CWE-1021: Improper Restriction of Rendered UI Layers or Frames
The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain.
131 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-44727 — Jupyter Server: Stored XSS in `NbconvertFileHandler` / `NbconvertPostHandler` via missing `sandbox` CSP
- CVE-2025-14812 — Address bar spoofing risk in Arc Search on iOS
- CVE-2026-2378 — Address bar spoofing risk in ArcSearch on Android
- CVE-2025-15032 — CVE-2025-15032: Increased Spoofing risk; custom new window missing about:blank
- CVE-2025-14809 — Address bar spoofing risk in ArcSearch on Android
- CVE-2025-13132 — Dia: Increased Spoof Risk; Missing full screen toast
- CVE-2026-87655 — Clickjacking in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineerin
- CVE-2026-70486 — Open WebUI: Same-origin XSS to account takeover via terminal file-preview iframe hardcoding allow-same-origin
- CVE-2025-24874 — Missing Defense in Depth Against Clickjacking in SAP Commerce Backoffice
- CVE-2025-59950 — FreshRSS: Double clickjacking can lead to privilege escalation
- CVE-2025-25213 — Improper restriction of rendered UI layers or frames issue exists in Wi-Fi AP UNIT 'AC-WPS-11ac series'. If a user views
- CVE-2024-28196 — Clickjacking in your_spotify
- CVE-2025-0362 — Improper Restriction of Rendered UI Layers or Frames in GitLab
- CVE-2024-1890 — Clickjacking vulnerability in Sunny Webbox
- CVE-2025-36149 — IBM Concert Software clickjacking
- CVE-2024-0669 — Cross-Frame Scripting (XFS) on Plone CMS
- CVE-2026-12348 — Address Bar Spoofing in Arc Search for Android (window.open race condition)
- CVE-2024-56435 — Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability
- CVE-2026-18534 — Address bar spoofing risk in affected iOS versions of Arc Search
- CVE-2025-54527 — In JetBrains YouTrack before 2025.2.86935, 2025.2.87167, 2025.3.87341, 2025.3.87344 improper iframe configuration in
Recently published
- CVE-2026-87538 — Clickjacking in Input in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer
- CVE-2026-87655 — Clickjacking in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineerin
- CVE-2026-87486 — Clickjacking in TrustedWebActivities in Google Chrome on on Android prior to 153.0.8010.36 allowed a local attacker to s
- CVE-2026-75548 — Ebyte NA111-M Improper Restriction of Rendered UI Layers or Frames
- CVE-2026-18534 — Address bar spoofing risk in affected iOS versions of Arc Search
- CVE-2026-44762 — Security Misconfiguration in SAP Data Services Management Console
- CVE-2026-70608 — Electron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navigation path
- CVE-2026-70600 — Electron: Cross-origin iframe can position native autofill popup
- CVE-2026-70486 — Open WebUI: Same-origin XSS to account takeover via terminal file-preview iframe hardcoding allow-same-origin
- CVE-2026-47723 — nebula-mesh: Web UI and API responses lack security headers (CSP, X-Frame-Options, HSTS, etc.)
- CVE-2026-59791 — In JetBrains YouTrack before 2026.2.17012 cSS injection via Mermaid diagram rendering was possible
- CVE-2026-44727 — Jupyter Server: Stored XSS in `NbconvertFileHandler` / `NbconvertPostHandler` via missing `sandbox` CSP
- CVE-2026-12348 — Address Bar Spoofing in Arc Search for Android (window.open race condition)
- CVE-2026-10733 — Improper Restriction of Rendered UI Layers or Frames in GitLab
- CVE-2026-21785 — HCL BigFix Remote Control Server WebUI is affected by a misconfigured Content Security Policy
- CVE-2026-9396 — Besen BS20 EV Charging Station Firmware Version Check ui layer
- CVE-2025-62316 — HCL AION is affected by a vulnerability where certain security-related HTTP response headers are not properly configured
- CVE-2026-3254 — Improper Restriction of Rendered UI Layers or Frames in GitLab
- CVE-2026-2378 — Address bar spoofing risk in ArcSearch on Android
- CVE-2025-62328 — HCL Nomad server on Domino is affected by a missing default frame-ancestors directive