← Back
CWE-1021

400 CVEs • Abstraction: Base

Improper Restriction of Rendered UI Layers or Frames

The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain, which can lead to user confusion about which interface the user is interacting with.

JSON object

Loading...

CVEs (400)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mozilla
1Firefox
Jun 17, 2026
Jun 11, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
By manipulating the fullscreen feature while opening a data-list, an attacker could have overlaid a text box over the address bar. This could have led to user confusion and possible spoofing attacks. This vulnerability a...Show more
By manipulating the fullscreen feature while opening a data-list, an attacker could have overlaid a text box over the address bar. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 127.Show less
1Zenml
1Zenml
Jun 17, 2026
Jun 6, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A clickjacking vulnerability exists in zenml-io/zenml versions up to and including 0.55.5 due to the application's failure to set appropriate X-Frame-Options or Content-Security-Policy HTTP headers. This vulnerability al...Show more
A clickjacking vulnerability exists in zenml-io/zenml versions up to and including 0.55.5 due to the application's failure to set appropriate X-Frame-Options or Content-Security-Policy HTTP headers. This vulnerability allows an attacker to embed the application UI within an iframe on a malicious page, potentially leading to unauthorized actions by tricking users into interacting with the interface under the attacker's control. The issue was addressed in version 0.56.3.Show less
2Fedoraproject
Google
2Chrome
Fedora
Jun 17, 2026
May 15, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Inappropriate implementation in Downloads in Google Chrome prior to 125.0.6422.60 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium...Show more
Inappropriate implementation in Downloads in Google Chrome prior to 125.0.6422.60 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)Show less
1Automattic
1Jetpack
Jun 17, 2026
Apr 24, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Improper Restriction of Rendered UI Layers or Frames vulnerability in Automattic Jetpack allows Clickjacking.This issue affects Jetpack: from n/a before 12.7.
-
-
Jun 17, 2026
Apr 23, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An unauthenticated remote attacker can deceive users into performing unintended actions due to improper restriction of rendered UI layers or frames. 
1Microsoft
1Edge Chromium
Jun 17, 2026
Apr 4, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Microsoft Edge (Chromium-based) Spoofing Vulnerability
1Mozilla
1Firefox
Jun 17, 2026
Mar 19, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Data was not properly sanitized when decoding a QUIC ACK frame; this could have led to unrestricted memory consumption and a crash. This vulnerability affects Firefox < 124.
1Yooooomi
1Your Spotify
Jun 17, 2026
Mar 13, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
your_spotify is an open source, self hosted Spotify tracking dashboard. YourSpotify version < 1.9.0 does not prevent other pages from displaying it in an iframe and is thus vulnerable to clickjacking. Clickjacking can be...Show more
your_spotify is an open source, self hosted Spotify tracking dashboard. YourSpotify version < 1.9.0 does not prevent other pages from displaying it in an iframe and is thus vulnerable to clickjacking. Clickjacking can be used to trick an existing user of YourSpotify to trigger actions, such as allowing signup of other users or deleting the current user account. Clickjacking works by opening the target application in an invisible iframe on an attacker-controlled site and luring a victim to visit the attacker page and interacting with it. By positioning elements over the invisible iframe, a victim can be tricked into triggering malicious or destructive actions in the invisible iframe, while they think they interact with a totally different site altogether. When a victim visits an attacker-controlled site while they are logged into YourSpotify, they can be tricked into performing actions on their YourSpotify instance without their knowledge. These actions include allowing signup of other users or deleting the current user account, resulting in a high impact to the integrity of YourSpotify. This issue has been addressed in version 1.9.0. Users are advised to upgrade. There are no known workarounds for this vulnerability.Show less
1Microsoft
1Edge
Jun 17, 2026
Mar 7, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Microsoft Edge for Android Spoofing Vulnerability
1Sma
1Sunny Webbox Firmware
Jun 17, 2026
Feb 26, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Vulnerability whereby an attacker could send a malicious link to an authenticated operator, which could allow remote attackers to perform a clickjacking attack on Sunny WebBox firmware version 1.6.1 and earlier.
2Debian
Mozilla
3Debian Linux
FirefoxThunderbird
Jun 17, 2026
