CWE-351: Insufficient Type Distinction
The product does not properly distinguish between different types of elements in a way that leads to insecure behavior.
13 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-30510 — Growatt Cloud portal Insufficient Type Distinction
- CVE-2025-54413 — skops' MethodNode can access unexpected object fields through dot notation, leading to arbitrary code execution at load time
- CVE-2025-54412 — skops' Inconsistent Trusted Type Validation Enables Hidden `operator` Methods Execution
- CVE-2025-31951 — HCL BigFix RunBookAI is affected by a Unvalidated Command Input / Potential Command Smuggling vulnerability
- CVE-2025-65960 — Contao is vulnerable to remote code execution in template closures
- CVE-2025-47939 — TYPO3 CMS Vulnerable to Unrestricted File Upload in File Abstraction Layer
- CVE-2026-15305 — TYPO3 CMS - Unrestricted File Upload in Form Framework
- CVE-2025-32035 — DNN does not check the contents of a file when uploading files
- CVE-2026-41341 — OpenClaw < 2026.3.31 - Component Interaction Misclassification in Discord Extension
Recently published
- CVE-2026-15305 — TYPO3 CMS - Unrestricted File Upload in Form Framework
- CVE-2025-31951 — HCL BigFix RunBookAI is affected by a Unvalidated Command Input / Potential Command Smuggling vulnerability
- CVE-2026-41341 — OpenClaw < 2026.3.31 - Component Interaction Misclassification in Discord Extension
- CVE-2025-65960 — Contao is vulnerable to remote code execution in template closures
- CVE-2025-54413 — skops' MethodNode can access unexpected object fields through dot notation, leading to arbitrary code execution at load time
- CVE-2025-54412 — skops' Inconsistent Trusted Type Validation Enables Hidden `operator` Methods Execution
- CVE-2025-47939 — TYPO3 CMS Vulnerable to Unrestricted File Upload in File Abstraction Layer
- CVE-2025-30510 — Growatt Cloud portal Insufficient Type Distinction
- CVE-2025-32035 — DNN does not check the contents of a file when uploading files