CWE-502
Deserialization of Untrusted Data
Description
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-586
CVEs mapped to this weakness (3,104)
page 14 of 156| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-61484 | Cri | 0.64 | 9.8 | 0.01 | Aug 5, 2026 | ** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or… | ||
| CVE-2026-70554 | Cri | 0.64 | 9.8 | 0.01 | Aug 4, 2026 | MaxSite CMS contains a PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by passing attacker-controlled serialized data in the maxsite_comuser cookie directly to unserialize() without validation or class allowlisting. Attackers… | ||
| CVE-2026-69098 | Cri | 0.64 | 9.8 | 0.01 | Aug 4, 2026 | kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows unauthenticated attackers to instantiate arbitrary Python classes by supplying crafted YAML/JSON input with a __type__ field. Attackers can exploit this to… | ||
| CVE-2026-12118 | Cri | 0.64 | 9.8 | 0.01 | Jul 30, 2026 | IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to execute arbitrary code on the system due to the deserialization of untrusted data. | ||
| CVE-2026-65883 | Cri | 0.64 | 9.8 | 0.01 | Jul 29, 2026 | Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 - A forged clfgd field allows PHP objection injection and thereby remote code execution. | ||
| CVE-2026-14512 | Cri | 0.64 | 9.8 | 0.01 | Jul 28, 2026 | IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe deserialization which could allow a remote attacker to bypass authentication or execute arbitrary code. | ||
| CVE-2026-66713 | Cri | 0.64 | 9.8 | 0.02 | Jul 28, 2026 | Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering component in Apache Software Foundation Apache Axis2/Java through 2.0.0 on Apache Tomcat (only when Tribes clustering is enabled, which is off by default) allows an unauthenticated remote… | ||
| CVE-2026-64608 | Cri | 0.64 | 9.8 | 0.00 | Jul 21, 2026 | Heap type confusion and out-of-bounds read/write in the Apache Fory C++ implementation. When deserializing data in compatible mode, the field-skip paths do not correctly validate the declared field types against the actual data, so input with an inconsistent schema can cause… | ||
| CVE-2026-8024 | Cri | 0.64 | 9.8 | 0.01 | Jun 18, 2026 | A remote, unauthenticated attacker may exploit a deserialization of untrusted data vulnerability in ibaPDA or ibaDatCoordinator to gain full access to the affected systems. | ||
| CVE-2026-54806 | Cri | 0.64 | 9.8 | 0.01 | Jun 17, 2026 | Unauthenticated PHP Object Injection in WP Activity Log <= 5.6.3.1 versions. | ||
| CVE-2026-54194 | Cri | 0.64 | 9.8 | 0.00 | Jun 17, 2026 | Contributor PHP Object Injection in Fusion Builder <= 3.15.4 versions. | ||
| CVE-2026-52706 | Cri | 0.64 | 9.8 | 0.00 | Jun 17, 2026 | Unauthenticated PHP Object Injection in JetEngine <= 3.8.10 versions. | ||
| CVE-2026-49107 | Cri | 0.64 | 9.8 | 0.00 | Jun 17, 2026 | Unauthenticated PHP Object Injection in Thrive Apprentice < 10.8.10.2 versions. | ||
| CVE-2026-49075 | Cri | 0.64 | 9.8 | 0.00 | Jun 17, 2026 | Contributor PHP Object Injection in JetEngine <= 3.8.9.1 versions. | ||
| CVE-2026-42380 | Cri | 0.64 | 9.8 | 0.01 | Jun 17, 2026 | Unauthenticated PHP Object Injection in AI Lab < 5.4.2 versions. | ||
| CVE-2026-40725 | Cri | 0.64 | 9.8 | 0.00 | Jun 17, 2026 | Unauthenticated PHP Object Injection in WooCommerce Product Filters < 2.0.6 versions. | ||
| CVE-2026-39529 | Cri | 0.64 | 9.8 | 0.00 | Jun 17, 2026 | Unauthenticated PHP Object Injection in Elementra <= 1.0.9 versions. | ||
| CVE-2026-27429 | Cri | 0.64 | 9.8 | 0.01 | Jun 17, 2026 | Unauthenticated PHP Object Injection in Nifty <= 1.4.1 versions. | ||
| CVE-2025-69122 | Cri | 0.64 | 9.8 | 0.01 | Jun 17, 2026 | Unauthenticated PHP Object Injection in SeaFood Company <= 1.4 versions. | ||
| CVE-2025-69108 | Cri | 0.64 | 9.8 | 0.01 | Jun 17, 2026 | Unauthenticated PHP Object Injection in Hot Coffee <= 1.7 versions. |
- risk 0.64cvss 9.8epss 0.01
** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or…
- risk 0.64cvss 9.8epss 0.01
MaxSite CMS contains a PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by passing attacker-controlled serialized data in the maxsite_comuser cookie directly to unserialize() without validation or class allowlisting. Attackers…
- risk 0.64cvss 9.8epss 0.01
kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows unauthenticated attackers to instantiate arbitrary Python classes by supplying crafted YAML/JSON input with a __type__ field. Attackers can exploit this to…
- risk 0.64cvss 9.8epss 0.01
IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to execute arbitrary code on the system due to the deserialization of untrusted data.
- risk 0.64cvss 9.8epss 0.01
Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 - A forged clfgd field allows PHP objection injection and thereby remote code execution.
- risk 0.64cvss 9.8epss 0.01
IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe deserialization which could allow a remote attacker to bypass authentication or execute arbitrary code.
- risk 0.64cvss 9.8epss 0.02
Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering component in Apache Software Foundation Apache Axis2/Java through 2.0.0 on Apache Tomcat (only when Tribes clustering is enabled, which is off by default) allows an unauthenticated remote…
- risk 0.64cvss 9.8epss 0.00
Heap type confusion and out-of-bounds read/write in the Apache Fory C++ implementation. When deserializing data in compatible mode, the field-skip paths do not correctly validate the declared field types against the actual data, so input with an inconsistent schema can cause…
- risk 0.64cvss 9.8epss 0.01
A remote, unauthenticated attacker may exploit a deserialization of untrusted data vulnerability in ibaPDA or ibaDatCoordinator to gain full access to the affected systems.
- risk 0.64cvss 9.8epss 0.01
Unauthenticated PHP Object Injection in WP Activity Log <= 5.6.3.1 versions.
- risk 0.64cvss 9.8epss 0.00
Contributor PHP Object Injection in Fusion Builder <= 3.15.4 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated PHP Object Injection in JetEngine <= 3.8.10 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated PHP Object Injection in Thrive Apprentice < 10.8.10.2 versions.
- risk 0.64cvss 9.8epss 0.00
Contributor PHP Object Injection in JetEngine <= 3.8.9.1 versions.
- risk 0.64cvss 9.8epss 0.01
Unauthenticated PHP Object Injection in AI Lab < 5.4.2 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated PHP Object Injection in WooCommerce Product Filters < 2.0.6 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated PHP Object Injection in Elementra <= 1.0.9 versions.
- risk 0.64cvss 9.8epss 0.01
Unauthenticated PHP Object Injection in Nifty <= 1.4.1 versions.
- risk 0.64cvss 9.8epss 0.01
Unauthenticated PHP Object Injection in SeaFood Company <= 1.4 versions.
- risk 0.64cvss 9.8epss 0.01
Unauthenticated PHP Object Injection in Hot Coffee <= 1.7 versions.