CWE-1021Base

Improper Restriction of Rendered UI Layers or Frames

Incomplete in the CWE catalog · 134 CVEs mapped

134
CVEs mapped
5.4
Median CVSS
What it is

The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain.

Recent examples
6.1cvss
CVE-2026-84139

CVE-2026-84139 - MEDIUM Severity Vulnerability

Clickjacking issue in the DOM: Events component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

MEDIUMno explanation yet
0%
epss
5.4cvss
CVE-2026-75548

CVE-2026-75548 - MEDIUM Severity Vulnerability

The affected Ebyte device web management interface does not restrict the interface from being rendered within an external frame. An unauthenticated remote attacker could use a crafted webpage to mislead an authenticated administrator into initiating unintended configuration changes or disruptive actions.

MEDIUMno explanation yet
0%
epss
7.4cvss
CVE-2026-18534

CVE-2026-18534 - HIGH Severity Vulnerability

ArcSearch for iOS versions prior to 1.48.0 could keep the address bar hidden after a page-initiated scroll, allowing attacker-controlled content to imitate browser interface elements and increasing spoofing risk.

HIGHno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-1021
Abstraction
Base
Structure
Simple
Status
Incomplete
References (5)