<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Clickjacking (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/clickjacking.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/clickjacking-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Clickjacking (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:34 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2025-34413 – Legality WHISTLEBLOWING by DigitalPA contains a protection mechanism failure in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-34413</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-34413</guid>
    <pubDate>Tue, 09 Dec 2025 18:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-34413</strong></p>
  <p>Legality WHISTLEBLOWING by DigitalPA contains a protection mechanism failure in which critical HTTP security headers are not emitted by default. Affected deployments omit Content-Security-Policy, Referrer-Policy, Permissions-Policy, Cross-Origin-Embedder-Policy, Cross-Origin-Opener-Policy, and Cross-Origin-Resource-Policy (with CSP delivered via HTML meta elements being inadequate). The absence o…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-693</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-34413">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-34114 – A client-side security misconfiguration vulnerability exists in OpenBlow whistle...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-34114</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-34114</guid>
    <pubDate>Fri, 25 Jul 2025 16:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-34114</strong></p>
  <p>A client-side security misconfiguration vulnerability exists in OpenBlow whistleblowing platform across multiple versions and default deployments, due to the absence of critical HTTP response headers including Content-Security-Policy, Referrer-Policy, Permissions-Policy, Cross-Origin-Embedder-Policy, and Cross-Origin-Resource-Policy. This omission weakens browser-level defenses and exposes users…</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-34114">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-49144 – Notepad++ is a free and open-source source code editor. In versions 8.8.1 and pr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-49144</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-49144</guid>
    <pubDate>Mon, 23 Jun 2025 19:15:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-49144</strong></p>
  <p>Notepad++ is a free and open-source source code editor. In versions 8.8.1 and prior, a privilege escalation vulnerability exists in the Notepad++ v8.8.1 installer that allows unprivileged users to gain SYSTEM-level privileges through insecure executable search paths. An attacker could use social engineering or clickjacking to trick users into downloading both the legitimate installer and a malici…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-272</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-49144">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-33377 – LB-LINK BL-W1210M v2.0 was discovered to contain a clickjacking vulnerability vi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-33377</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-33377</guid>
    <pubDate>Fri, 14 Jun 2024 15:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-33377</strong></p>
  <p>LB-LINK BL-W1210M v2.0 was discovered to contain a clickjacking vulnerability via the Administrator login page. Attackers can cause victim users to perform arbitrary operations via interaction with crafted elements on the web page.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-33377">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-41897 – Home assistant is an open source home automation. Home Assistant server does not...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-41897</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-41897</guid>
    <pubDate>Thu, 19 Oct 2023 23:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-41897</strong></p>
  <p>Home assistant is an open source home automation. Home Assistant server does not set any HTTP security headers, including the X-Frame-Options header, which specifies whether the web page is allowed to be framed. The omission of this and correlating headers facilitates covert clickjacking attacks and alternative exploit opportunities, such as the vector described in this security advisory. This fa…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-41897">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-34087 – In Ultimaker S3 3D printer, Ultimaker S5 3D printer, Ultimaker 3 3D printer S-li...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-34087</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-34087</guid>
    <pubDate>Mon, 10 Jan 2022 14:10:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-34087</strong></p>
  <p>In Ultimaker S3 3D printer, Ultimaker S5 3D printer, Ultimaker 3 3D printer S-line through 6.3 and Ultimaker 3 through 5.2.16, the local webserver can be used for clickjacking. This includes the settings page.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-34087">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-43048 – The Interior Server and Gateway Server components of TIBCO Software Inc.'s TIBCO...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-43048</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-43048</guid>
    <pubDate>Tue, 16 Nov 2021 18:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-43048</strong></p>
  <p>The Interior Server and Gateway Server components of TIBCO Software Inc.'s TIBCO PartnerExpress contain a vulnerability that theoretically allows an unauthenticated attacker with network access to execute a clickjacking attack on the affected system. A successful attack using this vulnerability does not require human interaction from a person other than the attacker. Affected releases are TIBCO S…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-43048">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-23274 – The Config UI component of TIBCO Software Inc.'s TIBCO API Exchange Gateway and ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-23274</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-23274</guid>
    <pubDate>Tue, 23 Mar 2021 17:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-23274</strong></p>
  <p>The Config UI component of TIBCO Software Inc.'s TIBCO API Exchange Gateway and TIBCO API Exchange Gateway Distribution for TIBCO Silver Fabric contains a vulnerability that theoretically allows an unauthenticated attacker with network access to execute a clickjacking attack on the affected system. A successful attack using this vulnerability does not require human interaction from a person other…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-23274">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-13119 – ismartgate PRO 1.5.9 is vulnerable to clickjacking.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-13119</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-13119</guid>
    <pubDate>Thu, 24 Sep 2020 16:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-13119</strong></p>
  <p>ismartgate PRO 1.5.9 is vulnerable to clickjacking.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-13119">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-8201 – Node.js &lt; 12.18.4 and &lt; 14.11 can be exploited to perform HTTP desync attacks an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-8201</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-8201</guid>
