I'd suggest to split MASWE-0083 between user-managed input (text) CWE-345: Insufficient Verification of Data Authenticity, which relays to human fail or injection, and system-managed input (QR, URL, clipboard) CWE-348: Use of Less Trusted Source, related to external attacks where the data may be tampered without user knowing it.
Originally posted by @truerick in OWASP/mastg#3152 (comment)