<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Clickjacking</title>
  <link>https://cvedaily.com/pages/tags/clickjacking.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/clickjacking.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Clickjacking</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:34 +0000</lastBuildDate>
  <item>
    <title>[Unknown] CVE-2026-38978 – transmission through 4.1.1 was found to have a clickjacking weakness in the brow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-38978</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-38978</guid>
    <pubDate>Tue, 02 Jun 2026 16:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk unknown">Unknown</span> CVE-2026-38978</strong></p>
  <p>transmission through 4.1.1 was found to have a clickjacking weakness in the browser-facing WebUI and RPC response paths.</p>
  <p><strong>CVSS:</strong> N/A · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-38978">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-58406 – The CGM CLININET application respond without essential security HTTP headers, ex...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-58406</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-58406</guid>
    <pubDate>Mon, 02 Mar 2026 12:16:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-58406</strong></p>
  <p>The CGM CLININET application respond without essential security HTTP headers, exposing users to client‑side attacks such as clickjacking, MIME sniffing, unsafe caching, weak cross‑origin isolation, and missing transport security controls.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-693</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58406">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-58405 – The CGM CLININET application does not implement any mechanisms that prevent clic...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-58405</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-58405</guid>
    <pubDate>Mon, 02 Mar 2026 12:16:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-58405</strong></p>
  <p>The CGM CLININET application does not implement any mechanisms that prevent clickjacking attacks, neither HTTP security headers nor HTML-based frame‑busting protections were detected. As a result, an attacker can embed the application inside a maliciously crafted IFRAME and trick users into performing unintended actions, including potentially bypassing CSRF/XSRF defenses.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58405">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-27511 – Shenzhen Tenda F3 Wireless Router firmware V12.01.01.55_multi contains a clickja...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27511</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27511</guid>
    <pubDate>Mon, 23 Feb 2026 17:23:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-27511</strong></p>
  <p>Shenzhen Tenda F3 Wireless Router firmware V12.01.01.55_multi contains a clickjacking vulnerability in the web-based administrative interface. The interface does not set the X-Frame-Options header, allowing attacker-controlled sites to embed administrative pages in an iframe and trick an authenticated administrator into unintended interactions that may result in unauthorized configuration changes.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27511">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-24839 – Dokploy is a free, self-hostable Platform as a Service (PaaS). In versions prior...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24839</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24839</guid>
    <pubDate>Wed, 28 Jan 2026 01:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-24839</strong></p>
  <p>Dokploy is a free, self-hostable Platform as a Service (PaaS). In versions prior to 0.26.6, the Dokploy web interface is vulnerable to Clickjacking attacks due to missing frame-busting headers. This allows attackers to embed Dokploy pages in malicious iframes and trick authenticated users into performing unintended actions. Version 0.26.6 patches the issue.</p>
  <p><strong>CVSS:</strong> 4.7 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24839">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-23731 – WeGIA is a web manager for charitable institutions. Prior to 3.6.2, The web appl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23731</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23731</guid>
    <pubDate>Fri, 16 Jan 2026 20:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-23731</strong></p>
  <p>WeGIA is a web manager for charitable institutions. Prior to 3.6.2, The web application is vulnerable to clickjacking attacks. The WeGIA application does not send any defensive HTTP headers related to framing protection. In particular, X-Frame-Options is missing andContent-Security-Policy with frame-ancestors directive is not configured. Because of this, an attacker can load any WeGIA page inside…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23731">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-52987 – A clickjacking vulnerability exists in the web portal of Juniper Networks Parago...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-52987</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-52987</guid>
    <pubDate>Thu, 15 Jan 2026 21:16:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-52987</strong></p>
  <p>A clickjacking vulnerability exists in the web portal of Juniper Networks Paragon Automation (Pathfinder, Planner, Insights) due to the application's failure to set appropriate X-Frame-Options and X-Content-Type HTTP headers. This vulnerability allows an attacker to trick users into interacting with the interface under the attacker's control.   This issue affects all versions of Paragon Automatio…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-52987">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-22918 – An attacker may exploit missing protection against clickjacking by tricking user...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22918</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22918</guid>
    <pubDate>Thu, 15 Jan 2026 13:16:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-22918</strong></p>
  <p>An attacker may exploit missing protection against clickjacking by tricking users into performing unintended actions through maliciously crafted web pages, leading to the extraction of sensitive data.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22918">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-0887 – Clickjacking issue, information disclosure in the PDF Viewer component. This vul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0887</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0887</guid>
    <pubDate>Tue, 13 Jan 2026 14:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-0887</strong></p>
  <p>Clickjacking issue, information disclosure in the PDF Viewer component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-497</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0887">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-65922 – PLANKA 2.0.0 lacks X-Frame-Options and CSP frame-ancestors headers, allowing the...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-65922</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-65922</guid>
    <pubDate>Mon, 05 Jan 2026 18:15:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-65922</strong></p>
  <p>PLANKA 2.0.0 lacks X-Frame-Options and CSP frame-ancestors headers, allowing the application to be embedded within malicious iframes. While this does not lead to unintended modification of projects or tasks, it exposes users to Phishing attacks. Attackers can frame the legitimate Planka application on a malicious site to establish false trust (UI Redressing), potentially tricking users into enter…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-65922">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-34412 – The Convercent Whistleblowing Platform operated by EQS Group contains a protecti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-34412</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-34412</guid>
    <pubDate>Mon, 15 Dec 2025 15:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-34412</strong></p>
  <p>The Convercent Whistleblowing Platform operated by EQS Group contains a protection mechanism failure in its browser and session handling. By default, affected deployments omit HTTP security headers such as Content-Security-Policy, Referrer-Policy, Permissions-Policy, Cross-Origin-Embedder-Policy, Cross-Origin-Opener-Policy, and Cross-Origin-Resource-Policy, and implement incomplete clickjacking p…</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> CWE-693</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-34412">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-34413 – Legality WHISTLEBLOWING by DigitalPA contains a protection mechanism failure in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-34413</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-34413</guid>
    <pubDate>Tue, 09 Dec 2025 18:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-34413</strong></p>
