CWE-502
Deserialization of Untrusted Data
Description
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-586
CVEs mapped to this weakness (3,308)
page 14 of 166| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-71374 | Cri | 0.64 | 9.8 | 0.00 | Sep 8, 2026 | Deserialization of untrusted data vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40-03, from 11-30 through… | ||
| CVE-2026-7861 | Cri | 0.64 | 9.8 | 0.00 | Sep 7, 2026 | Deserialization of untrusted data vulnerability in Next4Biz Information Technologies Inc. CSM (Customer Service Management) allows Code Injection. This issue affects CSM (Customer Service Management): before 8.0.3. | ||
| CVE-2026-84834 | Cri | 0.64 | 9.8 | 0.00 | Sep 3, 2026 | Unauthenticated PHP Object Injection in JobSearch <= 3.2.0 versions. | ||
| CVE-2026-84753 | Cri | 0.64 | 9.8 | 0.00 | Sep 3, 2026 | Unauthenticated PHP Object Injection in Mail Mint <= 1.31.0 versions. | ||
| CVE-2026-82226 | Cri | 0.64 | 9.8 | 0.00 | Aug 31, 2026 | Unauthenticated PHP Object Injection in Tickera <= 3.6.0.2 versions. | ||
| CVE-2026-78032 | Cri | 0.64 | 9.8 | 0.00 | Aug 28, 2026 | SOY CMS contains an issue with deserialization of untrusted data. An arbitrary code may be executed by an attacker with the web server privilege. | ||
| CVE-2026-78292 | Cri | 0.64 | 9.8 | 0.01 | Aug 27, 2026 | Unauthenticated PHP Object Injection in Hash Form <= 1.4.1 versions. | ||
| CVE-2026-78286 | Cri | 0.64 | 9.8 | 0.01 | Aug 27, 2026 | Unauthenticated PHP Object Injection in Geo Controller <= 8.9.8 versions. | ||
| CVE-2026-51368 | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2026 | An issue in Beijing Tongtech Co., Ltd tongweb v.7.0.24 in the Spring HttpInovkerServiceExporter component allows a remote attacker to execute arbitrary code via a crafted request to the console/heimdall endpoint | ||
| CVE-2026-78262 | Cri | 0.64 | 9.8 | 0.00 | Aug 24, 2026 | Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions. | ||
| CVE-2026-32563 | Cri | 0.64 | 9.8 | 0.00 | Aug 24, 2026 | Subscriber PHP Object Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions. | ||
| CVE-2026-66650 | Cri | 0.64 | 9.8 | 0.00 | Aug 24, 2026 | Unauthenticated PHP Object Injection in FreightCo <= 1.1.15 versions. | ||
| CVE-2026-73993 | Cri | 0.64 | 9.8 | 0.00 | Aug 20, 2026 | Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions. | ||
| CVE-2026-66672 | Cri | 0.64 | 9.8 | 0.00 | Aug 20, 2026 | Unauthenticated PHP Object Injection in Flatastic <= 2.0 versions. | ||
| CVE-2026-66583 | Cri | 0.64 | 9.8 | 0.00 | Aug 20, 2026 | Unauthenticated PHP Object Injection in Forminator <= 1.57.0 versions. | ||
| CVE-2026-73389 | Cri | 0.64 | 9.8 | 0.00 | Aug 19, 2026 | Unauthenticated PHP Object Injection in Kalles Addons <= 1.0.6 versions. | ||
| CVE-2026-73364 | Cri | 0.64 | 9.8 | 0.00 | Aug 19, 2026 | Customer PHP Object Injection in Flexible Subscriptions <= 1.8.1 versions. | ||
| CVE-2026-73397 | Cri | 0.64 | 9.8 | 0.00 | Aug 18, 2026 | Unauthenticated Deserialization of untrusted data in Youzify <= 1.3.7 versions. | ||
| CVE-2026-73380 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2026 | Unauthenticated PHP Object Injection in Popup by Supsystic <= 1.13.0 versions. | ||
| CVE-2026-73376 | Cri | 0.64 | 9.8 | 0.00 | Aug 18, 2026 | Unauthenticated PHP Object Injection in Ultimate Maps by Supsystic < 1.5.0 versions. |
- risk 0.64cvss 9.8epss 0.00
Deserialization of untrusted data vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40-03, from 11-30 through…
- risk 0.64cvss 9.8epss 0.00
Deserialization of untrusted data vulnerability in Next4Biz Information Technologies Inc. CSM (Customer Service Management) allows Code Injection. This issue affects CSM (Customer Service Management): before 8.0.3.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated PHP Object Injection in JobSearch <= 3.2.0 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated PHP Object Injection in Mail Mint <= 1.31.0 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated PHP Object Injection in Tickera <= 3.6.0.2 versions.
- risk 0.64cvss 9.8epss 0.00
SOY CMS contains an issue with deserialization of untrusted data. An arbitrary code may be executed by an attacker with the web server privilege.
- risk 0.64cvss 9.8epss 0.01
Unauthenticated PHP Object Injection in Hash Form <= 1.4.1 versions.
- risk 0.64cvss 9.8epss 0.01
Unauthenticated PHP Object Injection in Geo Controller <= 8.9.8 versions.
- risk 0.64cvss 9.8epss 0.01
An issue in Beijing Tongtech Co., Ltd tongweb v.7.0.24 in the Spring HttpInovkerServiceExporter component allows a remote attacker to execute arbitrary code via a crafted request to the console/heimdall endpoint
- risk 0.64cvss 9.8epss 0.00
Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions.
- risk 0.64cvss 9.8epss 0.00
Subscriber PHP Object Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated PHP Object Injection in FreightCo <= 1.1.15 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated PHP Object Injection in Flatastic <= 2.0 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated PHP Object Injection in Forminator <= 1.57.0 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated PHP Object Injection in Kalles Addons <= 1.0.6 versions.
- risk 0.64cvss 9.8epss 0.00
Customer PHP Object Injection in Flexible Subscriptions <= 1.8.1 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated Deserialization of untrusted data in Youzify <= 1.3.7 versions.
- risk 0.64cvss 9.8epss 0.01
Unauthenticated PHP Object Injection in Popup by Supsystic <= 1.13.0 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated PHP Object Injection in Ultimate Maps by Supsystic < 1.5.0 versions.