← Back
CWE-1021

412 CVEs • Abstraction: Base

Improper Restriction of Rendered UI Layers or Frames

The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain, which can lead to user confusion about which interface the user is interacting with.

JSON object

Loading...

CVEs (412)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1Security Secret Server
Jun 17, 2026
Jun 24, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
IBM Security Secret Server 10.7 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijac...Show more
IBM Security Secret Server 10.7 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 177511.Show less
1Ibm
2Spectrum Protect Client
Spectrum Protect For Space Management
Jun 17, 2026
Jun 15, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Spectrum Protect Client 8.1.7.0 through 8.1.9.1 (Linux and Windows), 8.1.9.0 trough 8.1.9.1 (AIX) and IBM Spectrum Protect for Space Management 8.1.7.0 through 8.1.9.1 (Linux), 8.1.9.0 through 8.1.9.1 (AIX) web user...Show more
IBM Spectrum Protect Client 8.1.7.0 through 8.1.9.1 (Linux and Windows), 8.1.9.0 trough 8.1.9.1 (AIX) and IBM Spectrum Protect for Space Management 8.1.7.0 through 8.1.9.1 (Linux), 8.1.9.0 through 8.1.9.1 (AIX) web user interfaces could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 179488.Show less
1Ibm
1Api Connect
Jun 17, 2026
May 12, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM API Connect V2018.4.1.0 through 2018.4.1.10 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulner...Show more
IBM API Connect V2018.4.1.0 through 2018.4.1.10 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 174859.Show less
1Mozilla
1Firefox Esr
Jun 17, 2026
Apr 24, 2020
N/A· v4
4.7 MEDIUM· v3
4.3 MEDIUM· v2
When following a link that opened an intent://-schemed URL, causing a custom tab to be opened, Firefox for Android could be tricked into displaying the incorrect URI. <br> *Note: This issue only affects Firefox for Andro...Show more
When following a link that opened an intent://-schemed URL, causing a custom tab to be opened, Firefox for Android could be tricked into displaying the incorrect URI. <br> *Note: This issue only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 68.7.Show less
1Zulip
1Zulip Server
Jun 17, 2026
Apr 20, 2020
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Zulip Server before 2.1.3 allows reverse tabnabbing via the Markdown functionality.
1Westerndigital
2Ibi
My Cloud Home
Jun 17, 2026
Apr 15, 2020
N/A· v4
4.7 MEDIUM· v3
4.3 MEDIUM· v2
Western Digital My Cloud Home and ibi devices before 2.2.0 allow clickjacking on sign-in pages.
2Quarkus
Redhat
2Keycloak
Quarkus
Jun 17, 2026
Apr 6, 2020
N/A· v4
5.4 MEDIUM· v3
5.8 MEDIUM· v2
A vulnerability was found in all versions of Keycloak where, the pages on the Admin Console area of the application are completely missing general HTTP security headers in HTTP-responses. This does not directly lead to a...Show more
A vulnerability was found in all versions of Keycloak where, the pages on the Admin Console area of the application are completely missing general HTTP security headers in HTTP-responses. This does not directly lead to a security issue, yet it might aid attackers in their efforts to exploit other problems. The flaws unnecessarily make the servers more prone to Clickjacking, channel downgrade attacks and other similar client-based attack vectors.Show less
1Hitachienergy
1Esoms
Jun 17, 2026
Apr 2, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
For ABB eSOMS versions 4.0 to 6.0.2, the X-Frame-Options header is not configured in HTTP response. This can potentially allow 'ClickJacking' attacks where an attacker can frame parts of the application on a malicious we...Show more
For ABB eSOMS versions 4.0 to 6.0.2, the X-Frame-Options header is not configured in HTTP response. This can potentially allow 'ClickJacking' attacks where an attacker can frame parts of the application on a malicious web site, revealing sensitive user information such as authentication credentials.Show less
1Google
1Android
Jun 17, 2026
Mar 10, 2020
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
In onCreate of SettingsHomepageActivity, there is a possible tapjacking attack. This could lead to local escalation of privilege in Settings with no additional execution privileges needed. User interaction is needed for...Show more
In onCreate of SettingsHomepageActivity, there is a possible tapjacking attack. This could lead to local escalation of privilege in Settings with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-138442483Show less
1Microfocus
1Service Manager
Jun 17, 2026
Mar 9, 2020