  <p>Legality WHISTLEBLOWING by DigitalPA contains a protection mechanism failure in which critical HTTP security headers are not emitted by default. Affected deployments omit Content-Security-Policy, Referrer-Policy, Permissions-Policy, Cross-Origin-Embedder-Policy, Cross-Origin-Opener-Policy, and Cross-Origin-Resource-Policy (with CSP delivered via HTML meta elements being inadequate). The absence o…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-693</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-34413">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-52622 – The BigFix SaaS's HTTP responses were missing some security headers. The absence...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-52622</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-52622</guid>
    <pubDate>Tue, 02 Dec 2025 18:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-52622</strong></p>
  <p>The BigFix SaaS's HTTP responses were missing some security headers. The absence of these headers weakens the application's client-side security posture, making it more vulnerable to common web attacks that these headers are designed to mitigate, such as Cross-Site Scripting (XSS), Clickjacking, and protocol downgrade attacks.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-1188</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-52622">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-64387 – The web application is vulnerable to a so-called ‘clickjacking’ attack. In this ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-64387</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-64387</guid>
    <pubDate>Fri, 31 Oct 2025 15:15:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-64387</strong></p>
  <p>The web application is vulnerable to a so-called ‘clickjacking’ attack. In this type of attack, the vulnerable page is inserted into a page controlled by the attacker in order to deceive the victim. This deception can range from making the victim click on a button to making them enter their login credentials in a form that, a priori, appears legitimate.</p>
  <p><strong>CVSS:</strong> 5.1 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-64387">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-31969 – HCL Unica Platform is impacted by misconfigured Content Security Policy (CSP).  ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-31969</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-31969</guid>
    <pubDate>Sun, 12 Oct 2025 08:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-31969</strong></p>
  <p>HCL Unica Platform is impacted by misconfigured Content Security Policy (CSP).  These can result in malicious resources getting loaded and browsers may come across certain types of attacks, such as cross-site scripting and clickjacking.</p>
  <p><strong>CVSS:</strong> 4.0 · <strong>CWE:</strong> CWE-358</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-31969">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-28129 – Phpgurukul Hostel Management System 2.1 is vulnerable to clickjacking.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-28129</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-28129</guid>
    <pubDate>Mon, 06 Oct 2025 18:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-28129</strong></p>
  <p>Phpgurukul Hostel Management System 2.1 is vulnerable to clickjacking.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-28129">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-59950 – FreshRSS is a free, self-hostable RSS aggregator. In versions 1.26.3 and below, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59950</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59950</guid>
    <pubDate>Tue, 30 Sep 2025 04:43:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-59950</strong></p>
  <p>FreshRSS is a free, self-hostable RSS aggregator. In versions 1.26.3 and below, due to a bypass of double clickjacking protection (confirmation dialog), it is possible to trick the admin into clicking the Promote button in another user's management page after the admin double clicks on a button inside an attacker-controlled website. A successful attack can allow the attacker to promote themselves…</p>
  <p><strong>CVSS:</strong> 6.7 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59950">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-0546 – Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-0546</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-0546</guid>
    <pubDate>Wed, 17 Sep 2025 12:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-0546</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting'), Improper Restriction of Rendered UI Layers or Frames vulnerability in Mevzuattr Software MevzuatTR allows Phishing, iFrame Overlay, Clickjacking, Forceful Browsing. This issue needs high privileges. This issue affects MevzuatTR: before 12.02.2025.</p>
  <p><strong>CVSS:</strong> 4.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0546">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-57117 – A Clickjacking vulnerability exists in Rems' Employee Management System 1.0. Thi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-57117</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-57117</guid>
    <pubDate>Mon, 15 Sep 2025 22:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-57117</strong></p>
  <p>A Clickjacking vulnerability exists in Rems' Employee Management System 1.0. This flaw allows remote attackers to execute arbitrary JavaScript on the department.php page by injecting a malicious payload into the Department Name field under Add Department.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-57117">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-13066 – Improper Restriction of Rendered UI Layers or Frames vulnerability in Akinsoft L...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13066</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13066</guid>
    <pubDate>Wed, 03 Sep 2025 13:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-13066</strong></p>
  <p>Improper Restriction of Rendered UI Layers or Frames vulnerability in Akinsoft LimonDesk allows iFrame Overlay, CAPEC - 103 - Clickjacking.  This issue affects LimonDesk: from s1.02.14 before v1.02.17.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13066">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-34114 – A client-side security misconfiguration vulnerability exists in OpenBlow whistle...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-34114</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-34114</guid>
    <pubDate>Fri, 25 Jul 2025 16:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-34114</strong></p>
  <p>A client-side security misconfiguration vulnerability exists in OpenBlow whistleblowing platform across multiple versions and default deployments, due to the absence of critical HTTP response headers including Content-Security-Policy, Referrer-Policy, Permissions-Policy, Cross-Origin-Embedder-Policy, and Cross-Origin-Resource-Policy. This omission weakens browser-level defenses and exposes users…</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-34114">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-54139 – HAX CMS allows users to manage their microsite universe with a NodeJS or PHP bac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54139</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54139</guid>
    <pubDate>Wed, 23 Jul 2025 00:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-54139</strong></p>
  <p>HAX CMS allows users to manage their microsite universe with a NodeJS or PHP backend. In haxcms-nodejs versions 11.0.12 and below and in haxcms-php versions 11.0.7 and below, all pages within the HAX CMS application do not contain headers to prevent other websites from loading the site within an iframe. This applies to both the CMS and generated sites. An unauthenticated attacker can load the sta…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54139">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-6983 – A 

Clickjacking vulnerability in TP-Link Archer C1200 web management page allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-6983</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-6983</guid>
    <pubDate>Wed, 16 Jul 2025 20:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-6983</strong></p>
  <p>A   Clickjacking vulnerability in TP-Link Archer C1200 web management page allows an attacker to trick users into performing unintended actions via rendered UI layers or frames.This issue affects Archer C1200 <= 1.1.5.</p>
  <p><strong>CVSS:</strong> 5.1 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-6983">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-27455 – The web application is vulnerable to clickjacking attacks. The site can be embed...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27455</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27455</guid>
    <pubDate>Thu, 03 Jul 2025 12:15:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-27455</strong></p>
