CWE-502
Deserialization of Untrusted Data
Description
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-586
CVEs mapped to this weakness (3,116)
page 109 of 156| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-66256 | Hig | 0.47 | 7.2 | 0.01 | Aug 13, 2026 | ** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Shindig. This issue affects Apache Shindig: all versions. Users with access to the Shindig REST API can send specially-crafted requests to trigger arbitrary code execution on the server. … | ||
| CVE-2026-27380 | Hig | 0.47 | 7.2 | 0.00 | Aug 13, 2026 | Editor PHP Object Injection in Car Rental Manager <= 1.3.9 versions. | ||
| CVE-2026-67260 | Hig | 0.47 | 7.3 | 0.01 | Aug 12, 2026 | Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swept by the scheduler. That sweep deserializes the task instance's `next_kwargs` without an allow-list, so a Dag author — who controls that value through the task… | ||
| CVE-2026-65549 | Hig | 0.47 | 7.2 | 0.00 | Aug 6, 2026 | Author PHP Object Injection in Jeg Kit for Elementor <= 3.2.10 versions. | ||
| CVE-2026-39499 | Hig | 0.47 | 7.2 | 0.00 | Jun 15, 2026 | Shop manager PHP Object Injection in Advanced Product Fields (Product Addons) for WooCommerce <= 1.6.19 versions. | ||
| CVE-2026-39498 | Hig | 0.47 | 7.2 | 0.00 | Jun 15, 2026 | Shop manager PHP Object Injection in YayMail <= 4.3.3 versions. | ||
| CVE-2026-39481 | Hig | 0.47 | 7.2 | 0.00 | Jun 15, 2026 | Author PHP Object Injection in Modula Image Gallery <= 2.14.18 versions. | ||
| CVE-2026-39472 | Hig | 0.47 | 7.2 | 0.00 | Jun 15, 2026 | Shop manager PHP Object Injection in WooCommerce PDF Invoices & Packing Slips < 5.9.0 versions. | ||
| CVE-2026-39471 | Hig | 0.47 | 7.2 | 0.00 | Jun 15, 2026 | Author PHP Object Injection in ShortPixel Image Optimizer <= 6.4.3 versions. | ||
| CVE-2026-39434 | Hig | 0.47 | 7.2 | 0.00 | Jun 15, 2026 | Shop manager PHP Object Injection in CTX Feed <= 6.6.26 versions. | ||
| CVE-2026-37579 | Hig | 0.47 | 7.3 | 0.00 | May 28, 2026 | An issue in SMSGate sms-core<=2.1.13.6 allows a remote attacker to execute arbitrary code via the Cmpp7FDeliverRequestMessageCodec.java component | ||
| CVE-2026-8751 | Hig | 0.47 | 7.3 | 0.00 | May 17, 2026 | A security flaw has been discovered in h2oai h2o-3 up to 7402. This affects the function importBinaryModel of the file h2o-core/src/main/java/hex/Model.java of the component JAR Handler. Performing a manipulation results in deserialization. The attack is possible to be carried… | ||
| CVE-2026-39467 | Hig | 0.47 | 7.2 | 0.00 | Apr 21, 2026 | Deserialization of Untrusted Data vulnerability in MetaSlider Responsive Slider by MetaSlider allows Object Injection.This issue affects Responsive Slider by MetaSlider: from n/a through 3.106.0. | ||
| CVE-2026-24156 | Hig | 0.47 | 7.3 | 0.00 | Apr 7, 2026 | NVIDIA DALI contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to arbitrary code execution. | ||
| CVE-2026-5536 | Hig | 0.47 | 7.3 | 0.00 | Apr 5, 2026 | A weakness has been identified in FedML-AI FedML up to 0.8.9. Affected is the function sendMessage of the file grpc_server.py of the component gRPC server. Executing a manipulation can lead to deserialization. The attack may be performed from remote. The vendor was contacted… | ||
| CVE-2026-33725 | Hig | 0.47 | 7.2 | 0.01 | Mar 27, 2026 | Metabase is an open source business intelligence and embedded analytics tool. In Metabase Enterprise prior to versions 1.54.22, 1.55.22, 1.56.22, 1.57.16, 1.58.10, and 1.59.4, authenticated admins on Metabase Enterprise Edition can achieve Remote Code Execution (RCE) and… | ||
| CVE-2026-4860 | Hig | 0.47 | 7.3 | 0.00 | Mar 26, 2026 | A security flaw has been discovered in 648540858 wvp-GB28181-pro up to 2.7.4. This affects the function GenericFastJsonRedisSerializer of the file src/main/java/com/genersoft/iot/vmp/conf/redis/RedisTemplateConfig.java of the component API Endpoint. The manipulation results in… | ||
| CVE-2026-3328 | Hig | 0.47 | 7.2 | 0.01 | Mar 26, 2026 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to PHP Object Injection via deserialization of the 'post_content' of admin_form posts in all versions up to, and including, 3.28.31. This is due to the use of WordPress's `maybe_unserialize()` function without… | ||
| CVE-2026-22480 | Hig | 0.47 | 7.2 | 0.01 | Mar 25, 2026 | Deserialization of Untrusted Data vulnerability in WebToffee Product Feed for WooCommerce webtoffee-product-feed allows Object Injection.This issue affects Product Feed for WooCommerce: from n/a through <= 2.3.3. | ||
| CVE-2024-47886 | Hig | 0.47 | 7.2 | 0.01 | Mar 2, 2026 | Chamilo is a learning management system. Chamillo is affected by a post-authentication phar unserialize which leads to a remote code execution (RCE) within versions 1.11.12 to 1.11.26. By abusing multiple supported features from the virtualization plugin vchamilo, the… |
- risk 0.47cvss 7.2epss 0.01
** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Shindig. This issue affects Apache Shindig: all versions. Users with access to the Shindig REST API can send specially-crafted requests to trigger arbitrary code execution on the server. …
- risk 0.47cvss 7.2epss 0.00
Editor PHP Object Injection in Car Rental Manager <= 1.3.9 versions.
