目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CWE-1021 不当限制渲染UI层或帧 类漏洞列表 130

CWE-1021 不当限制渲染UI层或帧 类弱点 130 条 CVE 漏洞汇总,含 AI 中文分析。

CWE-1021属于界面层限制不当漏洞,指Web应用未正确限制来自其他应用或域名的框架对象及UI层。攻击者常利用此缺陷,通过嵌入恶意iframe或覆盖合法界面,实施点击劫持或内容注入,诱导用户交互以窃取数据或执行未授权操作。开发者应避免直接嵌入不可信源,通过设置X-Frame-Options响应头或Content-Security-Policy策略,严格限制页面被帧嵌入的范围,从而有效隔离不同域名的UI层,保障用户界面完整性。

MITRE CWE 官方描述
CWE:CWE-1021 渲染 UI 层或框架的限制不当 英文:Web 应用程序未对属于其他应用程序或域名的 frame 对象或 UI 层进行限制,或限制不当。
常见影响 (1)
Access Control Gain Privileges or Assume Identity, Bypass Protection Mechanism, Read Application Data, Modify Application Data
An attacker can trick a user into performing actions that are masked and hidden from the user's view. The impact varies widely, depending on the functionality of the underlying application. For example, in a social media application, clickjacking could be used to trick the user into changing privacy…
缓解措施 (4)
Implementation The use of X-Frame-Options allows developers of web content to restrict the usage of their application within the form of overlays, frames, or iFrames. The developer can indicate from which domains can frame the content. The concept of X-Frame-Options is well documented, but implementation of this protection mechanism is in development to cover gaps. There is a need for allowing frames from multip…
Implementation A developer can use a "frame-breaker" script in each page that should not be framed. This is very helpful for legacy browsers that do not support X-Frame-Options security feature previously mentioned. It is also important to note that this tactic has been circumvented or bypassed. Improper usage of frames can persist in the web application through nested frames. The "frame-breaking" script does no…
Implementation This defense-in-depth technique can be used to prevent the improper usage of frames in web applications. It prioritizes the valid sources of data to be loaded into the application through the usage of declarative policies. Based on which implementation of Content Security Policy is in use, the developer should use the "frame-ancestors" directive or the "frame-src" directive to mitigate this weakne…
Implementation In addition to frames or iframes as previously mentioned, the web application is expected to place restrictions on whether it is allowed to be rendered within objects, embed, or applet elements.
CVE ID 标题 CVSS 风险等级 Published
CVE-2026-106400 Chrome Android低于155.0.8059.39点击劫持漏洞 — Chrome - - 2026-10-06
CVE-2026-106356 Chrome <155.0.8059.39 EVP点击劫持漏洞 — Chrome - - 2026-10-06
CVE-2026-106311 Chrome < 155.0.8059.39 Clickjacking漏洞 — Chrome - - 2026-10-06
CVE-2026-71177 Dell SCG Policy Manager 5.34前UI限制致提权 — Secure Connect Gateway (SCG) Policy Manager 5.4 Medium 2026-09-23
CVE-2026-84388 FortiPAM扩展7.4/8.0信息泄露 — FortiPAM Chrome Extension 9.1 Critical 2026-09-22
CVE-2026-87538 Google Chrome 处理逻辑错误漏洞 — Chrome - - 2026-09-09
CVE-2026-87655 Google Chrome 处理逻辑错误漏洞 — Chrome - - 2026-09-09
CVE-2026-87486 Google Chrome 处理逻辑错误漏洞 — Chrome - - 2026-09-09
CVE-2026-75548 Ebyte NE2-D11 Firmware 处理逻辑错误漏洞 — Ebyte NA111-M Firmware 5.4 Medium 2026-08-27
CVE-2026-18534 Browser Company ArcSearch 处理逻辑错误漏洞 — ArcSearch 7.4 High 2026-08-18
CVE-2026-44762 SAP Data Services Management Console 处理逻辑错误漏洞 — SAP Data Services Management Console 3.7 Low 2026-08-11
CVE-2026-70600 Electron 处理逻辑错误漏洞 — electron 3.1 Low 2026-08-05
CVE-2026-47723 Forgekeep nebula-mesh 处理逻辑错误漏洞 — nebula-mesh 7.1 High 2026-07-23
CVE-2026-58595 Microsoft Bing Search for iOS 处理逻辑错误漏洞 — Microsoft Bing Search for iOS 8.1 High 2026-07-14
CVE-2026-59791 JetBrains YouTrack 处理逻辑错误漏洞 — YouTrack 3.5 Low 2026-07-10
CVE-2026-12348 The Browser Company of New York Arc Search 处理逻辑错误漏洞 — Arc Search 7.4 High 2026-06-16
CVE-2026-10733 GitLab CE/EE 安全漏洞 — GitLab 4.3 Medium 2026-06-11
CVE-2026-21785 HCL BigFix Remote Control Server WebUI 安全漏洞 — BigFix Remote Control Server 4.0 Medium 2026-05-27
CVE-2026-9396 Besen BS20 EV Charging Station 安全漏洞 — BS20 EV Charging Station 3.7 Low 2026-05-24
CVE-2025-62316 HCL AION 安全漏洞 — AION 2.3 Low 2026-05-14
CVE-2026-3254 GitLab CE/EE 安全漏洞 — GitLab 3.5 Low 2026-04-22
CVE-2026-2378 ArcSearch 安全漏洞 — ArcSearch 7.4 High 2026-03-20
CVE-2025-62328 HCL Nomad Server 安全漏洞 — Nomad server on Domino 3.7 Low 2026-03-11
CVE-2025-58405 CGM CLININET 安全漏洞 — CGM CLININET 6.5AI Medium AI 2026-03-02
CVE-2026-27511 Tenda F3 安全漏洞 — Tenda F3 4.3 Medium 2026-02-23
CVE-2026-26000 XWiki Platform 安全漏洞 — xwiki-platform 4.1AI Medium AI 2026-02-12
CVE-2026-24839 Dokploy 安全漏洞 — dokploy 4.7 Medium 2026-01-28
CVE-2026-23731 WeGIA 安全漏洞 — WeGIA 4.3 Medium 2026-01-16
CVE-2025-15032 Dia 安全漏洞 — Dia 7.4 High 2026-01-16
CVE-2025-52987 Juniper Networks Paragon Automation 安全漏洞 — Paragon Automation (Pathfinder, Planner, Insights) 6.1 Medium 2026-01-15

CWE-1021(不当限制渲染UI层或帧) 是常见的弱点类别,本平台收录该类弱点关联的 130 条 CVE 漏洞。