  <p>The web application is vulnerable to clickjacking attacks. The site can be embedded into another frame, allowing an attacker to trick a user into clicking on something different from what the user perceives, thus potentially revealing confidential information or allowing others to take control of their computer while clicking on seemingly innocuous objects.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27455">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-53096 – Sunshine is a self-hosted game stream host for Moonlight. Prior to version 2025...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53096</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53096</guid>
    <pubDate>Tue, 01 Jul 2025 02:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-53096</strong></p>
  <p>Sunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.628.4510, the web UI of Sunshine lacks protection against Clickjacking attacks. This vulnerability allows an attacker to embed the Sunshine interface within a malicious website using an invisible or disguised iframe. If a user is tricked into interacting (one or multiple clicks) with the malicious page while authentic…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53096">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-6434 – The exception page for the HTTPS-Only feature, displayed when a website is opene...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-6434</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-6434</guid>
    <pubDate>Tue, 24 Jun 2025 13:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-6434</strong></p>
  <p>The exception page for the HTTPS-Only feature, displayed when a website is opened via HTTP, lacked an anti-clickjacking delay, potentially allowing an attacker to trick a user into granting an exception and loading a webpage over HTTP. This vulnerability was fixed in Firefox 140 and Thunderbird 140.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-6434">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-49144 – Notepad++ is a free and open-source source code editor. In versions 8.8.1 and pr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-49144</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-49144</guid>
    <pubDate>Mon, 23 Jun 2025 19:15:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-49144</strong></p>
  <p>Notepad++ is a free and open-source source code editor. In versions 8.8.1 and prior, a privilege escalation vulnerability exists in the Notepad++ v8.8.1 installer that allows unprivileged users to gain SYSTEM-level privileges through insecure executable search paths. An attacker could use social engineering or clickjacking to trick users into downloading both the legitimate installer and a malici…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-272</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-49144">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-49193 – The application fails to implement several security headers. These headers help ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-49193</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-49193</guid>
    <pubDate>Thu, 12 Jun 2025 15:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-49193</strong></p>
  <p>The application fails to implement several security headers. These headers help increase the overall security level of the web application by e.g., preventing the application to be displayed in an iFrame (Clickjacking attacks) or not executing injected malicious JavaScript code (XSS attacks).</p>
  <p><strong>CVSS:</strong> 4.2 · <strong>CWE:</strong> CWE-693</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-49193">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-49192 – The web application is vulnerable to clickjacking attacks. The site can be embed...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-49192</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-49192</guid>
    <pubDate>Thu, 12 Jun 2025 15:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-49192</strong></p>
  <p>The web application is vulnerable to clickjacking attacks. The site can be embedded into another frame, allowing an attacker to trick a user into clicking on something different from what the user perceives. This could potentially reveal confidential information or allow others to take control of their computer while clicking on seemingly innocuous objects.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-49192">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-5267 – A clickjacking vulnerability could have been used to trick a user into leaking s...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-5267</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-5267</guid>
    <pubDate>Tue, 27 May 2025 13:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-5267</strong></p>
  <p>A clickjacking vulnerability could have been used to trick a user into leaking saved payment card details to a malicious page. This vulnerability was fixed in Firefox 139, Firefox ESR 128.11, Thunderbird 139, and Thunderbird 128.11.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-5267">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-43854 – DIFY is an open-source LLM app development platform. Prior to version 1.3.0, a c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-43854</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-43854</guid>
    <pubDate>Mon, 28 Apr 2025 16:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-43854</strong></p>
  <p>DIFY is an open-source LLM app development platform. Prior to version 1.3.0, a clickjacking vulnerability was found in the default setup of the DIFY application, allowing malicious actors to trick users into clicking on elements of the web page without their knowledge or consent. This can lead to unauthorized actions being performed, potentially compromising the security and privacy of users. Thi…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-43854">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-31138 – tarteaucitron.js is a compliant and accessible cookie banner. A vulnerability wa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-31138</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-31138</guid>
    <pubDate>Mon, 07 Apr 2025 15:15:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-31138</strong></p>
  <p>tarteaucitron.js is a compliant and accessible cookie banner. A vulnerability was identified in tarteaucitron.js prior to 1.20.1, where user-controlled inputs for element dimensions (width and height) were not properly validated. This allowed an attacker with direct access to the site's source code or a CMS plugin to set values like 100%;height:100%;position:fixed;, potentially covering the entir…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-31138">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2024-54558 – A clickjacking issue was addressed with improved out-of-process view handling. T...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-54558</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-54558</guid>
    <pubDate>Mon, 10 Mar 2025 19:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2024-54558</strong></p>
  <p>A clickjacking issue was addressed with improved out-of-process view handling. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15. An app may be able to trick a user into granting access to photos from the user's photo library.</p>
  <p><strong>CVSS:</strong> 2.8 · <strong>CWE:</strong> CWE-451</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-54558">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-24874 – SAP Commerce (Backoffice) uses the deprecated X-FRAME-OPTIONS header to protect ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24874</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24874</guid>
    <pubDate>Tue, 11 Feb 2025 01:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-24874</strong></p>
  <p>SAP Commerce (Backoffice) uses the deprecated X-FRAME-OPTIONS header to protect against clickjacking. While this protection remains effective now, it may not be the case in the future as browsers might discontinue support for this header in favor of the frame-ancestors CSP directive. Hence, clickjacking could become possible then, and lead to exposure and modification of sensitive information.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24874">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-0729 – A vulnerability was found in TP-Link TL-SG108E 1.0.0 Build 20201208 Rel. 40304. ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-0729</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-0729</guid>
    <pubDate>Mon, 27 Jan 2025 17:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-0729</strong></p>
  <p>A vulnerability was found in TP-Link TL-SG108E 1.0.0 Build 20201208 Rel. 40304. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to clickjacking. The attack may be initiated remotely. Upgrading to version 1.0.0 Build 20250124 Rel. 54920(Beta) is able to address this issue. It is recommended to upgrade the affected component. The vendor was conta…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-451</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0729">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-57369 – Clickjacking vulnerability in typecho v1.2.1.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-57369</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-57369</guid>