    <pubDate>Fri, 18 Sep 2020 21:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-8201</strong></p>
  <p>Node.js < 12.18.4 and < 14.11 can be exploited to perform HTTP desync attacks and deliver malicious payloads to unsuspecting users. The payloads can be crafted by an attacker to hijack user sessions, poison cookies, perform clickjacking, and a multitude of other attacks depending on the architecture of the underlying system. The attack was possible due to a bug in processing of carrier-return sym…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-444</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-8201">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-5686 – Parts of the Puppet Enterprise Console 3.x were found to be susceptible to click...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-5686</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-5686</guid>
    <pubDate>Thu, 27 Feb 2020 01:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-5686</strong></p>
  <p>Parts of the Puppet Enterprise Console 3.x were found to be susceptible to clickjacking and CSRF (Cross-Site Request Forgery) attacks. This would allow an attacker to redirect user input to an untrusted site or hijack a user session.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-5686">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-16371 – LogMeIn LastPass before 4.33.0 allows attackers to construct a crafted web site ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-16371</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-16371</guid>
    <pubDate>Mon, 16 Sep 2019 18:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-16371</strong></p>
  <p>LogMeIn LastPass before 4.33.0 allows attackers to construct a crafted web site that captures the credentials for a victim's account on a previously visited web site, because do_popupregister can be bypassed via clickjacking.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-16371">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-3639 – Clickjack vulnerability in Adminstrator web console in McAfee Web Gateway (MWG) ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-3639</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-3639</guid>
    <pubDate>Wed, 14 Aug 2019 17:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-3639</strong></p>
  <p>Clickjack vulnerability in Adminstrator web console in McAfee Web Gateway (MWG) 7.8.2.x prior to 7.8.2.12 allows remote attackers to conduct clickjacking attacks via a crafted web page that contains an iframe via does not send an X-Frame-Options HTTP header.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-3639">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-16775 – Improper restriction of rendered UI layers or frames vulnerability in SSOOauth.c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-16775</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-16775</guid>
    <pubDate>Mon, 01 Apr 2019 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-16775</strong></p>
  <p>Improper restriction of rendered UI layers or frames vulnerability in SSOOauth.cgi in Synology SSO Server before 2.1.3-0129 allows remote attackers to conduct clickjacking attacks via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-16775">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-18496 – When the RSS Feed preview about:feeds page is framed within another page, it can...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-18496</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-18496</guid>
    <pubDate>Thu, 28 Feb 2019 18:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-18496</strong></p>
  <p>When the RSS Feed preview about:feeds page is framed within another page, it can be used in concert with scripted content for a clickjacking attack that confuses users into downloading and executing an executable file from a temporary directory. *Note: This issue only affects Windows operating systems. Other operating systems are not affected.*. This vulnerability affects Firefox < 64.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-18496">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-7491 – In PrestaShop through 1.7.2.5, a UI-Redressing/Clickjacking vulnerability was fo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-7491</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-7491</guid>
    <pubDate>Mon, 26 Feb 2018 17:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-7491</strong></p>
  <p>In PrestaShop through 1.7.2.5, a UI-Redressing/Clickjacking vulnerability was found that might lead to state-changing impact in the context of a user or an admin, because the generateHtaccess function in classes/Tools.php sets neither X-Frame-Options nor 'Content-Security-Policy "frame-ancestors' values.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-7491">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-1000479 – pfSense versions 2.4.1 and lower are vulnerable to clickjacking attacks in the C...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-1000479</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-1000479</guid>
    <pubDate>Wed, 03 Jan 2018 18:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-1000479</strong></p>
  <p>pfSense versions 2.4.1 and lower are vulnerable to clickjacking attacks in the CSRF error page resulting in privileged execution of arbitrary code, because the error detection occurs before an X-Frame-Options header is set. This is fixed in 2.4.2-RELEASE. OPNsense, a 2015 fork of pfSense, was not vulnerable since version 16.1.16 released on June 06, 2016. The unprotected web form was removed from…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-1000479">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-3101 – Adobe Connect versions 9.6.1 and earlier have a clickjacking vulnerability. Succ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-3101</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-3101</guid>
    <pubDate>Mon, 17 Jul 2017 13:18:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-3101</strong></p>
  <p>Adobe Connect versions 9.6.1 and earlier have a clickjacking vulnerability. Successful exploitation could lead to a clickjacking attack.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-3101">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-2831 – Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 do not ensure that ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-2831</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-2831</guid>
    <pubDate>Mon, 13 Jun 2016 10:59:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-2831</strong></p>
  <p>Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 do not ensure that the user approves the fullscreen and pointerlock settings, which allows remote attackers to cause a denial of service (UI outage), or conduct clickjacking or spoofing attacks, via a crafted web site.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-254</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-2831">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2014-2063 – Jenkins before 1.551 and LTS before 1.532.2 allows remote attackers to conduct c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-2063</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-2063</guid>
    <pubDate>Fri, 17 Oct 2014 15:55:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2014-2063</strong></p>
  <p>Jenkins before 1.551 and LTS before 1.532.2 allows remote attackers to conduct clickjacking attacks via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-2063">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
