CWE-357: Insufficient UI Warning of Dangerous Operations
The user interface provides a warning to a user regarding dangerous or sensitive operations, but the warning is not noticeable enough to warrant attention.
20 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-49585 — XWiki does not require right warnings for XClass definitions
- CVE-2025-49582 — XWiki's required right warnings for macros are incomplete
- CVE-2025-49587 — XWiki does not require right warnings for notification displayer objects
- CVE-2025-49583 — XWiki provides no warning when granting XWiki.Notifications.Code.NotificationEmailRendererClass admin right
- CVE-2026-47782 — Android App "RoboForm Password Manager" provided by Siber Systems, Inc. handles Android intents without sufficient URL v
Recently published
- CVE-2026-47782 — Android App "RoboForm Password Manager" provided by Siber Systems, Inc. handles Android intents without sufficient URL v
- CVE-2025-49587 — XWiki does not require right warnings for notification displayer objects
- CVE-2025-49585 — XWiki does not require right warnings for XClass definitions
- CVE-2025-49583 — XWiki provides no warning when granting XWiki.Notifications.Code.NotificationEmailRendererClass admin right
- CVE-2025-49582 — XWiki's required right warnings for macros are incomplete
More specific weaknesses
- CWE-450 — Multiple Interpretations of UI Input