    <pubDate>Fri, 17 Jan 2025 20:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-57369</strong></p>
  <p>Clickjacking vulnerability in typecho v1.2.1.</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-57369">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-10454 – Clickjacking vulnerability in Clibo Manager v1.1.9.12 in the '/public/login' dir...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-10454</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-10454</guid>
    <pubDate>Thu, 31 Oct 2024 13:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-10454</strong></p>
  <p>Clickjacking vulnerability in Clibo Manager v1.1.9.12 in the '/public/login' directory, a login panel. This vulnerability occurs due to the absence of an X-Frame-Options server-side header. An attacker could overlay a transparent iframe to perform click hijacking on victims.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-10454">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-9397 – A missing delay in directory upload UI could have made it possible for an attack...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-9397</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-9397</guid>
    <pubDate>Tue, 01 Oct 2024 16:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-9397</strong></p>
  <p>A missing delay in directory upload UI could have made it possible for an attacker to trick a user into granting permission via clickjacking. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-9397">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-41907 – A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-41907</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-41907</guid>
    <pubDate>Tue, 13 Aug 2024 08:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-41907</strong></p>
  <p>A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected application is missing general HTTP security headers in the web server. This could allow an attacker to make the servers more prone to clickjacking attack.</p>
  <p><strong>CVSS:</strong> 4.2 · <strong>CWE:</strong> CWE-358</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-41907">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-30126 – HCL BigFix Compliance is affected by a missing X-Frame-Options HTTP header which...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-30126</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-30126</guid>
    <pubDate>Thu, 18 Jul 2024 20:15:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-30126</strong></p>
  <p>HCL BigFix Compliance is affected by a missing X-Frame-Options HTTP header which can allow an attacker to create a malicious website that embeds the target website in a frame or iframe, tricking users into performing actions on the target website without their knowledge.</p>
  <p><strong>CVSS:</strong> 4.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-30126">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2024-30109 – HCL DRYiCE AEX is impacted by a lack of clickjacking protection in the AEX web a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-30109</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-30109</guid>
    <pubDate>Fri, 28 Jun 2024 06:15:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2024-30109</strong></p>
  <p>HCL DRYiCE AEX is impacted by a lack of clickjacking protection in the AEX web application.  An attacker can use multiple transparent or opaque layers to trick a user into clicking on a button or link on another page than the one intended.</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-30109">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-33377 – LB-LINK BL-W1210M v2.0 was discovered to contain a clickjacking vulnerability vi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-33377</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-33377</guid>
    <pubDate>Fri, 14 Jun 2024 15:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-33377</strong></p>
  <p>LB-LINK BL-W1210M v2.0 was discovered to contain a clickjacking vulnerability via the Administrator login page. Attackers can cause victim users to perform arbitrary operations via interaction with crafted elements on the web page.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-33377">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-2383 – A clickjacking vulnerability exists in zenml-io/zenml versions up to and includi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-2383</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-2383</guid>
    <pubDate>Thu, 06 Jun 2024 19:15:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-2383</strong></p>
  <p>A clickjacking vulnerability exists in zenml-io/zenml versions up to and including 0.55.5 due to the application's failure to set appropriate X-Frame-Options or Content-Security-Policy HTTP headers. This vulnerability allows an attacker to embed the application UI within an iframe on a malicious page, potentially leading to unauthorized actions by tricking users into interacting with the interfac…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-2383">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-47774 – Improper Restriction of Rendered UI Layers or Frames vulnerability in Automattic...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-47774</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-47774</guid>
    <pubDate>Wed, 24 Apr 2024 16:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-47774</strong></p>
  <p>Improper Restriction of Rendered UI Layers or Frames vulnerability in Automattic Jetpack allows Clickjacking.This issue affects Jetpack: from n/a before 12.7.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-47774">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-2609 – The permission prompt input delay could expire while the window is not in focus...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-2609</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-2609</guid>
    <pubDate>Tue, 19 Mar 2024 12:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-2609</strong></p>
  <p>The permission prompt input delay could expire while the window is not in focus. This makes it vulnerable to clickjacking by malicious websites. This vulnerability affects Firefox < 124, Firefox ESR < 115.10, and Thunderbird < 115.10.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-356</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-2609">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-28196 – your_spotify is an open source, self hosted Spotify tracking dashboard. YourSpot...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-28196</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-28196</guid>
    <pubDate>Wed, 13 Mar 2024 18:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-28196</strong></p>
  <p>your_spotify is an open source, self hosted Spotify tracking dashboard. YourSpotify version < 1.9.0 does not prevent other pages from displaying it in an iframe and is thus vulnerable to clickjacking. Clickjacking can be used to trick an existing user of YourSpotify to trigger actions, such as allowing signup of other users or deleting the current user account. Clickjacking works by opening the t…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-28196">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-1890 – Vulnerability whereby an attacker could send a malicious link to an authenticate...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-1890</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-1890</guid>
    <pubDate>Mon, 26 Feb 2024 16:27:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-1890</strong></p>
  <p>Vulnerability whereby an attacker could send a malicious link to an authenticated operator, which could allow remote attackers to perform a clickjacking attack on Sunny WebBox firmware version 1.6.1 and earlier.</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-1890">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-45698 – Sametime is impacted by lack of clickjacking protection in Outlook add-in. The a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-45698</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-45698</guid>
    <pubDate>Sat, 10 Feb 2024 04:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-45698</strong></p>
  <p>Sametime is impacted by lack of clickjacking protection in Outlook add-in. The application is not implementing appropriate protections in order to protect users from clickjacking attacks.</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-45698">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-6093 – A clickjacking vulnerability has been identified in OnCell G3150A-LTE Series fir...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-6093</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-6093</guid>
    <pubDate>Sun, 31 Dec 2023 10:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-6093</strong></p>
