VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,104)

page 125 of 156
  • CVE-2026-21619HigFeb 27, 2026
    risk 0.42cvss 7.5epss 0.01

    Uncontrolled Resource Consumption, Deserialization of Untrusted Data vulnerability in hexpm hex_core (hex_api modules), hexpm hex (mix_hex_api modules), erlang rebar3 (r3_hex_api modules) allows Object Injection, Excessive Allocation. This vulnerability is associated with…

  • CVE-2026-1235MedFeb 11, 2026
    risk 0.42cvss 6.5epss 0.00

    The WP eCommerce WordPress plugin through 3.15.1 unserializes user input via ajax actions, which could allow unauthenticated users to perform PHP Object Injection when a suitable gadget is present on the blog.

  • CVE-2026-23864HigJan 26, 2026
    risk 0.42cvss 7.5epss 0.02

    Multiple denial of service vulnerabilities exist in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack, react-server-dom-webpack. The vulnerabilities are triggered by sending specially crafted HTTP requests to Server…

  • CVE-2026-23737HigJan 21, 2026
    risk 0.42cvss 7.5epss 0.01

    seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. In versions 1.4.0 and below, improper input handling in the JSON deserialization component can lead to arbitrary JavaScript code execution. Exploitation is possible via…

  • CVE-2025-14071HigDec 21, 2025
    risk 0.42cvss 7.5epss 0.01

    The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.0.2 via deserialization of untrusted input in the dslc_module_posts_output shortcode. This makes it possible for authenticated…

  • CVE-2025-65035MedDec 19, 2025
    risk 0.42cvss 6.4epss 0.00

    pluginsGLPI's Database Inventory Plugin "manages" the Teclib' inventory agents in order to perform an inventory of the databases present on the workstation. Prior to version 1.1.2, in certain conditions (database write access must first be obtained through another vulnerability…

  • CVE-2025-63617MedNov 10, 2025
    risk 0.42cvss 6.5epss 0.00

    ktg-mes before commit a484f96 (2025-07-03) has a fastjson deserialization vulnerability. This is because it uses a vulnerable version of fastjson and deserializes unsafe input data.

  • CVE-2025-61505MedOct 10, 2025
    risk 0.42cvss 6.5epss 0.00

    e107 CMS thru 2.3.3 are vulnerable to insecure deserialization in the `install.php` script. The script processes user-controlled input in the `previous_steps` POST parameter using `unserialize(base64_decode())` without validation, allowing attackers to craft malicious serialized…

  • CVE-2025-60834MedOct 8, 2025
    risk 0.42cvss 6.5epss 0.00

    A fastjson deserialization vulnerability in uzy-ssm-mall v1.1.0 allows attackers to execute arbitrary code via supplying a crafted input.

  • CVE-2025-60830MedOct 8, 2025
    risk 0.42cvss 6.5epss 0.00

    redragon-erp v1.0 was discovered to contain a Shiro deserialization vulnerability caused by the default Shiro key.

  • CVE-2025-60828MedOct 8, 2025
    risk 0.42cvss 6.5epss 0.00

    WukongCRM-9.0-JAVA was discovered to contain a fastjson deserialization vulnerability via the /OaExamine/setOaExamine interface.

  • CVE-2025-9260MedSep 3, 2025
    risk 0.42cvss 6.5epss 0.01

    The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to PHP Object Injection in versions 5.1.16 to 6.1.1 via deserialization of untrusted input in the parseUserProperties function. This makes it possible…

  • CVE-2025-25692MedJul 30, 2025
    risk 0.42cvss 6.5epss 0.01

    A PHAR deserialization vulnerability in the _getHeaders function of PrestaShop v8.2.0 allows attackers to execute arbitrary code via a crafted POST request.

  • CVE-2025-25691MedJul 30, 2025
    risk 0.42cvss 6.5epss 0.01

    A PHAR deserialization vulnerability in the component /themes/import of PrestaShop v8.2.0 allows attackers to execute arbitrary code via a crafted POST request.

  • CVE-2025-4393MedJul 24, 2025
    risk 0.42cvss 6.5epss 0.00

    Medtronic MyCareLink Patient Monitor has an internal service that deserializes data, which allows a local attacker to interact with the service by crafting a binary payload to crash the service or elevate privileges. This issue affects MyCareLink Patient Monitor models 24950…

  • CVE-2025-43713MedJul 3, 2025
    risk 0.42cvss 6.5epss 0.00

    ASNA Assist and ASNA Registrar before 2025-03-31 allow deserialization attacks against .NET remoting. These are Windows system services that support license key management and deprecated Windows network authentication. The services are implemented with .NET remoting and can be…

  • CVE-2025-3857HigApr 21, 2025
    risk 0.42cvss 7.5epss 0.01

    When reading binary Ion data through Amazon.IonDotnet using the RawBinaryReader class, Amazon.IonDotnet does not check the number of bytes read from the underlying stream while deserializing the binary format. If the Ion data is malformed or truncated, this triggers an infinite…

  • CVE-2025-2485HigMar 28, 2025
    risk 0.42cvss 7.5epss 0.01

    The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3.8.7 via deserialization of untrusted input from the 'dnd_upload_cf7_upload' function. This makes it possible for…

  • CVE-2025-30160HigMar 20, 2025
    risk 0.42cvss 7.5epss 0.01

    Redlib is an alternative private front-end to Reddit. A vulnerability has been identified in Redlib where an attacker can cause a denial-of-service (DOS) condition by submitting a specially crafted base2048-encoded DEFLATE decompression bomb to the restore_preferences form. This…

  • CVE-2024-10942HigMar 13, 2025
    risk 0.42cvss 7.5epss 0.01

    The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 7.89 via deserialization of untrusted input in the 'replace_serialized_values' function. This makes it possible for unauthenticated attackers…