Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CWE-1021 (不当限制渲染UI层或帧) — Vulnerability Class 130

130 vulnerabilities classified as CWE-1021 (不当限制渲染UI层或帧). AI Chinese analysis included.

CWE-1021 represents a critical web application weakness where the system fails to properly restrict frame objects or user interface layers belonging to external applications or domains. This vulnerability is typically exploited through clickjacking attacks, where malicious actors embed the target application within an invisible or deceptive iframe on a different domain. By tricking users into interacting with hidden UI elements, attackers can perform unauthorized actions, such as transferring funds or changing account settings, without the user’s explicit consent or awareness. To mitigate this risk, developers must implement robust security headers, specifically the Content-Security-Policy (CSP) frame-ancestors directive, which explicitly defines which origins are permitted to embed the application. Additionally, setting the X-Frame-Options header to DENY or SAMEORIGIN provides an effective defense by preventing the browser from rendering the page within any frame unless it originates from the same domain, thereby neutralizing the attack vector.

MITRE CWE Description
The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain.
Common Consequences (1)
Access Control Gain Privileges or Assume Identity, Bypass Protection Mechanism, Read Application Data, Modify Application Data
An attacker can trick a user into performing actions that are masked and hidden from the user's view. The impact varies widely, depending on the functionality of the underlying application. For example, in a social media application, clickjacking could be used to trick the user into changing privacy…
Mitigations (4)
Implementation The use of X-Frame-Options allows developers of web content to restrict the usage of their application within the form of overlays, frames, or iFrames. The developer can indicate from which domains can frame the content. The concept of X-Frame-Options is well documented, but implementation of this protection mechanism is in development to cover gaps. There is a need for allowing frames from multip…
Implementation A developer can use a "frame-breaker" script in each page that should not be framed. This is very helpful for legacy browsers that do not support X-Frame-Options security feature previously mentioned. It is also important to note that this tactic has been circumvented or bypassed. Improper usage of frames can persist in the web application through nested frames. The "frame-breaking" script does no…
Implementation This defense-in-depth technique can be used to prevent the improper usage of frames in web applications. It prioritizes the valid sources of data to be loaded into the application through the usage of declarative policies. Based on which implementation of Content Security Policy is in use, the developer should use the "frame-ancestors" directive or the "frame-src" directive to mitigate this weakne…
Implementation In addition to frames or iframes as previously mentioned, the web application is expected to place restrictions on whether it is allowed to be rendered within objects, embed, or applet elements.
CVE ID Title CVSS Severity Published
CVE-2026-106400 Chrome Android低于155.0.8059.39点击劫持漏洞 — Chrome - - 2026-10-06
CVE-2026-106356 Chrome <155.0.8059.39 EVP点击劫持漏洞 — Chrome - - 2026-10-06
CVE-2026-106311 Chrome < 155.0.8059.39 Clickjacking漏洞 — Chrome - - 2026-10-06
CVE-2026-71177 Dell SCG Policy Manager 5.34前UI限制致提权 — Secure Connect Gateway (SCG) Policy Manager 5.4 Medium 2026-09-23
CVE-2026-84388 FortiPAM扩展7.4/8.0信息泄露 — FortiPAM Chrome Extension 9.1 Critical 2026-09-22
CVE-2026-87538 Google Chrome 处理逻辑错误漏洞 — Chrome - - 2026-09-09
CVE-2026-87655 Google Chrome 处理逻辑错误漏洞 — Chrome - - 2026-09-09
CVE-2026-87486 Google Chrome 处理逻辑错误漏洞 — Chrome - - 2026-09-09
CVE-2026-75548 Ebyte NA111-M Improper Restriction of Rendered UI Layers or Frames — Ebyte NA111-M Firmware 5.4 Medium 2026-08-27
CVE-2026-18534 Address bar spoofing risk in affected iOS versions of Arc Search — ArcSearch 7.4 High 2026-08-18
CVE-2026-44762 Security Misconfiguration in SAP Data Services Management Console — SAP Data Services Management Console 3.7 Low 2026-08-11
CVE-2026-70600 Electron: Cross-origin iframe can position native autofill popup — electron 3.1 Low 2026-08-05
CVE-2026-47723 nebula-mesh: Web UI and API responses lack security headers (CSP, X-Frame-Options, HSTS, etc.) — nebula-mesh 7.1 High 2026-07-23
CVE-2026-58595 Microsoft Bing App for IOS Spoofing Vulnerability — Microsoft Bing Search for iOS 8.1 High 2026-07-14
CVE-2026-59791 JetBrains YouTrack 处理逻辑错误漏洞 — YouTrack 3.5 Low 2026-07-10
CVE-2026-12348 Address Bar Spoofing in Arc Search for Android (window.open race condition) — Arc Search 7.4 High 2026-06-16
CVE-2026-10733 Improper Restriction of Rendered UI Layers or Frames in GitLab — GitLab 4.3 Medium 2026-06-11
CVE-2026-21785 HCL BigFix Remote Control Server WebUI is affected by a misconfigured Content Security Policy — BigFix Remote Control Server 4.0 Medium 2026-05-27
CVE-2026-9396 Besen BS20 EV Charging Station Firmware Version Check ui layer — BS20 EV Charging Station 3.7 Low 2026-05-24
CVE-2025-62316 HCL AION is affected by a vulnerability where certain security-related HTTP response headers are not properly configured — AION 2.3 Low 2026-05-14
CVE-2026-3254 Improper Restriction of Rendered UI Layers or Frames in GitLab — GitLab 3.5 Low 2026-04-22
CVE-2026-2378 Address bar spoofing risk in ArcSearch on Android — ArcSearch 7.4 High 2026-03-20
CVE-2025-62328 HCL Nomad server on Domino is affected by a missing default frame-ancestors directive — Nomad server on Domino 3.7 Low 2026-03-11
CVE-2025-58405 Lack of protection mechanisms against Clickjacking attacks — CGM CLININET 6.5AI Medium AI 2026-03-02
CVE-2026-27511 Tenda F3 Clickjacking in Web Management Interface — Tenda F3 4.3 Medium 2026-02-23
CVE-2026-26000 XWiki Platform affected by click-jacking through CSS injection in comments — xwiki-platform 4.1AI Medium AI 2026-02-12
CVE-2026-24839 Dokploy has a clickjacking vulnerability - Missing X-Frame-Options and CSP frame-ancestors headers — dokploy 4.7 Medium 2026-01-28
CVE-2026-23731 WeGIA Clickjacking Vulnerability — WeGIA 4.3 Medium 2026-01-16
CVE-2025-15032 CVE-2025-15032: Increased Spoofing risk; custom new window missing about:blank — Dia 7.4 High 2026-01-16
CVE-2025-52987 Paragon Automation: A clickjacking vulnerability in the web server configuration has been addressed — Paragon Automation (Pathfinder, Planner, Insights) 6.1 Medium 2026-01-15

Vulnerabilities classified as CWE-1021 (不当限制渲染UI层或帧) represent 130 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.