CWE-502
Deserialization of Untrusted Data
Description
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-586
CVEs mapped to this weakness (3,308)
page 132 of 166| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-68756 | Med | 0.43 | 6.6 | 0.00 | Aug 12, 2026 | A party with write access to stored session data may affect JFrog Artifactory under specific conditions. | ||
| CVE-2026-16062 | Med | 0.43 | 6.6 | 0.00 | Aug 2, 2026 | The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not prevent the deserialization of user-controlled input in some of its event content fields, allowing users with Contributor-level access and above to inject PHP objects. No POP chain is present in… | ||
| CVE-2026-12115 | Med | 0.43 | 6.6 | 0.01 | Jun 17, 2026 | The Counter Box – Add Countdowns, Timers & Dynamic Counters to WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.0.13 via deserialization of untrusted input . This makes it possible for authenticated attackers, with… | ||
| CVE-2026-7566 | Med | 0.43 | 6.6 | 0.00 | Jun 6, 2026 | The LearnPress – Backup & Migration Tool plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.1.4 via deserialization of untrusted input . This makes it possible for authenticated attackers, with administrator-level access and… | ||
| CVE-2026-48919 | Med | 0.43 | 6.6 | 0.00 | May 27, 2026 | Jenkins Active Directory Plugin 2.41 and earlier deserializes data from LDAP referrals without validation. | ||
| CVE-2026-48917 | Med | 0.43 | 6.6 | 0.00 | May 27, 2026 | Jenkins LDAP Plugin 807.v7d7de30930cf and earlier deserializes data from LDAP referrals without validation. | ||
| CVE-2025-67779 | Hig | 0.43 | 7.5 | 0.20 | Dec 12, 2025 | It was found that the fix addressing CVE-2025-55184 in React Server Components was incomplete and does not prevent a denial of service attack in a specific case. React Server Components versions 19.0.2, 19.1.3 and 19.2.2 are affected, allowing unsafe deserialization of payloads… | ||
| CVE-2025-67535 | Med | 0.43 | 6.6 | 0.00 | Dec 9, 2025 | Deserialization of Untrusted Data vulnerability in Flipper Code - WordPress Development Company WP Maps wp-google-map-plugin allows Object Injection.This issue affects WP Maps: from n/a through <= 4.8.6. | ||
| CVE-2025-54053 | Med | 0.43 | 6.6 | 0.00 | Aug 20, 2025 | Deserialization of Untrusted Data vulnerability in Adrian Tobey Groundhogg groundhogg allows Object Injection.This issue affects Groundhogg: from n/a through <= 4.2.2. | ||
| CVE-2025-46738 | Med | 0.43 | 6.6 | 0.00 | May 12, 2025 | An authenticated attacker can maliciously modify layout data files in the SEL-5033 installation directory to execute arbitrary code. | ||
| CVE-2025-39565 | Med | 0.43 | 6.6 | 0.01 | Apr 16, 2025 | Deserialization of Untrusted Data vulnerability in Melapress MelaPress Login Security melapress-login-security allows Object Injection.This issue affects MelaPress Login Security: from n/a through <= 2.1.0. | ||
| CVE-2021-27017 | Med | 0.43 | 6.6 | 0.01 | Feb 7, 2025 | Utilization of a module presented a security risk by allowing the deserialization of untrusted/user supplied data. This is resolved in the Puppet Agent 7.4.0 release. | ||
| CVE-2024-13297 | Med | 0.43 | 6.6 | 0.00 | Jan 9, 2025 | Deserialization of Untrusted Data vulnerability in Drupal Eloqua allows Object Injection.This issue affects Eloqua: from 7.X-* before 7.X-1.15. | ||
| CVE-2024-13296 | Med | 0.43 | 6.6 | 0.00 | Jan 9, 2025 | Deserialization of Untrusted Data vulnerability in Drupal Mailjet allows Object Injection.This issue affects Mailjet: from 0.0.0 before 4.0.1. | ||
| CVE-2024-13295 | Med | 0.43 | 6.6 | 0.00 | Jan 9, 2025 | Deserialization of Untrusted Data vulnerability in Drupal Node export allows Object Injection.This issue affects Node export: from 7.X-* before 7.X-3.3. | ||
| CVE-2021-4451 | Med | 0.43 | 6.6 | 0.01 | Oct 16, 2024 | The NinjaFirewall plugin for WordPress is vulnerable to Authenticated PHAR Deserialization in versions up to, and including, 4.3.3. This allows authenticated attackers to perform phar deserialization on the server. This deserialization can allow other plugin or theme exploits… | ||
| CVE-2024-43466 | Med | 0.43 | 6.5 | 0.04 | Sep 10, 2024 | Microsoft SharePoint Server Denial of Service Vulnerability | ||
| CVE-2024-0668 | Med | 0.43 | 6.6 | 0.01 | Feb 5, 2024 | The Advanced Database Cleaner plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.1.3 via deserialization of untrusted input in the 'process_bulk_action' function. This makes it possible for authenticated attacker, with… | ||
| CVE-2022-45083 | Med | 0.43 | 6.6 | 0.01 | Jan 19, 2024 | Deserialization of Untrusted Data vulnerability in ProfilePress Membership Team Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress.This issue affects Paid Membership Plugin, Ecommerce, User Registration Form,… | ||
| CVE-2023-36381 | Med | 0.43 | 6.6 | 0.00 | Dec 28, 2023 | Deserialization of Untrusted Data vulnerability in Gesundheit Bewegt GmbH Zippy.This issue affects Zippy: from n/a through 1.6.5. |
- risk 0.43cvss 6.6epss 0.00
A party with write access to stored session data may affect JFrog Artifactory under specific conditions.