N/A· v4
5.4 MEDIUM· v3
4.9 MEDIUM· v2
There is an improper restriction of rendered UI layers or frames vulnerability in Micro Focus Service Manager Release Control versions 9.50 and 9.60. The vulnerability may result in the ability of malicious users to perf...Show more
There is an improper restriction of rendered UI layers or frames vulnerability in Micro Focus Service Manager Release Control versions 9.50 and 9.60. The vulnerability may result in the ability of malicious users to perform UI redress attacks.Show less
1Puppet
1Puppet Enterprise
Nov 21, 2024
Feb 27, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Parts of the Puppet Enterprise Console 3.x were found to be susceptible to clickjacking and CSRF (Cross-Site Request Forgery) attacks. This would allow an attacker to redirect user input to an untrusted site or hijack a...Show more
Parts of the Puppet Enterprise Console 3.x were found to be susceptible to clickjacking and CSRF (Cross-Site Request Forgery) attacks. This would allow an attacker to redirect user input to an untrusted site or hijack a user session.Show less
1Mozilla
1Firefox
Nov 21, 2024
Feb 18, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Mozilla Firefox before 25 allows modification of anonymous content of pluginProblem.xml binding
1Google
1Android
Jun 17, 2026
Feb 13, 2020
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
It is possible for a malicious application to construct a TYPE_TOAST window manually and make that window clickable. This could lead to a local escalation of privilege with no additional execution privileges needed. User...Show more
It is possible for a malicious application to construct a TYPE_TOAST window manually and make that window clickable. This could lead to a local escalation of privilege with no additional execution privileges needed. User action is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-128674520Show less
1Siemens
8Scalance X 200irt Firmware
Scalance X 300 FirmwareScalance Xb 200 Firmware+5 more
Jun 17, 2026
Feb 11, 2020
N/A· v4
5.4 MEDIUM· v3
4.3 MEDIUM· v2
A vulnerability has been identified in SCALANCE S602 (All versions < V4.1), SCALANCE S612 (All versions < V4.1), SCALANCE S623 (All versions < V4.1), SCALANCE S627-2M (All versions < V4.1), SCALANCE X-200 switch family (...Show more
A vulnerability has been identified in SCALANCE S602 (All versions < V4.1), SCALANCE S612 (All versions < V4.1), SCALANCE S623 (All versions < V4.1), SCALANCE S627-2M (All versions < V4.1), SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < 5.2.4), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.5.0), SCALANCE X-200RNA switch family (All versions < V3.2.7), SCALANCE X-300 switch family (incl. X408 and SIPLUS NET variants) (All versions < 4.1.3). The device does not send the X-Frame-Option Header in the administrative web interface, which makes it vulnerable to Clickjacking attacks. The security vulnerability could be exploited by an attacker that is able to trick an administrative user with a valid session on the target device into clicking on a website controlled by the attacker. The vulnerability could allow an attacker to perform administrative actions via the web interface.Show less
1Netapp
1Snap Creator Framework
Nov 21, 2024
Feb 11, 2020
N/A· v4
4.6 MEDIUM· v3
3.5 LOW· v2
NetApp Snap Creator Framework before 4.3P1 allows remote authenticated users to conduct clickjacking attacks via unspecified vectors.
1Cisco
1Linksys E4200 Firmware
Nov 21, 2024
Feb 5, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Cisco Linksys E4200 1.0.05 Build 7 devices contain a Clickjacking Vulnerability which allows remote attackers to obtain sensitive information.
1Brother
1Mfc 9970cdw Firmware
Nov 21, 2024
Feb 5, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Brother MFC-9970CDW 1.10 devices with Firmware L contain a Frameable response (Clickjacking) vulnerability which could allow remote attackers to obtain sensitive information.
1Ibm
1Security Directory Server
Jun 17, 2026
Feb 4, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
IBM Security Directory Server 6.4.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to h...Show more
IBM Security Directory Server 6.4.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 165950.Show less
1Jenkins
1Jenkins
Jun 17, 2026
Jan 29, 2020
N/A· v4
5.4 MEDIUM· v3
4.3 MEDIUM· v2
REST API endpoints in Jenkins 2.218 and earlier, LTS 2.204.1 and earlier were vulnerable to clickjacking attacks.
1Splunk
1Splunk
Nov 21, 2024
Jan 23, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Splunk before 5.0.4 lacks X-Frame-Options which can allow Clickjacking