CWE-351: Insufficient Type Distinction
The product does not properly distinguish between different types of elements in a way that leads to insecure behavior.
Last updated
Overview
CWE-351 (Insufficient Type Distinction) is a base-level software weakness catalogued by MITRE in the Common Weakness Enumeration (CWE). It describes a recurring type of mistake that can lead to exploitable security vulnerabilities.
Real-world CVEs
14 recorded CVEs are caused by CWE-351 (Insufficient Type Distinction), including 1 in CISA's KEV (Known Exploited Vulnerabilities) catalog. KEVs are shown first. 2 new CWE-351 CVEs have been recorded so far in 2026 (6 in 2025).
- CVE-2023-38831CISA KEVHigh · CVSS 8.4 · EPSS 100th2023-08-23
- CVE-2025-30510
Growatt Cloud portal Insufficient Type Distinction
Critical · CVSS 9.3 · EPSS 15th2025-04-15 - CVE-2025-54413
skops' MethodNode can access unexpected object fields through dot notation, leading to arbitrary code execution at load time
High · CVSS 8.7 · EPSS 4th2025-07-26 - CVE-2025-54412
skops' Inconsistent Trusted Type Validation Enables Hidden `operator` Methods Execution
High · CVSS 8.7 · EPSS 3th2025-07-26 - CVE-2023-2866High · CVSS 7.8 · EPSS 4th2023-06-07
- CVE-2025-32035
DNN does not check the contents of a file when uploading files
High · CVSS 7.5 · EPSS 7th2025-04-08 - CVE-2022-1642High · CVSS 7.5 · EPSS 47th2022-06-16
- CVE-2025-65960
Contao is vulnerable to remote code execution in template closures
Medium · CVSS 6.6 · EPSS 7th2025-11-25 - CVE-2026-15305
TYPO3 CMS - Unrestricted File Upload in Form Framework
Medium · CVSS 6.3 · EPSS 17th2026-07-14 - CVE-2020-10134Medium · CVSS 6.3 · EPSS 49th2020-05-19
- CVE-2024-4769Medium · CVSS 5.9 · EPSS 30th2024-05-14
- CVE-2025-47939
TYPO3 CMS Vulnerable to Unrestricted File Upload in File Abstraction Layer
Medium · CVSS 5.4 · EPSS 7th2025-05-20
Showing 12 of 14 recorded CWE-351 CVEs. Track new ones as they are published and get AI-written analysis and fixes.
Monitor CWE-351 vulnerabilitiesCommon consequences
What can happen when CWE-351 is exploited.
Other
Affects: Other
How it happens
When it is introduced
Typically introduced during these phases of the software lifecycle.
Illustrative examples
Real CVEs that MITRE cites as examples of this weakness.
- CVE-2005-2260 — Browser user interface does not distinguish between user-initiated and synthetic events.
- CVE-2005-2801 — Product does not compare all required data in two separate elements, causing it to think they are the same, leading to loss of ACLs. Similar to Same Name error.
Terminology & mappings
Mapped taxonomies
- PLOVER: Insufficient Type Distinction
Frequently asked questions
Common questions about CWE-351.
- What is CWE-351?
- The product does not properly distinguish between different types of elements in a way that leads to insecure behavior.
- What CVEs are caused by CWE-351?
- 14 recorded CVEs are attributed to CWE-351, including CVE-2023-38831, CVE-2025-30510, CVE-2025-54413. 1 are listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.
- What are the consequences of CWE-351?
- Exploiting CWE-351 can lead to: Other.
- Is CWE-351 actively exploited?
- Yes. 1 CWE-351 vulnerabilities are in CISA's KEV catalog of actively exploited flaws, out of 14 recorded CVEs.
References
- MITRE CWE definition (CWE-351) (opens in a new tab)
- CWE-351 vulnerabilities on NVD (opens in a new tab)
- Learn: What is a CWE?
Weakness data is sourced from the MITRE CWE catalog (v4.20). CVE associations are aggregated and kept current by RadicalNotion.AI.
Stay ahead of CWE-351
Get alerted the moment a new CWE-351 vulnerability affects your stack, with AI-written analysis, severity context, and remediation guidance.