VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,116)

page 103 of 156
  • CVE-2026-24385HigMar 5, 2026
    risk 0.49cvss 7.5epss 0.00

    Deserialization of Untrusted Data vulnerability in gerritvanaaken Podlove Web Player podlove-web-player allows Object Injection.This issue affects Podlove Web Player: from n/a through <= 5.9.1.

  • CVE-2026-2471HigFeb 28, 2026
    risk 0.49cvss 7.5epss 0.00

    The WP Mail Logging plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.15.0 via deserialization of untrusted input from the email log message field. This is due to the `BaseModel` class constructor calling `maybe_unserialize()` on…

  • CVE-2026-24891HigFeb 20, 2026
    risk 0.49cvss 7.5epss 0.00

    openITCOCKPIT is an open source monitoring tool built for different monitoring engines like Nagios, Naemon and Prometheus. Versions 5.3.1 and below contain an unsafe deserialization sink in the Gearman worker implementation. The worker function registered as oitc_gearman calls…

  • CVE-2026-21511HigFeb 10, 2026
    risk 0.49cvss 7.5epss 0.04

    Deserialization of untrusted data in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2026-25614HigFeb 3, 2026
    risk 0.49cvss 7.5epss 0.00

    Blesta 3.x through 5.x before 5.13.3 allows object injection, aka CORE-5680.

  • CVE-2026-0772HigJan 23, 2026
    risk 0.49cvss 7.5epss 0.01

    Langflow Disk Cache Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Authentication is required to exploit this vulnerability. The specific flaw…

  • CVE-2025-68924HigJan 16, 2026
    risk 0.49cvss 7.5epss 0.01

    In Umbraco UmbracoForms through 8.13.16, an authenticated attacker can supply a malicious WSDL (aka Webservice) URL as a data source for remote code execution.

  • CVE-2026-21226HigJan 13, 2026
    risk 0.49cvss 7.5epss 0.01

    Deserialization of untrusted data in Azure Core shared client library for Python allows an authorized attacker to execute code over a network.

  • CVE-2025-68665HigDec 23, 2025
    risk 0.49cvss 8.6epss 0.01

    LangChain is a framework for building LLM-powered applications. Prior to @langchain/core versions 0.3.80 and 1.1.8, and prior to langchain versions 0.3.37 and 1.2.3, a serialization injection vulnerability exists in LangChain JS's toJSON() method (and subsequently when…

  • CVE-2025-63951HigDec 18, 2025
    risk 0.49cvss 7.5epss 0.01

    An insecure deserialization vulnerability exists in the rss-mp3.php script of the MiczFlor RPi-Jukebox-RFID project through commit 4b2334f0ae0e87c0568876fc41c48c38aa9a7014 (2025-10-07). The 'rss' GET parameter receives data that is passed directly to the unserialize() function…

  • CVE-2025-63950HigDec 18, 2025
    risk 0.49cvss 7.5epss 0.01

    An insecure deserialization vulnerability exists in the download.php script of the to3k Twittodon application through commit b1c58a7d1dc664b38deb486ca290779621342c0b (2023-02-28). The 'obj' parameter receives base64-encoded data that is passed directly to the unserialize()…

  • CVE-2025-60080HigDec 18, 2025
    risk 0.49cvss 7.5epss 0.00

    Deserialization of Untrusted Data vulnerability in add-ons.org PDF for Gravity Forms + Drag And Drop Template Builder pdf-for-gravity-forms allows Object Injection.This issue affects PDF for Gravity Forms + Drag And Drop Template Builder: from n/a through <= 6.5.0.

  • CVE-2025-64512HigNov 10, 2025
    risk 0.49cvss 8.6epss 0.00

    Pdfminer.six is a community maintained fork of the original PDFMiner, a tool for extracting information from PDF documents. Prior to version 20251107, pdfminer.six will execute arbitrary code from a malicious pickle file if provided with a malicious PDF file. The…

  • CVE-2025-8289HigAug 20, 2025
    risk 0.49cvss 7.5epss 0.00

    The Redirection for Contact Form 7 plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.2.4 via deserialization of untrusted input in the delete_associated_files function. This makes it possible for unauthenticated attackers to…

  • CVE-2025-6742HigJul 9, 2025
    risk 0.49cvss 7.5epss 0.00

    The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.7.3 via the use of file_exists() in the delete_entry_files() function without restriction on the path provided. This…

  • CVE-2025-6464HigJul 2, 2025
    risk 0.49cvss 7.5epss 0.00

    The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.44.2 via deserialization of untrusted input in the 'entry_delete_upload_files' function. This makes it…

  • CVE-2025-27819HigJun 10, 2025
    risk 0.49cvss 7.5epss 0.01

    In CVE-2023-25194, we announced the RCE/Denial of service attack via SASL JAAS JndiLoginModule configuration in Kafka Connect API. But not only Kafka Connect API is vulnerable to this attack, the Apache Kafka brokers also have this vulnerability. To exploit this vulnerability,…

  • CVE-2025-48018HigMay 20, 2025
    risk 0.49cvss 7.5epss 0.00

    An authenticated user can modify application state data.

  • CVE-2025-23249HigApr 22, 2025
    risk 0.49cvss 7.6epss 0.01

    NVIDIA NeMo Framework contains a vulnerability where a user could cause a deserialization of untrusted data by remote code execution. A successful exploit of this vulnerability might lead to code execution and data tampering.

  • CVE-2025-31103HigMar 31, 2025
    risk 0.49cvss 7.5epss 0.00

    Untrusted data deserialization vulnerability exists in a-blog cms. Processing a specially crafted request may store arbitrary files on the server where the product is running. This can be leveraged to execute an arbitrary script on the server.