CWE-451Class2 in KEV

User Interface (UI) Misrepresentation of Critical Information

Draft in the CWE catalog · 151 CVEs mapped

151
CVEs mapped
2
In KEV
5.3
Median CVSS
What it is

The user interface (UI) does not properly represent critical information to the user, allowing the information - or its source - to be obscured or spoofed. This is often a component in phishing attacks.

Recent examples
3.1cvss
CVE-2026-63020

CVE-2026-63020 - LOW Severity Vulnerability

A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages  Impact: An attacker may trick authenticated BIG-IP users into accessing malicious links and reflect a spoofed error message in the victim's BIG-IP Configuration utility web browser session. This is a control plane issue; there is no data plane exposure. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

LOWno explanation yet
0%
epss
4.3cvss
CVE-2026-84356

CVE-2026-84356 - MEDIUM Severity Vulnerability

UI misrepresentation in FullScreen in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Low)

MEDIUMno explanation yet
0%
epss
5.4cvss
CVE-2026-84330

CVE-2026-84330 - MEDIUM Severity Vulnerability

UI misrepresentation in FullScreen in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Medium)

MEDIUMno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-451
Abstraction
Class
Structure
Simple
Status
Draft
References (1)