  <p>A clickjacking vulnerability has been identified in OnCell G3150A-LTE Series firmware versions v1.3 and prior.  This vulnerability is caused by incorrectly restricts frame objects, which can lead to user confusion about which interface the user is interacting with. This vulnerability may lead the attacker to trick the user into interacting with the application.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-6093">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-6867 – The timing of a button click causing a popup to disappear was approximately the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-6867</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-6867</guid>
    <pubDate>Tue, 19 Dec 2023 14:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-6867</strong></p>
  <p>The timing of a button click causing a popup to disappear was approximately the same length as the anti-clickjacking delay on permission prompts. It was possible to use this fact to surprise users by luring them to click where the permission grant button would be about to appear. This vulnerability affects Firefox ESR < 115.6 and Firefox < 121.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-6867">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-4958 – In Red Hat Advanced Cluster Security (RHACS), it was found that some security re...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-4958</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-4958</guid>
    <pubDate>Tue, 12 Dec 2023 10:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-4958</strong></p>
  <p>In Red Hat Advanced Cluster Security (RHACS), it was found that some security related HTTP headers were missing, allowing an attacker to exploit this with a clickjacking attack. An attacker could exploit this by convincing a valid RHACS user to visit an attacker-controlled web page, that deceptively points to valid RHACS endpoints, hijacking the user's account permissions to perform other actions.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-4958">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-2265 – An Improper Restriction of Rendered UI Layers or Frames in the Schweitzer Engine...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-2265</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-2265</guid>
    <pubDate>Thu, 30 Nov 2023 17:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-2265</strong></p>
  <p>An Improper Restriction of Rendered UI Layers or Frames in the Schweitzer Engineering Laboratories SEL-411L could allow an unauthenticated attacker to perform clickjacking based attacks against an authenticated and authorized user.    See product Instruction Manual Appendix A dated 20230830 for more details.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-2265">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-6206 – The black fade animation when exiting fullscreen is roughly the length of the an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-6206</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-6206</guid>
    <pubDate>Tue, 21 Nov 2023 15:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-6206</strong></p>
  <p>The black fade animation when exiting fullscreen is roughly the length of the anti-clickjacking delay on permission prompts. It was possible to use this fact to surprise users by luring them to click where the permission grant button would be about to appear. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-6206">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-47311 – An issue in Yamcs 5.8.6 allows attackers to send aribitrary telelcommands in a C...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-47311</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-47311</guid>
    <pubDate>Mon, 20 Nov 2023 21:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-47311</strong></p>
  <p>An issue in Yamcs 5.8.6 allows attackers to send aribitrary telelcommands in a Command Stack via Clickjacking.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-47311">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-4956 – A flaw was found in Quay. Clickjacking is when an attacker uses multiple transpa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-4956</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-4956</guid>
    <pubDate>Tue, 07 Nov 2023 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-4956</strong></p>
  <p>A flaw was found in Quay. Clickjacking is when an attacker uses multiple transparent or opaque layers to trick a user into clicking on a button or link on another page when they intend to click on the top-level page. During the pentest, it has been detected that the config-editor page is vulnerable to clickjacking. This flaw allows an attacker to trick an administrator user into clicking on butto…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-4956">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-36920 – In SAP Enable Now - versions WPB_MANAGER 1.0, WPB_MANAGER_CE 10, WPB_MANAGER_HAN...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-36920</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-36920</guid>
    <pubDate>Mon, 30 Oct 2023 17:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-36920</strong></p>
  <p>In SAP Enable Now - versions WPB_MANAGER 1.0, WPB_MANAGER_CE 10, WPB_MANAGER_HANA 10, ENABLE_NOW_CONSUMP_DEL 1704, the X-FRAME-OPTIONS response header is not implemented, allowing an unauthenticated attacker to attempt clickjacking, which could result in disclosure or modification of information.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-36920">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-41897 – Home assistant is an open source home automation. Home Assistant server does not...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-41897</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-41897</guid>
    <pubDate>Thu, 19 Oct 2023 23:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-41897</strong></p>
  <p>Home assistant is an open source home automation. Home Assistant server does not set any HTTP security headers, including the X-Frame-Options header, which specifies whether the web page is allowed to be framed. The omission of this and correlating headers facilitates covert clickjacking attacks and alternative exploit opportunities, such as the vector described in this security advisory. This fa…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-41897">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-38873 – The commit 3730880 (April 2023) and v.0.9-beta1 of gugoan Economizzer is vulnera...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-38873</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-38873</guid>
    <pubDate>Thu, 28 Sep 2023 04:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-38873</strong></p>
  <p>The commit 3730880 (April 2023) and v.0.9-beta1 of gugoan Economizzer is vulnerable to Clickjacking. Clickjacking, also known as a "UI redress attack", is when an attacker uses multiple transparent or opaque layers to trick a user into clicking on a button or link on another page when they were intending to click on the top-level page. Thus, the attacker is "hijacking" clicks meant for their page…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-38873">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-38687 – Svelecte is a flexible autocomplete/select component written in Svelte. Svelecte...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-38687</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-38687</guid>
    <pubDate>Mon, 14 Aug 2023 21:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-38687</strong></p>
  <p>Svelecte is a flexible autocomplete/select component written in Svelte. Svelecte item names are rendered as raw HTML with no escaping. This allows the injection of arbitrary HTML into the Svelecte dropdown. This can be exploited to execute arbitrary JavaScript whenever a Svelecte dropdown is opened. Item names given to Svelecte appear to be directly rendered as HTML by the default item renderer.…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-38687">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2023-23343 – A clickjacking vulnerability in the HCL BigFix OSD Bare Metal Server version 311...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-23343</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-23343</guid>
    <pubDate>Thu, 22 Jun 2023 22:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2023-23343</strong></p>
  <p>A clickjacking vulnerability in the HCL BigFix OSD Bare Metal Server version 311.12 or lower allows attacker to use transparent or opaque layers to trick a user into clicking on a button or link on another page to perform a redirect to an attacker-controlled domain.</p>
  <p><strong>CVSS:</strong> 2.4 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-23343">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-3140 – Missing HTTP headers (X-Frame-Options, Content-Security-Policy) in KNIME
 Busine...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-3140</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-3140</guid>
    <pubDate>Wed, 07 Jun 2023 10:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-3140</strong></p>
