VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,308)

page 132 of 166
  • CVE-2026-68756MedAug 12, 2026
    risk 0.43cvss 6.6epss 0.00

    A party with write access to stored session data may affect JFrog Artifactory under specific conditions.

  • CVE-2026-16062MedAug 2, 2026
    risk 0.43cvss 6.6epss 0.00

    The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not prevent the deserialization of user-controlled input in some of its event content fields, allowing users with Contributor-level access and above to inject PHP objects. No POP chain is present in…

  • CVE-2026-12115MedJun 17, 2026
    risk 0.43cvss 6.6epss 0.01

    The Counter Box – Add Countdowns, Timers & Dynamic Counters to WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.0.13 via deserialization of untrusted input . This makes it possible for authenticated attackers, with…

  • CVE-2026-7566MedJun 6, 2026
    risk 0.43cvss 6.6epss 0.00

    The LearnPress – Backup & Migration Tool plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.1.4 via deserialization of untrusted input . This makes it possible for authenticated attackers, with administrator-level access and…

  • CVE-2026-48919MedMay 27, 2026
    risk 0.43cvss 6.6epss 0.00

    Jenkins Active Directory Plugin 2.41 and earlier deserializes data from LDAP referrals without validation.

  • CVE-2026-48917MedMay 27, 2026
    risk 0.43cvss 6.6epss 0.00

    Jenkins LDAP Plugin 807.v7d7de30930cf and earlier deserializes data from LDAP referrals without validation.

  • CVE-2025-67779HigDec 12, 2025
    risk 0.43cvss 7.5epss 0.20

    It was found that the fix addressing CVE-2025-55184 in React Server Components was incomplete and does not prevent a denial of service attack in a specific case. React Server Components versions 19.0.2, 19.1.3 and 19.2.2 are affected, allowing unsafe deserialization of payloads…

  • CVE-2025-67535MedDec 9, 2025
    risk 0.43cvss 6.6epss 0.00

    Deserialization of Untrusted Data vulnerability in Flipper Code - WordPress Development Company WP Maps wp-google-map-plugin allows Object Injection.This issue affects WP Maps: from n/a through <= 4.8.6.

  • CVE-2025-54053MedAug 20, 2025
    risk 0.43cvss 6.6epss 0.00

    Deserialization of Untrusted Data vulnerability in Adrian Tobey Groundhogg groundhogg allows Object Injection.This issue affects Groundhogg: from n/a through <= 4.2.2.

  • CVE-2025-46738MedMay 12, 2025
    risk 0.43cvss 6.6epss 0.00

    An authenticated attacker can maliciously modify layout data files in the SEL-5033 installation directory to execute arbitrary code.

  • CVE-2025-39565MedApr 16, 2025
    risk 0.43cvss 6.6epss 0.01

    Deserialization of Untrusted Data vulnerability in Melapress MelaPress Login Security melapress-login-security allows Object Injection.This issue affects MelaPress Login Security: from n/a through <= 2.1.0.

  • CVE-2021-27017MedFeb 7, 2025
    risk 0.43cvss 6.6epss 0.01

    Utilization of a module presented a security risk by allowing the deserialization of untrusted/user supplied data. This is resolved in the Puppet Agent 7.4.0 release.

  • CVE-2024-13297MedJan 9, 2025
    risk 0.43cvss 6.6epss 0.00

    Deserialization of Untrusted Data vulnerability in Drupal Eloqua allows Object Injection.This issue affects Eloqua: from 7.X-* before 7.X-1.15.

  • CVE-2024-13296MedJan 9, 2025
    risk 0.43cvss 6.6epss 0.00

    Deserialization of Untrusted Data vulnerability in Drupal Mailjet allows Object Injection.This issue affects Mailjet: from 0.0.0 before 4.0.1.

  • CVE-2024-13295MedJan 9, 2025
    risk 0.43cvss 6.6epss 0.00

    Deserialization of Untrusted Data vulnerability in Drupal Node export allows Object Injection.This issue affects Node export: from 7.X-* before 7.X-3.3.

  • CVE-2021-4451MedOct 16, 2024
    risk 0.43cvss 6.6epss 0.01

    The NinjaFirewall plugin for WordPress is vulnerable to Authenticated PHAR Deserialization in versions up to, and including, 4.3.3. This allows authenticated attackers to perform phar deserialization on the server. This deserialization can allow other plugin or theme exploits…

  • CVE-2024-43466MedSep 10, 2024
    risk 0.43cvss 6.5epss 0.04

    Microsoft SharePoint Server Denial of Service Vulnerability

  • CVE-2024-0668MedFeb 5, 2024
    risk 0.43cvss 6.6epss 0.01

    The Advanced Database Cleaner plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.1.3 via deserialization of untrusted input in the 'process_bulk_action' function. This makes it possible for authenticated attacker, with…

  • CVE-2022-45083MedJan 19, 2024
    risk 0.43cvss 6.6epss 0.01

    Deserialization of Untrusted Data vulnerability in ProfilePress Membership Team Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress.This issue affects Paid Membership Plugin, Ecommerce, User Registration Form,…

  • CVE-2023-36381MedDec 28, 2023
    risk 0.43cvss 6.6epss 0.00

    Deserialization of Untrusted Data vulnerability in Gesundheit Bewegt GmbH Zippy.This issue affects Zippy: from n/a through 1.6.5.