← Back
CWE-1021

400 CVEs • Abstraction: Base

Improper Restriction of Rendered UI Layers or Frames

The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain, which can lead to user confusion about which interface the user is interacting with.

JSON object

Loading...

CVEs (400)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Google
1Android
Jun 17, 2026
Feb 13, 2020
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
It is possible for a malicious application to construct a TYPE_TOAST window manually and make that window clickable. This could lead to a local escalation of privilege with no additional execution privileges needed. User...Show more
It is possible for a malicious application to construct a TYPE_TOAST window manually and make that window clickable. This could lead to a local escalation of privilege with no additional execution privileges needed. User action is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-128674520Show less
1Siemens
8Scalance X 200irt Firmware
Scalance X 300 FirmwareScalance Xb 200 Firmware+5 more
Jun 17, 2026
Feb 11, 2020
N/A· v4
5.4 MEDIUM· v3
4.3 MEDIUM· v2
A vulnerability has been identified in SCALANCE S602 (All versions < V4.1), SCALANCE S612 (All versions < V4.1), SCALANCE S623 (All versions < V4.1), SCALANCE S627-2M (All versions < V4.1), SCALANCE X-200 switch family (...Show more
A vulnerability has been identified in SCALANCE S602 (All versions < V4.1), SCALANCE S612 (All versions < V4.1), SCALANCE S623 (All versions < V4.1), SCALANCE S627-2M (All versions < V4.1), SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < 5.2.4), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.5.0), SCALANCE X-200RNA switch family (All versions < V3.2.7), SCALANCE X-300 switch family (incl. X408 and SIPLUS NET variants) (All versions < 4.1.3). The device does not send the X-Frame-Option Header in the administrative web interface, which makes it vulnerable to Clickjacking attacks. The security vulnerability could be exploited by an attacker that is able to trick an administrative user with a valid session on the target device into clicking on a website controlled by the attacker. The vulnerability could allow an attacker to perform administrative actions via the web interface.Show less
1Netapp
1Snap Creator Framework
Nov 21, 2024
Feb 11, 2020
N/A· v4
4.6 MEDIUM· v3
3.5 LOW· v2
NetApp Snap Creator Framework before 4.3P1 allows remote authenticated users to conduct clickjacking attacks via unspecified vectors.
1Cisco
1Linksys E4200 Firmware
Nov 21, 2024
Feb 5, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Cisco Linksys E4200 1.0.05 Build 7 devices contain a Clickjacking Vulnerability which allows remote attackers to obtain sensitive information.
1Brother
1Mfc 9970cdw Firmware
Nov 21, 2024
Feb 5, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Brother MFC-9970CDW 1.10 devices with Firmware L contain a Frameable response (Clickjacking) vulnerability which could allow remote attackers to obtain sensitive information.
1Ibm
1Security Directory Server
Jun 17, 2026
Feb 4, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
IBM Security Directory Server 6.4.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to h...Show more
IBM Security Directory Server 6.4.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 165950.Show less
1Jenkins
1Jenkins
Jun 17, 2026
Jan 29, 2020
N/A· v4
5.4 MEDIUM· v3
4.3 MEDIUM· v2
REST API endpoints in Jenkins 2.218 and earlier, LTS 2.204.1 and earlier were vulnerable to clickjacking attacks.
1Splunk
1Splunk
Nov 21, 2024
Jan 23, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Splunk before 5.0.4 lacks X-Frame-Options which can allow Clickjacking
1Ibm
1Financial Transaction Manager For Multiplatform
Jun 17, 2026
Dec 20, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
IBM Financial Transaction Manager 3.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to...Show more
IBM Financial Transaction Manager 3.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 172877.Show less
1Intesync
1Solismed
Jun 17, 2026
Dec 12, 2019
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Intesync Solismed 3.3sp allows Clickjacking.
1Google
1Chrome
Jun 17, 2026
Nov 25, 2019