  <p>Missing HTTP headers (X-Frame-Options, Content-Security-Policy) in KNIME  Business Hub before 1.4.0 has left users vulnerable to click  jacking. Clickjacking is an attack that occurs when an attacker uses a  transparent iframe in a window to trick a user into clicking on an  actionable item, such as a button or link, to another server in which  they have an identical webpage. The attacker essenti…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-3140">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-40268 – Improper Restriction of Rendered UI Layers or Frames vulnerability in Mitsubishi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-40268</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-40268</guid>
    <pubDate>Thu, 02 Feb 2023 08:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-40268</strong></p>
  <p>Improper Restriction of Rendered UI Layers or Frames vulnerability in Mitsubishi Electric Corporation GOT2000 Series GT27 model versions 01.14.000 to 01.47.000, Mitsubishi Electric Corporation GOT2000 Series GT25 model versions 01.14.000 to 01.47.000 and Mitsubishi Electric Corporation GT SoftGOT2000 versions 1.265B to 1.285X allows a remote unauthenticated attacker to lead legitimate users to pe…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-40268">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-23126 – Connectwise Automate 2022.11 is vulnerable to Clickjacking. The login screen can...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-23126</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-23126</guid>
    <pubDate>Wed, 01 Feb 2023 14:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-23126</strong></p>
  <p>Connectwise Automate 2022.11 is vulnerable to Clickjacking. The login screen can be iframed and used to manipulate users to perform unintended actions. NOTE: the vendor's position is that a Content-Security-Policy HTTP response header is present to block this attack.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-23126">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-46061 – AeroCMS v0.0.1 is vulnerable to ClickJacking.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-46061</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-46061</guid>
    <pubDate>Tue, 13 Dec 2022 14:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-46061</strong></p>
  <p>AeroCMS v0.0.1 is vulnerable to ClickJacking.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-46061">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-3260 – The response header has not enabled X-FRAME-OPTIONS, Which helps prevents agains...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-3260</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-3260</guid>
    <pubDate>Thu, 08 Dec 2022 16:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-3260</strong></p>
  <p>The response header has not enabled X-FRAME-OPTIONS, Which helps prevents against Clickjacking attack.. Some browsers would interpret these results incorrectly, allowing clickjacking attacks.</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-3260">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-4105 – A stored XSS in a kiwi Test Plan can run malicious javascript which could be cha...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-4105</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-4105</guid>
    <pubDate>Mon, 21 Nov 2022 20:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-4105</strong></p>
  <p>A stored XSS in a kiwi Test Plan can run malicious javascript which could be chained with an HTML injection to perform a UI redressing attack (clickjacking) and an HTML injection which disables the use of the history page.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-4105">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-36182 – Hashicorp Boundary v0.8.0 is vulnerable to Clickjacking which allow for the inte...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-36182</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-36182</guid>
    <pubDate>Thu, 27 Oct 2022 13:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-36182</strong></p>
  <p>Hashicorp Boundary v0.8.0 is vulnerable to Clickjacking which allow for the interception of login credentials, re-direction of users to malicious sites, or causing users to perform malicious actions on the site.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-36182">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-36736 – Jitsi-2.10.5550 was discovered to contain a vulnerability in its web UI which al...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-36736</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-36736</guid>
    <pubDate>Thu, 08 Sep 2022 13:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-36736</strong></p>
  <p>Jitsi-2.10.5550 was discovered to contain a vulnerability in its web UI which allows attackers to perform a clickjacking attack via a crafted HTTP request. NOTE: this is disputed by the vendor</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-36736">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-2800 – A vulnerability, which was classified as problematic, has been found in SourceCo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-2800</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-2800</guid>
    <pubDate>Fri, 12 Aug 2022 20:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-2800</strong></p>
  <p>A vulnerability, which was classified as problematic, has been found in SourceCodester Gym Management System. Affected by this issue is some unknown functionality. The manipulation leads to clickjacking. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-206246 is the identifier assigned to this vulnerability.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-451</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-2800">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-2179 – The X-Frame-Options header in Rockwell Automation MicroLogix 1100/1400 Versions ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-2179</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-2179</guid>
    <pubDate>Wed, 20 Jul 2022 16:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-2179</strong></p>
  <p>The X-Frame-Options header in Rockwell Automation MicroLogix 1100/1400 Versions 21.007 and prior is not configured in the HTTP response, which could allow clickjacking attacks.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-2179">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-28889 – In Apache Druid 0.22.1 and earlier, the server did not set appropriate headers t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-28889</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-28889</guid>
    <pubDate>Thu, 07 Jul 2022 19:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-28889</strong></p>
  <p>In Apache Druid 0.22.1 and earlier, the server did not set appropriate headers to prevent clickjacking. Druid 0.23.0 and later prevent clickjacking using the Content-Security-Policy header.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-28889">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-27220 – A vulnerability has been identified in SINEMA Remote Connect Server (All version...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-27220</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-27220</guid>
    <pubDate>Tue, 14 Jun 2022 10:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-27220</strong></p>
  <p>A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). Affected application is missing general HTTP security headers in the web server configured on port 6220. This could aid attackers by making the servers more prone to clickjacking, channel downgrade attacks and other similar client-based attack vectors.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-358</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-27220">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-27219 – A vulnerability has been identified in SINEMA Remote Connect Server (All version...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-27219</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-27219</guid>
    <pubDate>Tue, 14 Jun 2022 10:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-27219</strong></p>
  <p>A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). Affected application is missing general HTTP security headers in the web server configured on port 443. This could aid attackers by making the servers more prone to clickjacking, channel downgrade attacks and other similar client-based attack vectors.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-358</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-27219">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-27773 – This vulnerability allows users to execute a clickjacking attack in the meeting'...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-27773</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-27773</guid>
    <pubDate>Thu, 12 May 2022 22:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-27773</strong></p>
  <p>This vulnerability allows users to execute a clickjacking attack in the meeting's chat.</p>