- risk 0.47cvss 7.3epss 0.01
Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swept by the scheduler. That sweep deserializes the task instance's `next_kwargs` without an allow-list, so a Dag author — who controls that value through the task…
- risk 0.47cvss 7.2epss 0.00
Author PHP Object Injection in Jeg Kit for Elementor <= 3.2.10 versions.
- risk 0.47cvss 7.2epss 0.00
Shop manager PHP Object Injection in Advanced Product Fields (Product Addons) for WooCommerce <= 1.6.19 versions.
- risk 0.47cvss 7.2epss 0.00
Shop manager PHP Object Injection in YayMail <= 4.3.3 versions.
- risk 0.47cvss 7.2epss 0.00
Author PHP Object Injection in Modula Image Gallery <= 2.14.18 versions.
- risk 0.47cvss 7.2epss 0.00
Shop manager PHP Object Injection in WooCommerce PDF Invoices & Packing Slips < 5.9.0 versions.
- risk 0.47cvss 7.2epss 0.00
Author PHP Object Injection in ShortPixel Image Optimizer <= 6.4.3 versions.
- risk 0.47cvss 7.2epss 0.00
Shop manager PHP Object Injection in CTX Feed <= 6.6.26 versions.
- risk 0.47cvss 7.3epss 0.00
An issue in SMSGate sms-core<=2.1.13.6 allows a remote attacker to execute arbitrary code via the Cmpp7FDeliverRequestMessageCodec.java component
- risk 0.47cvss 7.3epss 0.00
A security flaw has been discovered in h2oai h2o-3 up to 7402. This affects the function importBinaryModel of the file h2o-core/src/main/java/hex/Model.java of the component JAR Handler. Performing a manipulation results in deserialization. The attack is possible to be carried…
- risk 0.47cvss 7.2epss 0.00
Deserialization of Untrusted Data vulnerability in MetaSlider Responsive Slider by MetaSlider allows Object Injection.This issue affects Responsive Slider by MetaSlider: from n/a through 3.106.0.
- risk 0.47cvss 7.3epss 0.00
NVIDIA DALI contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to arbitrary code execution.
- risk 0.47cvss 7.3epss 0.00
A weakness has been identified in FedML-AI FedML up to 0.8.9. Affected is the function sendMessage of the file grpc_server.py of the component gRPC server. Executing a manipulation can lead to deserialization. The attack may be performed from remote. The vendor was contacted…
- risk 0.47cvss 7.2epss 0.01
Metabase is an open source business intelligence and embedded analytics tool. In Metabase Enterprise prior to versions 1.54.22, 1.55.22, 1.56.22, 1.57.16, 1.58.10, and 1.59.4, authenticated admins on Metabase Enterprise Edition can achieve Remote Code Execution (RCE) and…
- risk 0.47cvss 7.3epss 0.00
A security flaw has been discovered in 648540858 wvp-GB28181-pro up to 2.7.4. This affects the function GenericFastJsonRedisSerializer of the file src/main/java/com/genersoft/iot/vmp/conf/redis/RedisTemplateConfig.java of the component API Endpoint. The manipulation results in…
- risk 0.47cvss 7.2epss 0.01
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to PHP Object Injection via deserialization of the 'post_content' of admin_form posts in all versions up to, and including, 3.28.31. This is due to the use of WordPress's `maybe_unserialize()` function without…
- risk 0.47cvss 7.2epss 0.01
Deserialization of Untrusted Data vulnerability in WebToffee Product Feed for WooCommerce webtoffee-product-feed allows Object Injection.This issue affects Product Feed for WooCommerce: from n/a through <= 2.3.3.
- risk 0.47cvss 7.2epss 0.01
Chamilo is a learning management system. Chamillo is affected by a post-authentication phar unserialize which leads to a remote code execution (RCE) within versions 1.11.12 to 1.11.26. By abusing multiple supported features from the virtualization plugin vchamilo, the…