VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,116)

page 112 of 156
  • CVE-2024-13899HigFeb 22, 2025
    risk 0.47cvss 7.2epss 0.01

    The Mambo Importer plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0 via deserialization of untrusted input via the $data parameter in the fImportMenu function. This makes it possible for authenticated attackers, with…

  • CVE-2024-9664HigFeb 7, 2025
    risk 0.47cvss 7.2epss 0.01

    The WP All Import Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.9.7 via deserialization of untrusted input from an import file. This makes it possible for authenticated attackers, with Administrator-level access and above,…

  • CVE-2025-0841HigJan 29, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability has been found in Aridius XYZ up to 20240927 on OpenCart and classified as critical. This vulnerability affects the function loadMore of the component News. The manipulation leads to deserialization. The attack can be initiated remotely. The exploit has been…

  • CVE-2025-0586HigJan 20, 2025
    risk 0.47cvss 7.2epss 0.01

    The a+HRD from aEnrich Technology has an Insecure Deserialization vulnerability, allowing remote attackers with database modification privileges and regular system privileges to perform arbitrary code execution.

  • CVE-2025-22510HigJan 9, 2025
    risk 0.47cvss 7.2epss 0.01

    Deserialization of Untrusted Data vulnerability in kkarpieszuk WC Price History for Omnibus wc-price-history allows Object Injection.This issue affects WC Price History for Omnibus: from n/a through <= 2.1.4.

  • CVE-2024-11465HigJan 7, 2025
    risk 0.47cvss 7.2epss 0.01

    The Custom Product Tabs for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.8.5 via deserialization of untrusted input in the 'yikes_woo_products_tabs' post meta parameter. This makes it possible for authenticated…

  • CVE-2024-12721HigDec 21, 2024
    risk 0.47cvss 7.2epss 0.01

    The Custom Product Tabs For WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.2.4 via deserialization of untrusted input from the 'wb_custom_tabs' parameter. This makes it possible for authenticated attackers, with…

  • CVE-2024-54282HigDec 13, 2024
    risk 0.47cvss 7.2epss 0.01

    Deserialization of Untrusted Data vulnerability in Themeum WP Mega Menu wp-megamenu allows Object Injection.This issue affects WP Mega Menu: from n/a through <= 1.4.2.

  • CVE-2022-41137HigDec 5, 2024
    risk 0.47cvss 8.3epss 0.02

    Apache Hive Metastore (HMS) uses SerializationUtilities#deserializeObjectWithTypeInformation method when filtering and fetching partitions that is unsafe and can lead to Remote Code Execution (RCE) since it allows the deserialization of arbitrary data. In real deployments,…

  • CVE-2024-5580HigNov 22, 2024
    risk 0.47cvss 7.2epss 0.02

    Allegra loadFieldMatch Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Allegra. Authentication is required to exploit this vulnerability. The specific flaw…

  • CVE-2024-5579HigNov 22, 2024
    risk 0.47cvss 7.2epss 0.02

    Allegra renderFieldMatch Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Allegra. Authentication is required to exploit this vulnerability. The specific flaw…

  • CVE-2024-11409HigNov 21, 2024
    risk 0.47cvss 7.2epss 0.01

    The Grid View Gallery plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0 via deserialization of untrusted input from cs_all_photos_details parameter. This makes it possible for authenticated attackers, with Editor-level access…

  • CVE-2023-32736HigNov 12, 2024
    risk 0.47cvss 7.3epss 0.00

    A vulnerability has been identified in SIMATIC S7-PLCSIM V16 (All versions), SIMATIC S7-PLCSIM V17 (All versions), SIMATIC STEP 7 Safety V16 (All versions), SIMATIC STEP 7 Safety V17 (All versions < V17 Update 8), SIMATIC STEP 7 Safety V18 (All versions < V18 Update 5), SIMATIC…

  • CVE-2024-49684HigOct 23, 2024
    risk 0.47cvss 7.2epss 0.01

    Deserialization of Untrusted Data vulnerability in revmakx Backup and Staging by WP Time Capsule wp-time-capsule allows Object Injection.This issue affects Backup and Staging by WP Time Capsule: from n/a through <= 1.22.21.

  • CVE-2024-9005HigOct 8, 2024
    risk 0.47cvss epss 0.00

    CWE-502: Deserialization of Untrusted Data vulnerability exists that could allow code to be remotely executed on the server when unsafely deserialized data is posted to the web server.

  • CVE-2024-43191HigSep 26, 2024
    risk 0.47cvss 7.2epss 0.01

    IBM ManageIQ could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted yaml file request.

  • CVE-2024-7351HigAug 24, 2024
    risk 0.47cvss 7.2epss 0.01

    The Simple Job Board plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.12.3 via deserialization of untrusted input when editing job applications. This makes it possible for authenticated attackers, with Editor-level access and…

  • CVE-2024-7560HigAug 8, 2024
    risk 0.47cvss 7.2epss 0.01

    The News Flash theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1.0 via deserialization of untrusted input from the newsflash_post_meta meta value. This makes it possible for authenticated attackers, with Editor-level access and…

  • CVE-2024-2290HigMay 14, 2024
    risk 0.47cvss 7.2epss 0.01

    The Advanced Ads plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.52.1 via deserialization of untrusted input in the 'placement_slug' parameter. This makes it possible for authenticated attackers to inject a PHP Object. No POP…

  • CVE-2023-4971HigOct 16, 2023
    risk 0.47cvss 7.2epss 0.01

    The Weaver Xtreme Theme Support WordPress plugin before 6.3.1 unserialises the content of an imported file, which could lead to PHP object injections issues when a high privilege user import a malicious file and a suitable gadget chain is present on the blog.