  <p><strong>CVSS:</strong> 4.2 · <strong>CWE:</strong> CWE-451</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-27773">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-24733 – Sylius is an open source eCommerce platform. Prior to versions 1.9.10, 1.10.11, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-24733</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-24733</guid>
    <pubDate>Mon, 14 Mar 2022 19:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-24733</strong></p>
  <p>Sylius is an open source eCommerce platform. Prior to versions 1.9.10, 1.10.11, and 1.11.2, it is possible for a page controlled by an attacker to load the website within an iframe. This will enable a clickjacking attack, in which the attacker's page overlays the target application's interface with a different interface provided by the attacker. The issue is fixed in versions 1.9.10, 1.10.11, and…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24733">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-41657 – SmartBear CodeCollaborator v6.1.6102 was discovered to contain a vulnerability i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-41657</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-41657</guid>
    <pubDate>Thu, 10 Mar 2022 17:44:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-41657</strong></p>
  <p>SmartBear CodeCollaborator v6.1.6102 was discovered to contain a vulnerability in the web UI which would allow an attacker to conduct a clickjacking attack.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-41657">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-3660 – Cockpit (and its plugins) do not seem to protect itself against clickjacking. It...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-3660</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-3660</guid>
    <pubDate>Thu, 10 Mar 2022 17:42:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-3660</strong></p>
  <p>Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a cockpit server via another website, inside an <iFrame> HTML entry. This may be used by a malicious website in clickjacking or similar attacks.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3660">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-22552 – Dell EMC AppSync versions 3.9 to 4.3 contain a clickjacking vulnerability in App...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-22552</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-22552</guid>
    <pubDate>Fri, 21 Jan 2022 21:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-22552</strong></p>
  <p>Dell EMC AppSync versions 3.9 to 4.3 contain a clickjacking vulnerability in AppSync. A remote unauthenticated attacker could potentially exploit this vulnerability to trick the victim into executing state changing operations.</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-22552">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-34087 – In Ultimaker S3 3D printer, Ultimaker S5 3D printer, Ultimaker 3 3D printer S-li...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-34087</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-34087</guid>
    <pubDate>Mon, 10 Jan 2022 14:10:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-34087</strong></p>
  <p>In Ultimaker S3 3D printer, Ultimaker S5 3D printer, Ultimaker 3 3D printer S-line through 6.3 and Ultimaker 3 through 5.2.16, the local webserver can be used for clickjacking. This includes the settings page.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-34087">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-43048 – The Interior Server and Gateway Server components of TIBCO Software Inc.'s TIBCO...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-43048</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-43048</guid>
    <pubDate>Tue, 16 Nov 2021 18:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-43048</strong></p>
  <p>The Interior Server and Gateway Server components of TIBCO Software Inc.'s TIBCO PartnerExpress contain a vulnerability that theoretically allows an unauthenticated attacker with network access to execute a clickjacking attack on the affected system. A successful attack using this vulnerability does not require human interaction from a person other than the attacker. Affected releases are TIBCO S…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-43048">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-35237 – A missing HTTP header (X-Frame-Options) in Kiwi Syslog Server has left customers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-35237</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-35237</guid>
    <pubDate>Fri, 29 Oct 2021 14:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-35237</strong></p>
  <p>A missing HTTP header (X-Frame-Options) in Kiwi Syslog Server has left customers vulnerable to click jacking. Clickjacking is an attack that occurs when an attacker uses a transparent iframe in a window to trick a user into clicking on an actionable item, such as a button or link, to another server in which they have an identical webpage. The attacker essentially hijacks the user activity intende…</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-35237">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-27003 – Clustered Data ONTAP versions prior to 9.5P18, 9.6P15, 9.7P14, 9.8P5 and 9.9.1 a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-27003</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-27003</guid>
    <pubDate>Tue, 12 Oct 2021 18:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-27003</strong></p>
  <p>Clustered Data ONTAP versions prior to 9.5P18, 9.6P15, 9.7P14, 9.8P5 and 9.9.1 are missing an X-Frame-Options header which could allow a clickjacking attack.</p>
  <p><strong>CVSS:</strong> 4.7 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-27003">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-3731 – LedgerSMB does not sufficiently guard against being wrapped by other sites, maki...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-3731</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-3731</guid>
    <pubDate>Mon, 23 Aug 2021 13:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-3731</strong></p>
  <p>LedgerSMB does not sufficiently guard against being wrapped by other sites, making it vulnerable to 'clickjacking'. This allows an attacker to trick a targetted user to execute unintended actions.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3731">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-32070 – The MiCollab Client Service component in Mitel MiCollab before 9.3 could allow a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-32070</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-32070</guid>
    <pubDate>Fri, 13 Aug 2021 16:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-32070</strong></p>
  <p>The MiCollab Client Service component in Mitel MiCollab before 9.3 could allow an attacker to perform a clickjacking attack due to an insecure header response. A successful exploit could allow an attacker to modify the browser header and redirect users.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-32070">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-37788 – A vulnerability in the web UI of Gurock TestRail v5.3.0.3603 could allow an unau...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-37788</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-37788</guid>
    <pubDate>Mon, 09 Aug 2021 13:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-37788</strong></p>
  <p>A vulnerability in the web UI of Gurock TestRail v5.3.0.3603 could allow an unauthenticated, remote attacker to affect the integrity of a device via a clickjacking attack. The vulnerability is due to insufficient input validation of iFrame data in HTTP requests that are sent to an affected device. An attacker could exploit this vulnerability by sending crafted HTTP packets with malicious iFrame d…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-37788">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-10743 – It was discovered that OpenShift Container Platform's (OCP) distribution of Kiba...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-10743</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-10743</guid>
    <pubDate>Wed, 02 Jun 2021 11:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-10743</strong></p>
  <p>It was discovered that OpenShift Container Platform's (OCP) distribution of Kibana could open in an iframe, which made it possible to intercept and manipulate requests. This flaw allows an attacker to trick a user into performing arbitrary actions in OCP's distribution of Kibana, such as clickjacking.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-358</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-10743">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-23274 – The Config UI component of TIBCO Software Inc.'s TIBCO API Exchange Gateway and ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-23274</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-23274</guid>
    <pubDate>Tue, 23 Mar 2021 17:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-23274</strong></p>
