Cyber Resilience

CWE · MITRE source

CWE-451User Interface (UI) Misrepresentation of Critical Information

Abstraction: Class · CVEs in our corpus: 346

The user interface (UI) does not properly represent critical information to the user, allowing the information - or its source - to be obscured or spoofed. This is often a component in phishing attacks.

If an attacker can cause the UI to display erroneous data, or to otherwise convince the user to display information that appears to come from a trusted source, then the attacker could trick the user into performing the wrong action. This is often a component in phishing attacks, but other kinds of problems exist. For example, if the UI is used to monitor the security state of a system or network, then omitting or obscuring an important indicator could prevent the user from detecting and reacting to a security-critical event. UI misrepresentation can take many forms:

Last updated: 11 August 2026 10:53 UTC

Cumulative inbound coverage

How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.

Collective: partial · 12 mapping(s) from 2 framework(s): ATT&CK 7 (partial) · CAPEC 5 (partial)

See the full cumulative-coverage rollup →

OWASP Top 10 for Web (2025)

This weakness contributes to A06:2025 Insecure Design.

Control responseHuman-reviewed

Answering this weakness across the control lifecycle, from our framework cross-walks.

Prevent
Stop it (NIST 800-53 / CSF Protect)
  • PR.PS-06
  • PR.AT-01
  • AC-16 Security and Privacy Attributes
  • SC-16 Transmission of Security and Privacy Attributes
Detect
Catch it (CSF Detect / Respond)

Harden
Shrink the surface (DISA STIG)

Validate
Prove the fix (OWASP ASVS)

NIST 800-53 r5 controls that address this weakness (0)AI-assisted

Control Title Family Why it addresses this CWE
No NIST controls proposed yet.

MITRE ATT&CK techniques this weakness enables

Our own two-way CWE↔ATT&CK cross-walk — a direct mapping with no public source (the CWE→CAPEC→ATT&CK chain leaves most top weaknesses, incl. XSS and SQLi, mapped to nothing).

Direction: other covers this; this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2024-43461 KEV 9.28.80.52162024-09-10
CVE-2024-38112 KEV 8.37.50.84232024-07-09
CVE-2025-9491 8.37.80.68862025-08-26
CVE-2026-0907 8.19.80.07692026-01-20
CVE-2025-8043 7.29.80.00372025-07-22
CVE-2026-0906 7.29.80.00322026-01-20
CVE-2026-2634 7.29.80.00312026-02-24
CVE-2021-22866 6.88.80.01042021-05-14
CVE-2021-41598 6.88.80.01152022-01-25
CVE-2024-0750 6.78.80.00842024-01-23
CVE-2024-490406.67.50.07752024-11-12
CVE-2020-9236 6.58.80.00422024-12-27
CVE-2025-31951 6.48.80.00252026-05-06
CVE-2026-11172 6.48.80.00232026-06-04
CVE-2026-11175 6.48.80.00232026-06-04
CVE-2024-38197 6.36.50.16082024-08-13
CVE-2022-39258 6.28.10.00662022-09-27
CVE-2024-52269 6.08.10.00282024-12-04
CVE-2025-11720 6.08.10.00252025-10-14
CVE-2026-21527 6.06.50.07682026-02-10
CVE-2019-25718 6.08.40.00122026-06-01
CVE-2026-538295.98.00.00232026-06-12
CVE-2022-32816 5.86.50.06702022-09-23
CVE-2024-23708 5.87.80.00342024-05-07
CVE-2024-52276 5.87.50.00352024-12-04