CWE-1021

Improper Restriction of Rendered UI Layers or Frames

Parent: CWE-441 - Unintended Proxy or Intermediary ('Confused Deputy')

The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain.

401 vulnerabilities with CWE-1021
CVE-2026-47723 HIGH
nebula-mesh: Web UI and API responses lack security headers (CSP, X-Frame-Options, HSTS, etc.)
CVE-2026-60370 HIGH
Oracle Platform Security for Java 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Takeover via HTTP
CVSS 7.5
CVE-2026-16397 MEDIUM
Mozilla Firefox for Android WebExtensions - Clickjacking
CVSS 6.5
CVE-2026-40957 HIGH
Absolute Secure Access < 14.55 Login Page - Clickjacking Credential Theft
CVSS 7.5
CVE-2026-58595 HIGH
Microsoft Bing App for IOS Spoofing Vulnerability
CVSS 8.1
CVE-2026-59791 LOW
Jetbrains YouTrack < 2026.2.17012 - Improper Restriction of Rendered UI Layers or Frames
CVSS 3.5
CVE-2026-38979 MEDIUM
ajenti <= 2.2.13 - Clickjacking via Missing Anti-Framing Headers
CVSS 5.4
CVE-2026-14142 MEDIUM
Google Chrome < 150.0.7871.47 - UI Spoofing via Crafted HTML Page
CVSS 5.4
CVE-2026-14110 MEDIUM
Google Chrome < 150.0.7871.47 - UI Spoofing via DarkMode Implementation
CVSS 4.3
CVE-2026-44727 MEDIUM
Jupyter Server: Stored XSS in `NbconvertFileHandler` / `NbconvertPostHandler` via missing `sandbox` CSP
CVSS 5.4
CVE-2026-12348 HIGH
Address Bar Spoofing in Arc Search for Android (window.open race condition)
CVSS 7.4
CVE-2026-12323 MEDIUM
Mozilla Firefox and Thunderbird - DOM Core and HTML Spoofing
CVSS 5.4
CVE-2026-12322 MEDIUM
Mozilla Firefox and Thunderbird - Widget Gtk Clickjacking
CVSS 5.4
CVE-2026-10733 MEDIUM
Improper Restriction of Rendered UI Layers or Frames in GitLab
CVSS 4.3
CVE-2026-28577 HIGH
Google Android - Improper Restriction of Rendered UI Layers or Frames
CVSS 7.8
CVE-2026-0061 MEDIUM
Android 14-16 WindowState - Tapjacking Privilege Escalation
CVSS 5.9
CVE-2026-0036 HIGH
Android 14-16 StageCoordinator - Tapjacking Privilege Escalation
CVSS 7.8
CVE-2026-21785 MEDIUM
HCL BigFix Remote Control Server WebUI is affected by a misconfigured Content Security Policy
CVSS 4.0
CVE-2026-9396 LOW
Besen BS20 EV Charging Station Firmware Version Check ui layer
CVSS 3.7
CVE-2026-37470 HIGH
ClipBucket v5 v.5.5.2 - Remote Code Execution via Authentication Interface
CVSS 7.3
CVE-2026-42502 MEDIUM
Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html
CVSS 6.1
CVE-2026-27136 MEDIUM
Invoking duplicate attributes can cause XSS in golang.org/x/net/html
CVSS 6.1
CVE-2026-25681 MEDIUM
Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html
CVSS 6.1
CVE-2026-28971 MEDIUM
iOS and iPadOS < 26.5 - UI Layer Restriction Bypass via Malicious Iframe
CVSS 4.3
CVE-2026-8022 LOW
Google Chrome < 148.0.7778.96 - Cross-Origin Data Leak via MHTML
CVSS 3.1
Details
Vulnerabilities 401