← Back
CWE-1021

400 CVEs • Abstraction: Base

Improper Restriction of Rendered UI Layers or Frames

The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain, which can lead to user confusion about which interface the user is interacting with.

JSON object

Loading...

CVEs (400)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Google
1Chrome
Jun 17, 2026
Jan 8, 2021
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Insufficient data validation in UI in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
1Vidyo
1Vidyo
Jun 17, 2026
Dec 29, 2020
N/A· v4
4.7 MEDIUM· v3
4.3 MEDIUM· v2
Vidyo 02-09-/D allows clickjacking via the portal/ URI.
1Schneider Electric
1Easergy T300 Firmware
Jun 17, 2026
Dec 11, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
A CWE-1021: Improper Restriction of Rendered UI Layers or Frames vulnerability exists in Easergy T300 (firmware 2.7 and older), that would allow an attacker to trick a user into initiating an unintended action.
1Mozilla
1Firefox
Jun 17, 2026
Dec 9, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-origin iframes that contained a login form could have been recognized by the login autofill service, and populated. This could have been used in clickjacking attacks, as well as be read across partitions in dynamic...Show more
Cross-origin iframes that contained a login form could have been recognized by the login autofill service, and populated. This could have been used in clickjacking attacks, as well as be read across partitions in dynamic first party isolation. This vulnerability affects Firefox < 83.Show less
1Mozilla
3Firefox
Firefox EsrThunderbird
Jun 17, 2026
Dec 9, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
It was possible to cause the browser to enter fullscreen mode without displaying the security UI; thus making it possible to attempt a phishing attack or otherwise confuse the user. This vulnerability affects Firefox < 8...Show more
It was possible to cause the browser to enter fullscreen mode without displaying the security UI; thus making it possible to attempt a phishing attack or otherwise confuse the user. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.Show less
1Apple
4Ipados
Iphone OsSafari+1 more
Jun 17, 2026
Dec 8, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The issue was addressed with improved UI handling. This issue is fixed in watchOS 7.0, Safari 14.0, iOS 14.0 and iPadOS 14.0. Visiting a malicious website may lead to address bar spoofing.
1Apple
1Safari
Jun 17, 2026
Dec 8, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
An inconsistent user interface issue was addressed with improved state management. This issue is fixed in Safari 14.0. Visiting a malicious website may lead to address bar spoofing.
1Apple
2Mac Os X
Safari
Jun 17, 2026
Dec 8, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
A spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, Safari 14.0.1. Visiting a malicious website may lead to address bar...Show more
A spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, Safari 14.0.1. Visiting a malicious website may lead to address bar spoofing.Show less
1Apple
2Mac Os X
Safari
Jun 17, 2026
Dec 8, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
An inconsistent user interface issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1, Safari 13.1.2. Visiting a malicious website may lead to address bar spoofing.
1Ec Cube
1Ec Cube
Jun 17, 2026
Dec 3, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Improper restriction of rendered UI layers or frames in EC-CUBE versions from 3.0.0 to 3.0.18 leads to clickjacking attacks. If a user accesses a specially crafted page while logged into the administrative page, unintend...Show more
Improper restriction of rendered UI layers or frames in EC-CUBE versions from 3.0.0 to 3.0.18 leads to clickjacking attacks. If a user accesses a specially crafted page while logged into the administrative page, unintended operations may be conducted.Show less
1Ibm
1App Connect Enterprise Certified Container
Jun 17, 2026
Nov 3, 2020
N/A· v4
5.4 MEDIUM· v3
4.9 MEDIUM· v2
IBM App Connect Enterprise Certified Container 1.0.0, 1.0.1, 1.0.2, 1.0.3, and 1.0.4 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remo...Show more
IBM App Connect Enterprise Certified Container 1.0.0, 1.0.1, 1.0.2, 1.0.3, and 1.0.4 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 189219.Show less
1Getgophish
1Gophish
Jun 17, 2026
Oct 28, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The Reset button on the Account Settings page in Gophish before 0.11.0 allows attackers to cause a denial of service via a clickjacking attack
1Apple
2Iphone Os
Safari
Jun 17, 2026
Oct 27, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
This issue was addressed with improved iframe sandbox enforcement. This issue is fixed in Safari 13.0.1, iOS 13. Maliciously crafted web content may violate iframe sandboxing policy.
1Raiseitsolutions
1Rits Browser
Jun 17, 2026
Oct 20, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
User Interface (UI) Misrepresentation of Critical Information vulnerability in the address bar of the Yandex Browser allows an attacker to obfuscate the true source of data as presented in the browser. This issue affects...Show more
User Interface (UI) Misrepresentation of Critical Information vulnerability in the address bar of the Yandex Browser allows an attacker to obfuscate the true source of data as presented in the browser. This issue affects the RITS Browser version 3.3.9 and prior versions.Show less
1Siemens
1Desigo Insight
Jun 17, 2026
Oct 15, 2020
N/A· v4
5.4 MEDIUM· v3
5.8 MEDIUM· v2
A vulnerability has been identified in Desigo Insight (All versions). The device does not properly set the X-Frame-Options HTTP Header which makes it vulnerable to Clickjacking attacks. This could allow an unauthenticate...Show more
A vulnerability has been identified in Desigo Insight (All versions). The device does not properly set the X-Frame-Options HTTP Header which makes it vulnerable to Clickjacking attacks. This could allow an unauthenticated attacker to retrieve or modify data in the context of a legitimate user by tricking that user to click on a website controlled by the attacker.Show less
1Ibm
1Infosphere Information Server
Jun 17, 2026
Sep 25, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
IBM InfoSphere Information Server 11.7 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability t...Show more
IBM InfoSphere Information Server 11.7 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim.Show less
1Gogogate
1Ismartgate Pro Firmware
Jun 17, 2026
Sep 24, 2020
N/A· v4
8.1 HIGH· v3
4.3 MEDIUM· v2
ismartgate PRO 1.5.9 is vulnerable to clickjacking.
3Debian
FedoraprojectGoogle
3Chrome
Debian LinuxFedora
Jun 17, 2026
Sep 21, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Incorrect security UI in media in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially obtain sensitive information via a crafted HTML page.
1Google
1Android
Jun 17, 2026
Sep 17, 2020
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
In PackageInstaller, there is a possible permissions bypass due to a tapjacking vulnerability. This could lead to local escalation of privilege using an app set as the default Assist app with User execution privileges ne...Show more
In PackageInstaller, there is a possible permissions bypass due to a tapjacking vulnerability. This could lead to local escalation of privilege using an app set as the default Assist app with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-138443815Show less
1Google
1Android
Jun 17, 2026
Sep 17, 2020
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
In manifest files of the SmartSpace package, there is a possible tapjacking vector due to a missing permission check. This could lead to local escalation of privilege and account hijacking with no additional execution pr...Show more
In manifest files of the SmartSpace package, there is a possible tapjacking vector due to a missing permission check. This could lead to local escalation of privilege and account hijacking with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-156046804Show less