- risk 0.43cvss 6.6epss 0.00
The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not prevent the deserialization of user-controlled input in some of its event content fields, allowing users with Contributor-level access and above to inject PHP objects. No POP chain is present in…
- risk 0.43cvss 6.6epss 0.01
The Counter Box – Add Countdowns, Timers & Dynamic Counters to WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.0.13 via deserialization of untrusted input . This makes it possible for authenticated attackers, with…
- risk 0.43cvss 6.6epss 0.00
The LearnPress – Backup & Migration Tool plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.1.4 via deserialization of untrusted input . This makes it possible for authenticated attackers, with administrator-level access and…
- risk 0.43cvss 6.6epss 0.00
Jenkins Active Directory Plugin 2.41 and earlier deserializes data from LDAP referrals without validation.
- risk 0.43cvss 6.6epss 0.00
Jenkins LDAP Plugin 807.v7d7de30930cf and earlier deserializes data from LDAP referrals without validation.
- risk 0.43cvss 7.5epss 0.20
It was found that the fix addressing CVE-2025-55184 in React Server Components was incomplete and does not prevent a denial of service attack in a specific case. React Server Components versions 19.0.2, 19.1.3 and 19.2.2 are affected, allowing unsafe deserialization of payloads…
- risk 0.43cvss 6.6epss 0.00
Deserialization of Untrusted Data vulnerability in Flipper Code - WordPress Development Company WP Maps wp-google-map-plugin allows Object Injection.This issue affects WP Maps: from n/a through <= 4.8.6.
- risk 0.43cvss 6.6epss 0.00
Deserialization of Untrusted Data vulnerability in Adrian Tobey Groundhogg groundhogg allows Object Injection.This issue affects Groundhogg: from n/a through <= 4.2.2.
- risk 0.43cvss 6.6epss 0.00
An authenticated attacker can maliciously modify layout data files in the SEL-5033 installation directory to execute arbitrary code.
- risk 0.43cvss 6.6epss 0.01
Deserialization of Untrusted Data vulnerability in Melapress MelaPress Login Security melapress-login-security allows Object Injection.This issue affects MelaPress Login Security: from n/a through <= 2.1.0.
- risk 0.43cvss 6.6epss 0.01
Utilization of a module presented a security risk by allowing the deserialization of untrusted/user supplied data. This is resolved in the Puppet Agent 7.4.0 release.
- risk 0.43cvss 6.6epss 0.00
Deserialization of Untrusted Data vulnerability in Drupal Eloqua allows Object Injection.This issue affects Eloqua: from 7.X-* before 7.X-1.15.
- risk 0.43cvss 6.6epss 0.00
Deserialization of Untrusted Data vulnerability in Drupal Mailjet allows Object Injection.This issue affects Mailjet: from 0.0.0 before 4.0.1.
- risk 0.43cvss 6.6epss 0.00
Deserialization of Untrusted Data vulnerability in Drupal Node export allows Object Injection.This issue affects Node export: from 7.X-* before 7.X-3.3.
- risk 0.43cvss 6.6epss 0.01
The NinjaFirewall plugin for WordPress is vulnerable to Authenticated PHAR Deserialization in versions up to, and including, 4.3.3. This allows authenticated attackers to perform phar deserialization on the server. This deserialization can allow other plugin or theme exploits…
- risk 0.43cvss 6.5epss 0.04
Microsoft SharePoint Server Denial of Service Vulnerability
- risk 0.43cvss 6.6epss 0.01
The Advanced Database Cleaner plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.1.3 via deserialization of untrusted input in the 'process_bulk_action' function. This makes it possible for authenticated attacker, with…
- risk 0.43cvss 6.6epss 0.01
Deserialization of Untrusted Data vulnerability in ProfilePress Membership Team Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress.This issue affects Paid Membership Plugin, Ecommerce, User Registration Form,…
- risk 0.43cvss 6.6epss 0.00
Deserialization of Untrusted Data vulnerability in Gesundheit Bewegt GmbH Zippy.This issue affects Zippy: from n/a through 1.6.5.