VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,308)

page 133 of 166
  • CVE-2023-46154MedDec 19, 2023
    risk 0.43cvss 6.6epss 0.01

    Deserialization of Untrusted Data vulnerability in E2Pdf.Com E2Pdf – Export To Pdf Tool for WordPress.This issue affects E2Pdf – Export To Pdf Tool for WordPress: from n/a through 1.20.18.

  • CVE-2022-39298HigOct 12, 2022
    risk 0.43cvss 7.7epss 0.01

    MelisFront is the engine that displays website hosted on Melis Platform. It deals with showing pages, plugins, URL rewritting, search optimization and SEO, etc. Attackers can deserialize arbitrary data on affected versions of `melisplatform/melis-front`, and ultimately leads to…

  • CVE-2022-39297HigOct 12, 2022
    risk 0.43cvss 7.7epss 0.01

    MelisCms provides a full CMS for Melis Platform, including templating system, drag'n'drop of plugins, SEO and many administration tools. Attackers can deserialize arbitrary data on affected versions of `melisplatform/melis-cms`, and ultimately leads to the execution of arbitrary…

  • CVE-2021-23592HigMay 6, 2022
    risk 0.43cvss 7.7epss 0.02

    The package topthink/framework before 6.0.12 are vulnerable to Deserialization of Untrusted Data due to insecure unserialize method in the Driver class.

  • CVE-2021-39140MedAug 23, 2021
    risk 0.43cvss 6.5epss 0.06

    XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of…

  • CVE-2021-23420HigAug 11, 2021
    risk 0.43cvss 7.7epss 0.03

    This affects the package codeception/codeception from 4.0.0 and before 4.1.22, before 3.1.3. The RunProcess class can be leveraged as a gadget to run arbitrary commands on a system that is deserializing user input without validation.

  • CVE-2021-21349MedMar 23, 2021
    risk 0.43cvss 6.1epss 0.47

    XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed input…

  • CVE-2021-21345MedMar 23, 2021
    risk 0.43cvss 5.8epss 0.72

    XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker who has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user…

  • CVE-2020-10740MedJun 22, 2020
    risk 0.43cvss 6.6epss 0.02

    A vulnerability was found in Wildfly in versions before 20.0.0.Final, where a remote deserialization attack is possible in the Enterprise Application Beans(EJB) due to lack of validation/filtering capabilities in wildfly.

  • CVE-2020-4043HigJun 10, 2020
    risk 0.43cvss 7.7epss 0.03

    phpMussel from versions 1.0.0 and less than 1.6.0 has an unserialization vulnerability in PHP's phar wrapper. Uploading a specially crafted file to an affected version allows arbitrary code execution (discovered, tested, and confirmed by myself), so the risk factor should be…

  • CVE-2020-9484HigMay 20, 2020
    risk 0.43cvss 7.0epss 0.57

    When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is configured to use the PersistenceManager with a FileStore;…

  • CVE-2019-14439HigJul 30, 2019
    risk 0.43cvss 7.5epss 0.11

    A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2. This occurs when Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the logback jar in the classpath.

  • CVE-2026-93872HigSep 18, 2026
    risk 0.42cvss 7.5epss 0.00

    Cotonti 1.0.0 passes the base64-decoded cb parameter to unserialize() without allowed_classes restriction in the comments plugin EditAction. Registered users with comment write permissions can instantiate arbitrary PHP objects and potentially achieve file write or code execution…

  • CVE-2026-11711MedSep 18, 2026
    risk 0.42cvss 6.5epss 0.00

    IBM WebSphere Application Server 9.0 and 8.5 is affected by a deserialization vulnerability in the Name Service component.

  • CVE-2026-57822MedSep 10, 2026
    risk 0.42cvss 6.5epss 0.00

    When the broker is processing message-based management requests, sent by an authenticated messaging client that is authorized with MANAGE permission to perform management-via-messaging, the parameter processing can trigger Java deserialization of certain method parameters that…

  • CVE-2024-58381HigSep 9, 2026
    risk 0.42cvss 7.5epss 0.00

    PocketMine-MP before 5.11.1 contains a denial of service vulnerability in LoginPacket JSON processing that allows remote attackers to crash the server by sending malformed JSON data. Attackers can exploit improper object initialization from scalar JSON types to trigger unset…

  • CVE-2026-61686HigSep 4, 2026
    risk 0.42cvss 7.5epss 0.00

    SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, the `DataGrid` LiveComponent deserializes a `context` prop value using PHP's `unserialize()` after receiving it from the client. Because the prop is marked `writable: true`, an authenticated attacker can…

  • CVE-2026-82259HigAug 28, 2026
    risk 0.42cvss 7.5epss 0.00

    SvelteKit versions from 2.49.0 through 2.53.2 (fixed in 2.53.3) contain a deserialization expansion issue in the experimental form remote function. When an application enables experimental.remoteFunctions and uses the form function to process the files array without validating…

  • CVE-2026-63516MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.01

    Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

  • CVE-2026-62912MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.01

    Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to deny service over a network.