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Insufficient data validation in Blink in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to bypass anti-clickjacking policy via a crafted HTML page.
1Ibm
1Smartcloud Analytics Log Analysis
Jun 17, 2026
Nov 22, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
IBM SmartCloud Analytics 1.3.1 through 1.3.5 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerabi...Show more
IBM SmartCloud Analytics 1.3.1 through 1.3.5 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 159186.Show less
1Vbulletin
1Vbulletin
Jun 17, 2026
Oct 4, 2019
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
vBulletin before 5.5.4 allows clickjacking.
1Ibm
1Websphere Extreme Scale
Jun 17, 2026
Sep 30, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
IBM WebSphere eXtreme Scale 8.6 Admin Console could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerab...Show more
IBM WebSphere eXtreme Scale 8.6 Admin Console could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 158102.Show less
1Cisco
5Hyperflex Hx220c Af M5 Firmware
Hyperflex Hx220c Edge M5 FirmwareHyperflex Hx220c M5 Firmware+2 more
Jun 17, 2026
Sep 18, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A vulnerability in the web-based interface of Cisco HyperFlex Software could allow an unauthenticated, remote attacker to execute a cross-frame scripting (XFS) attack on an affected device. This vulnerability is due to i...Show more
A vulnerability in the web-based interface of Cisco HyperFlex Software could allow an unauthenticated, remote attacker to execute a cross-frame scripting (XFS) attack on an affected device. This vulnerability is due to insufficient HTML iframe protection. An attacker could exploit this vulnerability by directing a user to an attacker-controlled web page that contains a malicious HTML iframe. A successful exploit could allow the attacker to conduct clickjacking or other clientside browser attacks.Show less
1Ibm
1Application Performance Management
Jun 17, 2026
Sep 17, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
IBM Cloud Application Performance Management 8.1.4 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vul...Show more
IBM Cloud Application Performance Management 8.1.4 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 157509.Show less
1Logmein
1Lastpass
Jun 17, 2026
Sep 16, 2019
N/A· v4
8.2 HIGH· v3
5.8 MEDIUM· v2
LogMeIn LastPass before 4.33.0 allows attackers to construct a crafted web site that captures the credentials for a victim's account on a previously visited web site, because do_popupregister can be bypassed via clickjac...Show more
LogMeIn LastPass before 4.33.0 allows attackers to construct a crafted web site that captures the credentials for a victim's account on a previously visited web site, because do_popupregister can be bypassed via clickjacking.Show less
1Limesurvey
1Limesurvey
Jun 17, 2026
Sep 9, 2019
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
A clickjacking vulnerability was found in Limesurvey before 3.17.14.
1Google
1Android
Jun 17, 2026
Aug 20, 2019
N/A· v4
7.3 HIGH· v3
4.4 MEDIUM· v2
In ChangeDefaultDialerDialog.java, there is a possible escalation of privilege due to an overlay attack. This could lead to local escalation of privilege, granting privileges to a local app without the user's informed co...Show more
In ChangeDefaultDialerDialog.java, there is a possible escalation of privilege due to an overlay attack. This could lead to local escalation of privilege, granting privileges to a local app without the user's informed consent, with no additional privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-132275252.Show less
1Mcafee
1Web Gateway
Jun 17, 2026
Aug 14, 2019
N/A· v4
7.1 HIGH· v3
5.8 MEDIUM· v2
Clickjack vulnerability in Adminstrator web console in McAfee Web Gateway (MWG) 7.8.2.x prior to 7.8.2.12 allows remote attackers to conduct clickjacking attacks via a crafted web page that contains an iframe via does no...Show more
Clickjack vulnerability in Adminstrator web console in McAfee Web Gateway (MWG) 7.8.2.x prior to 7.8.2.12 allows remote attackers to conduct clickjacking attacks via a crafted web page that contains an iframe via does not send an X-Frame-Options HTTP header.Show less