Feb 20, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A malicious website could have used a combination of exiting fullscreen mode and `requestPointerLock` to cause the user's mouse to be re-positioned unexpectedly, which could have led to user confusion and inadvertently g...Show more
A malicious website could have used a combination of exiting fullscreen mode and `requestPointerLock` to cause the user's mouse to be re-positioned unexpectedly, which could have led to user confusion and inadvertently granting permissions they did not intend to grant. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.Show less
1Hcltech
1Sametime Chat And Meetings
Jun 17, 2026
Feb 10, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Sametime is impacted by lack of clickjacking protection in Outlook add-in. The application is not implementing appropriate protections in order to protect users from clickjacking attacks.
1Samsung
1Android
Jun 17, 2026
Feb 6, 2024
N/A· v4
3.3 LOW· v3
N/A· v2
Implicit intent hijacking vulnerability in Smart Suggestions prior to SMR Feb-2024 Release 1 allows local attackers to get sensitive information.
1Plone
1Plone
Jun 17, 2026
Jan 18, 2024
N/A· v4
7.1 HIGH· v3
N/A· v2
A Cross-Frame Scripting vulnerability has been found on Plone CMS affecting verssion below 6.0.5. An attacker could store a malicious URL to be opened by an administrator and execute a malicios iframe element.
1Apple
3Ipados
Iphone OsMacos
Jun 17, 2026
Jan 10, 2024
N/A· v4
4.7 MEDIUM· v3
N/A· v2
The issue was addressed with improved UI handling. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1. Visiting a website that frames malicious content may lead to UI spoofing.
1Moxa
1Oncell G3150a Lte Firmware
Jun 17, 2026
Dec 31, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A clickjacking vulnerability has been identified in OnCell G3150A-LTE Series firmware versions v1.3 and prior. This vulnerability is caused by incorrectly restricts frame objects, which can lead to user confusion about...Show more
A clickjacking vulnerability has been identified in OnCell G3150A-LTE Series firmware versions v1.3 and prior. This vulnerability is caused by incorrectly restricts frame objects, which can lead to user confusion about which interface the user is interacting with. This vulnerability may lead the attacker to trick the user into interacting with the application. Show less
2Debian
Mozilla
3Debian Linux
FirefoxFirefox Esr
Jun 17, 2026
Dec 19, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
The timing of a button click causing a popup to disappear was approximately the same length as the anti-clickjacking delay on permission prompts. It was possible to use this fact to surprise users by luring them to click...Show more
The timing of a button click causing a popup to disappear was approximately the same length as the anti-clickjacking delay on permission prompts. It was possible to use this fact to surprise users by luring them to click where the permission grant button would be about to appear. This vulnerability affects Firefox ESR < 115.6 and Firefox < 121.Show less
1Redhat
1Advanced Cluster Security
Jun 17, 2026
Dec 12, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
In Red Hat Advanced Cluster Security (RHACS), it was found that some security related HTTP headers were missing, allowing an attacker to exploit this with a clickjacking attack. An attacker could exploit this by convinci...Show more
In Red Hat Advanced Cluster Security (RHACS), it was found that some security related HTTP headers were missing, allowing an attacker to exploit this with a clickjacking attack. An attacker could exploit this by convincing a valid RHACS user to visit an attacker-controlled web page, that deceptively points to valid RHACS endpoints, hijacking the user's account permissions to perform other actions.Show less
1Selinc
1Sel 411l Firmware
Jun 17, 2026
Nov 30, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
An Improper Restriction of Rendered UI Layers or Frames in the Schweitzer Engineering Laboratories SEL-411L could allow an unauthenticated attacker to perform clickjacking based attacks against an authenticated and autho...Show more
An Improper Restriction of Rendered UI Layers or Frames in the Schweitzer Engineering Laboratories SEL-411L could allow an unauthenticated attacker to perform clickjacking based attacks against an authenticated and authorized user. See product Instruction Manual Appendix A dated 20230830 for more details. Show less
1Mozilla
1Firefox
Jun 17, 2026
Nov 21, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
If an attacker needed a user to load an insecure http: page and knew that user had enabled HTTPS-only mode, the attacker could have tricked the user into clicking to grant an HTTPS-only exception if they could get the us...Show more
If an attacker needed a user to load an insecure http: page and knew that user had enabled HTTPS-only mode, the attacker could have tricked the user into clicking to grant an HTTPS-only exception if they could get the user to participate in a clicking game. This vulnerability affects Firefox < 120.Show less