CWE-356: Product UI does not Warn User of Unsafe Actions
The product's user interface does not warn the user before undertaking an unsafe action on behalf of that user. This makes it easier for attackers to trick users into inflicting damage to their system.
29 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-3839 — Epiphany: insecure external protocol invocation in epiphany
- CVE-2025-2450 — NI Vision Builder AI VBAI File Processing Missing Warning Remote Code Execution Vulnerability
- CVE-2025-14417 — pdfforge PDF Architect Launch Insufficient UI Warning Remote Code Execution Vulnerability
- CVE-2025-14414 — Soda PDF Desktop Word File Insufficient UI Warning Remote Code Execution Vulnerability
- CVE-2025-14412 — Soda PDF Desktop XLS File Insufficient UI Warning Remote Code Execution Vulnerability
- CVE-2025-14403 — PDFsam Enhanced Launch Insufficient UI Warning Remote Code Execution Vulnerability
- CVE-2025-14418 — pdfforge PDF Architect XLS File Insufficient UI Warning Remote Code Execution Vulnerability
- CVE-2025-14416 — pdfforge PDF Architect DOC File Insufficient UI Warning Remote Code Execution Vulnerability
- CVE-2025-14415 — Soda PDF Desktop Launch Insufficient UI Warning Remote Code Execution Vulnerability
- CVE-2025-14404 — PDFsam Enhanced XLS File Insufficient UI Warning Remote Code Execution Vulnerability
- CVE-2025-14402 — PDFsam Enhanced DOC File Insufficient UI Warning Remote Code Execution Vulnerability
- CVE-2025-31334 — Issue that bypasses the "Mark of the Web" security warning function for files when opening a symbolic link that points t
- CVE-2026-25805 — Zed does not show Parameter Values for MCP Tool Calls. Users cannot detect tool poisoning.
- CVE-2025-58335 — In JetBrains Junie before 252.284.66, 251.284.66, 243.284.66, 252.284.61, 251.284.61, 243.284.61, 252.284.50, 252.284.54
- CVE-2024-4187 — Stored XSS vulnerability has been discovered in OpenText™ Filr. The vulnerability could cause users to not be warned when clicking links to external sites.
Recently published
- CVE-2026-25805 — Zed does not show Parameter Values for MCP Tool Calls. Users cannot detect tool poisoning.
- CVE-2025-3839 — Epiphany: insecure external protocol invocation in epiphany
- CVE-2025-14414 — Soda PDF Desktop Word File Insufficient UI Warning Remote Code Execution Vulnerability
- CVE-2025-14415 — Soda PDF Desktop Launch Insufficient UI Warning Remote Code Execution Vulnerability
- CVE-2025-14412 — Soda PDF Desktop XLS File Insufficient UI Warning Remote Code Execution Vulnerability
- CVE-2025-14418 — pdfforge PDF Architect XLS File Insufficient UI Warning Remote Code Execution Vulnerability
- CVE-2025-14417 — pdfforge PDF Architect Launch Insufficient UI Warning Remote Code Execution Vulnerability
- CVE-2025-14416 — pdfforge PDF Architect DOC File Insufficient UI Warning Remote Code Execution Vulnerability
- CVE-2025-14404 — PDFsam Enhanced XLS File Insufficient UI Warning Remote Code Execution Vulnerability
- CVE-2025-14403 — PDFsam Enhanced Launch Insufficient UI Warning Remote Code Execution Vulnerability
- CVE-2025-14402 — PDFsam Enhanced DOC File Insufficient UI Warning Remote Code Execution Vulnerability
- CVE-2025-58335 — In JetBrains Junie before 252.284.66, 251.284.66, 243.284.66, 252.284.61, 251.284.61, 243.284.61, 252.284.50, 252.284.54
- CVE-2025-31334 — Issue that bypasses the "Mark of the Web" security warning function for files when opening a symbolic link that points t
- CVE-2025-2450 — NI Vision Builder AI VBAI File Processing Missing Warning Remote Code Execution Vulnerability
- CVE-2024-4187 — Stored XSS vulnerability has been discovered in OpenText™ Filr. The vulnerability could cause users to not be warned when clicking links to external sites.