.40cvss 7.2epss 0.00

    Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10, 41.10.3, and 42.0.1, a sandboxed iframe without the allow-popups keyword could still open a new window or trigger setWindowOpenHandler with no user…

  • CVE-2025-58405MedMar 2, 2026
    risk 0.40cvss 6.1epss 0.00

    The CGM CLININET application does not implement any mechanisms that prevent clickjacking attacks, neither HTTP security headers nor HTML-based frame‑busting protections were detected. As a result, an attacker can embed the application inside a maliciously crafted IFRAME and…

  • CVE-2025-52987MedJan 15, 2026
    risk 0.40cvss 6.1epss 0.00

    A clickjacking vulnerability exists in the web portal of Juniper Networks Paragon Automation (Pathfinder, Planner, Insights) due to the application's failure to set appropriate X-Frame-Options and X-Content-Type HTTP headers. This vulnerability allows an attacker to trick users…

  • CVE-2025-59479MedDec 16, 2025
    risk 0.40cvss 6.1epss 0.00

    CHOCO TEI WATCHER mini (IB-MCT001) contains an issue with improper restriction of rendered UI layers or frames. If a user clicks on content on a malicious web page while logged into the product, unintended operations may be performed on the product.

  • CVE-2025-1494MedAug 26, 2025
    risk 0.40cvss 6.1epss 0.00

    IBM Cognos Command Center 10.2.4.1 and 10.2.5 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly…

  • CVE-2025-54527MedJul 28, 2025
    risk 0.40cvss 6.1epss 0.00

    In JetBrains YouTrack before 2025.2.86935, 2025.2.87167, 2025.3.87341, 2025.3.87344 improper iframe configuration in widget sandbox allows popups to bypass security restrictions