CWE-1021

Improper Restriction of Rendered UI Layers or Frames

Parent: CWE-441 - Unintended Proxy or Intermediary ('Confused Deputy')

The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain, which can lead to user confusion about which interface the user is interacting with.

372 vulnerabilities with CWE-1021
CVE-2026-0007 HIGH
WindowInfo.cpp - Privilege Escalation
CVSS 8.6
CVE-2025-58405 MEDIUM
CGM CLININET - Clickjacking
CVSS 6.1
CVE-2026-27511 MEDIUM
Shenzhen Tenda F3 V12.01.01.55 - Clickjacking
CVSS 4.3
CVE-2026-26000 MEDIUM
XWiki Platform <17.9.0, <17.4.6, <16.10.13 - XSS
CVSS 6.1
CVE-2026-20645 MEDIUM
iOS <26.3 & iPadOS <26.3 - Info Disclosure
CVSS 4.6
CVE-2026-24839 MEDIUM
Dokploy <0.26.6 - CSRF
CVSS 4.7
CVE-2026-23731 MEDIUM
WeGIA <3.6.2 - CSRF
CVSS 4.3
CVE-2025-15032 HIGH
Dia <1.9.0 - XSS
CVSS 7.4
CVE-2025-52987 MEDIUM
Juniper Networks Paragon Automation <24.1.1 - CSRF
CVSS 6.1
CVE-2026-22918 MEDIUM
Web Application - CSRF
CVSS 4.3
CVE-2025-65922 MEDIUM
PLANKA 2.0.0 - CSRF
CVSS 4.3
CVE-2025-14812 HIGH
ArcSearch <1.45.2 - CSRF
CVSS 7.5
CVE-2025-14809 HIGH
ArcSearch <1.12.6 - CSRF
CVSS 7.4
CVE-2025-59849 MEDIUM
HCL BigFix Remote Control Lite Web Portal <10.1.0.0326 - XSS
CVSS 4.7
CVE-2025-59479 MEDIUM
CHOCO TEI WATCHER mini - Info Disclosure
CVSS 6.1
CVE-2025-14373 MEDIUM
Google Chrome <143.0.7499.110 - SSRF
CVSS 4.3
CVE-2025-48639 HIGH
Java - Privilege Escalation
CVSS 7.3
CVE-2025-48597 HIGH
Multiple Locations - Privilege Escalation
CVSS 7.8
CVE-2025-63522 MEDIUM
FeehiCMS 2.1.1 - CSRF
CVSS 4.6
CVE-2025-36149 MEDIUM
IBM Concert Software <2.0.0 - CSRF
CVSS 6.3
CVE-2025-13132 HIGH
Browser - Info Disclosure
CVSS 7.4
CVE-2025-0421 MEDIUM
Shopside <05022025 - Info Disclosure
CVSS 4.7
CVE-2025-64387
Web Application - CSRF
CVE-2025-30191 MEDIUM
Email - CSRF
CVSS 5.4
CVE-2025-28129 MEDIUM
Phpgurukul Hostel Mgt Sys 2.1 - CSRF
CVSS 5.4
Details
Vulnerabilities 372