  <p>The Config UI component of TIBCO Software Inc.'s TIBCO API Exchange Gateway and TIBCO API Exchange Gateway Distribution for TIBCO Silver Fabric contains a vulnerability that theoretically allows an unauthenticated attacker with network access to execute a clickjacking attack on the affected system. A successful attack using this vulnerability does not require human interaction from a person other…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-23274">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-23955 – The browser could have been confused into transferring a pointer lock state into...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-23955</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-23955</guid>
    <pubDate>Fri, 26 Feb 2021 03:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-23955</strong></p>
  <p>The browser could have been confused into transferring a pointer lock state into another tab, which could have lead to clickjacking attacks. This vulnerability affects Firefox < 85.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-23955">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-21444 – SAP Business Objects BI Platform, versions - 410, 420, 430, allows multiple X-Fr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21444</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21444</guid>
    <pubDate>Tue, 09 Feb 2021 21:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-21444</strong></p>
  <p>SAP Business Objects BI Platform, versions - 410, 420, 430, allows multiple X-Frame-Options headers entries in the response headers, which may not be predictably treated by all user agents. This could, as a result, nullify the added X-Frame-Options header leading to Clickjacking attack.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21444">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-35735 – Vidyo 02-09-/D allows clickjacking via the portal/ URI.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-35735</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-35735</guid>
    <pubDate>Tue, 29 Dec 2020 19:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-35735</strong></p>
  <p>Vidyo 02-09-/D allows clickjacking via the portal/ URI.</p>
  <p><strong>CVSS:</strong> 4.7 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-35735">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-26962 – Cross-origin iframes that contained a login form could have been recognized by t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-26962</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-26962</guid>
    <pubDate>Wed, 09 Dec 2020 01:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-26962</strong></p>
  <p>Cross-origin iframes that contained a login form could have been recognized by the login autofill service, and populated. This could have been used in clickjacking attacks, as well as be read across partitions in dynamic first party isolation. This vulnerability affects Firefox < 83.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-26962">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-5679 – Improper restriction of rendered UI layers or frames in EC-CUBE versions from 3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-5679</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-5679</guid>
    <pubDate>Thu, 03 Dec 2020 12:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-5679</strong></p>
  <p>Improper restriction of rendered UI layers or frames in EC-CUBE versions from 3.0.0 to 3.0.18 leads to clickjacking attacks. If a user accesses a specially crafted page while logged into the administrative page, unintended operations may be conducted.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-5679">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-24711 – The Reset button on the Account Settings page in Gophish before 0.11.0 allows at...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-24711</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-24711</guid>
    <pubDate>Wed, 28 Oct 2020 20:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-24711</strong></p>
  <p>The Reset button on the Account Settings page in Gophish before 0.11.0 allows attackers to cause a denial of service via a clickjacking attack</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-24711">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-15793 – A vulnerability has been identified in Desigo Insight (All versions). The device...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15793</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15793</guid>
    <pubDate>Thu, 15 Oct 2020 19:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-15793</strong></p>
  <p>A vulnerability has been identified in Desigo Insight (All versions). The device does not properly set the X-Frame-Options HTTP Header which makes it vulnerable to Clickjacking attacks. This could allow an unauthenticated attacker to retrieve or modify data in the context of a legitimate user by tricking that user to click on a website controlled by the attacker.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15793">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-13119 – ismartgate PRO 1.5.9 is vulnerable to clickjacking.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-13119</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-13119</guid>
    <pubDate>Thu, 24 Sep 2020 16:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-13119</strong></p>
  <p>ismartgate PRO 1.5.9 is vulnerable to clickjacking.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-13119">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-8201 – Node.js &lt; 12.18.4 and &lt; 14.11 can be exploited to perform HTTP desync attacks an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-8201</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-8201</guid>
    <pubDate>Fri, 18 Sep 2020 21:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-8201</strong></p>
  <p>Node.js < 12.18.4 and < 14.11 can be exploited to perform HTTP desync attacks and deliver malicious payloads to unsuspecting users. The payloads can be crafted by an attacker to hijack user sessions, poison cookies, perform clickjacking, and a multitude of other attacks depending on the architecture of the underlying system. The attack was possible due to a bug in processing of carrier-return sym…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-444</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-8201">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-13174 – The web server in the Teradici Managament console versions 20.04 and 20.01.1 did...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-13174</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-13174</guid>
    <pubDate>Tue, 11 Aug 2020 18:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-13174</strong></p>
  <p>The web server in the Teradici Managament console versions 20.04 and 20.01.1 did not properly set the X-Frame-Options HTTP header, which could allow an attacker to trick a user into clicking a malicious link via clickjacking.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-13174">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-4323 – "HCL AppScan Enterprise advisory API documentation is susceptible to clickjackin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-4323</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-4323</guid>
    <pubDate>Tue, 07 Jul 2020 15:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-4323</strong></p>
  <p>"HCL AppScan Enterprise advisory API documentation is susceptible to clickjacking, which could allow an attacker to embed the contents of untrusted web pages in a frame."</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-4323">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-10951 – Western Digital My Cloud Home and ibi devices before 2.2.0 allow clickjacking on...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-10951</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-10951</guid>
    <pubDate>Wed, 15 Apr 2020 20:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-10951</strong></p>
  <p>Western Digital My Cloud Home and ibi devices before 2.2.0 allow clickjacking on sign-in pages.</p>
  <p><strong>CVSS:</strong> 4.7 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-10951">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-1728 – A vulnerability was found in all versions of Keycloak where, the pages on the Ad...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-1728</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-1728</guid>
    <pubDate>Mon, 06 Apr 2020 14:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-1728</strong></p>
  <p>A vulnerability was found in all versions of Keycloak where, the pages on the Admin Console area of the application are completely missing general HTTP security headers in HTTP-responses. This does not directly lead to a security issue, yet it might aid attackers in their efforts to exploit other problems. The flaws unnecessarily make the servers more prone to Clickjacking, channel downgrade atta…</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-358</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-1728">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
