VYPR

CWE-451

User Interface (UI) Misrepresentation of Critical Information

ClassDraft

Description

The user interface (UI) does not properly represent critical information to the user, allowing the information - or its source - to be obscured or spoofed. This is often a component in phishing attacks.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-154 · CAPEC-163 · CAPEC-164 · CAPEC-173 · CAPEC-98

CVEs mapped to this weakness (347)

page 17 of 18
  • CVE-2026-13948LowJun 30, 2026
    risk 0.20cvss 3.1epss 0.00

    Insufficient policy enforcement in Extensions in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Medium)

  • CVE-2026-13945LowJun 30, 2026
    risk 0.20cvss 3.1epss 0.00

    Insufficient policy enforcement in Extensions in Google Chrome on Linux prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Medium)

  • CVE-2026-12458LowJun 17, 2026
    risk 0.20cvss 3.1epss 0.00

    Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-48851LowMay 25, 2026
    risk 0.20cvss 3.1epss 0.00

    PuTTY 0.77 before 0.84 uses a copy of the PuTTY icon as a trust indication for TELNET data but the trust status is not cleared between proxy authentication and the main session.

  • CVE-2026-20732LowFeb 4, 2026
    risk 0.20cvss 3.1epss 0.00

    A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

  • CVE-2025-65046LowDec 18, 2025
    risk 0.20cvss 3.1epss 0.00

    Microsoft Edge (Chromium-based) Spoofing Vulnerability

  • CVE-2025-14023LowDec 15, 2025
    risk 0.20cvss 3.1epss 0.00

    LINE client for iOS prior to 15.19 allows UI spoofing due to inconsistencies between the navigation state and the in-app browser's user interface, which could create confusion about the trust context of displayed pages or interactive elements under specific conditions.

  • CVE-2024-6595LowJul 17, 2024
    risk 0.20cvss 3.0epss 0.00

    An issue was discovered in GitLab CE/EE affecting all versions starting from 11.8 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2 where it was possible to upload an NPM package with conflicting package data.

  • CVE-2024-54558LowMar 10, 2025
    risk 0.18cvss 2.8epss 0.00

    A clickjacking issue was addressed with improved out-of-process view handling. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15. An app may be able to trick a user into granting access to photos from the user's photo library.

  • CVE-2024-51749LowNov 12, 2024
    risk 0.16cvss 3.5epss 0.00

    Element is a Matrix web client built using the Matrix React SDK. Versions of Element Web and Desktop earlier than 1.11.85 do not check if thumbnails for attachments, stickers and images are coherent. It is possible to add thumbnails to events trigger a file download once…

  • CVE-2025-46394LowApr 23, 2025
    risk 0.14cvss 3.2epss 0.00

    In tar in BusyBox through 1.37.0, a TAR archive can have filenames hidden from a listing through the use of terminal escape sequences.

  • CVE-2025-43712LowJul 25, 2025
    risk 0.12cvss 2.9epss 0.00

    JHipster before v.8.9.0 allows privilege escalation via a modified authorities parameter. Upon registering in the JHipster portal and logging in as a standard user, the authorities parameter in the response from the api/account endpoint contains the value ROLE_USER. By…

  • CVE-2026-64735MedJul 27, 2026
    risk 0.00cvss 6.5epss 0.00

    An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. A remote attacker may be able to bypass…

  • CVE-2026-64730MedJul 27, 2026
    risk 0.00cvss 6.5epss 0.00

    The issue was addressed with improved UI. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Visiting a website that frames malicious content may lead to UI spoofing.

  • CVE-2026-60658HigJul 21, 2026
    risk 0.00cvss 7.5epss 0.00

    Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to…

  • CVE-2026-11925LowJul 21, 2026
    risk 0.00cvss 2.7epss 0.00

    Tanium addressed a User Interface (UI) Misrepresentation of Critical Information vulnerability in Tanium Server.

  • CVE-2026-45150MedJul 15, 2026
    risk 0.00cvss epss 0.00

    Zen is a firefox-based browser. Prior to 1.19.13b, Zen Browser did not provide a persistent, clearly visible security notification when a webpage entered fullscreen mode, allowing an attacker-controlled page to hide the real browser UI and origin information, imitate a trusted…

  • CVE-2026-13356MedJul 7, 2026
    risk 0.00cvss 6.3epss 0.00

    A malicious webpage could interrupt a pending navigation by enqueuing a synchronous JavaScript dialog, causing the browser UI to display the destination origin in the address bar while continuing to render attacker-controlled content. This vulnerability was fixed in Firefox for…

  • CVE-2026-45488MedJul 3, 2026
    risk 0.00cvss 5.4epss 0.00

    User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2026-14410MedJul 1, 2026
    risk 0.00cvss 4.3epss 0.00

    Inappropriate implementation in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)