CWE-1021: CWE-1021

68
Total CVEs
3
Critical
28
High
6.4
Avg CVSS

Yearly Trend

2026
9
2025
28
2024
15
2023
2
2022
4

Top Affected Vendors

1 Google 23
2 Mozilla 7
3 Ibm 4
4 Huawei 3
5 Gitlab 2
6 Sick 2
7 Wegia 1
8 Xwiki 1
9 Ruoyi 1
10 Freshrss 1

All CWE-1021 CVEs (68)

CVE-2024-6466
5.3

This vulnerability in NEC WebSAM DeploymentManager allows attackers to reset configurations or restart products via network requests when X-FRAME-OPTI...

Jan 21, 2025
CVE-2026-24839
4.7

Dokploy versions before 0.26.6 are vulnerable to clickjacking attacks due to missing frame-busting headers. This allows attackers to embed Dokploy's w...

Jan 28, 2026
CVE-2025-0421
4.7

This vulnerability allows attackers to overlay malicious iFrames on top of legitimate Shopside application interfaces, potentially tricking users into...

Nov 19, 2025
CVE-2026-20645
4.6

This CVE describes a user interface inconsistency vulnerability in Apple iOS and iPadOS that allows an attacker with physical access to a locked devic...

Feb 11, 2026
CVE-2026-27511
4.3

This clickjacking vulnerability in Tenda F3 router's web interface allows malicious websites to embed the admin panel in invisible frames. An authenti...

Feb 23, 2026
CVE-2026-23731
4.3

This CVE describes a clickjacking vulnerability in WeGIA web management software for charitable institutions. Attackers can embed WeGIA pages in malic...

Jan 16, 2026
CVE-2026-22918
4.3

This CVE describes a clickjacking vulnerability where attackers can trick users into performing unintended actions on web interfaces, potentially lead...

Jan 15, 2026
CVE-2025-65922
4.3

PLANKA 2.0.0 lacks X-Frame-Options and CSP frame-ancestors headers, allowing the application to be embedded in malicious iframes. This enables UI redr...

Jan 5, 2026
CVE-2025-14373
4.3

This vulnerability allows attackers to spoof website domains in the Chrome toolbar on Android devices, potentially tricking users into believing they'...

Dec 12, 2025
CVE-2024-13066
4.3

This CVE describes a clickjacking vulnerability in Akinsoft LimonDesk where attackers can overlay malicious iFrames on legitimate pages, tricking user...

Sep 3, 2025
CVE-2025-9108
4.3

This vulnerability allows attackers to manipulate the login page interface layers improperly, potentially enabling UI-based attacks like clickjacking ...

Aug 18, 2025
CVE-2025-54139
4.3

HAX CMS versions 11.0.12 and below (NodeJS) and 11.0.7 and below (PHP) lack X-Frame-Options headers, allowing attackers to embed the CMS login page an...

Jul 23, 2025
CVE-2025-7903
4.3

This vulnerability in RuoYi's Image Source Handler allows attackers to bypass UI layer restrictions, potentially enabling unauthorized interface manip...

Jul 20, 2025
CVE-2025-27455
4.3

This clickjacking vulnerability allows attackers to embed the web application in malicious frames, tricking users into clicking hidden elements. This ...

Jul 3, 2025
CVE-2025-49192
4.3

This clickjacking vulnerability allows attackers to embed the vulnerable web application in an invisible frame and trick users into clicking malicious...

Jun 12, 2025
CVE-2025-1923
4.3

This vulnerability allows attackers who convince users to install malicious Chrome extensions to perform UI spoofing attacks. The malicious extension ...

Mar 5, 2025
CVE-2025-1917
4.3

This vulnerability allows attackers to spoof browser UI elements in Google Chrome on Android, potentially tricking users into interacting with malicio...

Mar 5, 2025
CVE-2023-42011
4.3

This vulnerability in IBM Sterling B2B Integrator allows clickjacking attacks where malicious websites can embed the application's interface in hidden...

Jun 27, 2024

About CWE-1021 (CWE-1021)

Our database tracks 68 CVEs classified as CWE-1021, with 3 rated critical and 28 rated high severity. The average CVSS score for CWE-1021 vulnerabilities is 6.4.

External reference: View CWE-1021 on MITRE CWE →

Monitor CWE-1021 Vulnerabilities

Get alerted when new CWE-1021 CVEs affect your infrastructure.

Start Monitoring Free