VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,323)

page 146 of 167
  • CVE-2025-58218HigAug 27, 2025
    risk 0.40cvss 7.2epss 0.00

    Deserialization of Untrusted Data vulnerability in enituretechnology Small Package Quotes – USPS Edition small-package-quotes-usps-edition allows Object Injection.This issue affects Small Package Quotes – USPS Edition: from n/a through <= 1.3.9.

  • CVE-2025-31935MedApr 11, 2025
    risk 0.40cvss 6.2epss 0.00

    Subnet Solutions PowerSYSTEM Center is affected by a mishandling of exceptional conditions vulnerability. Crafted data that is passed to the API may trigger an exception, resulting in a denial-of-service condition.

  • CVE-2025-2251MedApr 7, 2025
    risk 0.40cvss 6.2epss 0.01

    A security flaw exists in WildFly and JBoss Enterprise Application Platform (EAP) within the Enterprise JavaBeans (EJB) remote invocation mechanism. This vulnerability stems from untrusted data deserialization handled by JBoss Marshalling. This flaw allows an attacker to send a…

  • CVE-2024-13889HigMar 26, 2025
    risk 0.40cvss 7.2epss 0.01

    The WordPress Importer plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 0.8.3 via deserialization of untrusted input in the 'maybe_unserialize' function. This makes it possible for authenticated attackers, with Administrator-level…

  • CVE-2025-1971HigMar 22, 2025
    risk 0.40cvss 7.2epss 0.01

    The Export and Import Users and Customers plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.2 via deserialization of untrusted input from the 'form_data' parameter. This makes it possible for authenticated attackers, with…

  • CVE-2024-13921HigMar 20, 2025
    risk 0.40cvss 7.2epss 0.01

    The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.0 via deserialization of untrusted input from the 'form_data' parameter. This makes it possible for authenticated attackers, with…

  • CVE-2024-13906HigMar 7, 2025
    risk 0.40cvss 7.2epss 0.01

    The Gallery by BestWebSoft – Customizable Image and Photo Galleries for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.7.3 via deserialization of untrusted input in the 'import_gallery_from_csv' function. This makes…

  • CVE-2024-13833HigMar 1, 2025
    risk 0.40cvss 7.2epss 0.01

    The Album Gallery – WordPress Gallery plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.6.3 via deserialization of untrusted input from gallery meta. This makes it possible for authenticated attackers, with Editor-level access…

  • CVE-2024-12600HigJan 25, 2025
    risk 0.40cvss 7.2epss 0.01

    The Custom Product Tabs Lite for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.9.0 via deserialization of untrusted input from the 'frs_woo_product_tabs' parameter. This makes it possible for authenticated…

  • CVE-2025-0429HigJan 22, 2025
    risk 0.40cvss 7.2epss 0.01

    The "AI Power: Complete AI Pack" plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.8.96 via deserialization of untrusted input from the $form['post_content'] variable through the wpaicg_export_ai_forms() function. This allows…

  • CVE-2025-0428HigJan 22, 2025
    risk 0.40cvss 7.2epss 0.01

    The "AI Power: Complete AI Pack" plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.8.96 via deserialization of untrusted input from the $form['post_content'] variable through the wpaicg_export_prompts function. This allows…

  • CVE-2024-9314HigOct 5, 2024
    risk 0.40cvss 7.2epss 0.01

    The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.228 via deserialization of untrusted input 'set_redirections' function. This makes it possible for authenticated…

  • CVE-2022-2439HigSep 24, 2024
    risk 0.40cvss 7.2epss 0.01

    The Easy Digital Downloads – Simple eCommerce for Selling Digital Files plugin for WordPress is vulnerable to deserialization of untrusted input via the 'upload[file]' parameter in versions up to, and including 3.3.3. This makes it possible for authenticated administrative…

  • CVE-2022-2446HigSep 13, 2024
    risk 0.40cvss 7.2epss 0.01

    The WP Editor plugin for WordPress is vulnerable to deserialization of untrusted input via the 'current_theme_root' parameter in versions up to, and including 1.2.9. This makes it possible for authenticated attackers with administrative privileges to call files using a PHAR…

  • CVE-2022-2440HigAug 29, 2024
    risk 0.40cvss 7.2epss 0.01

    The Theme Editor plugin for WordPress is vulnerable to deserialization of untrusted input via the 'images_array' parameter in versions up to, and including 2.8. This makes it possible for authenticated attackers with administrative privileges to call files using a PHAR wrapper…

  • CVE-2024-3020HigApr 10, 2024
    risk 0.40cvss 7.2epss 0.01

    The plugin is vulnerable to PHP Object Injection in versions up to and including, 2.6.3 via deserialization of untrusted input in the import function via the 'shortcode' parameter. This allows authenticated attackers, with administrator-level access to inject a PHP Object. If a…

  • CVE-2023-38177MedNov 14, 2023
    risk 0.40cvss 6.1epss 0.03

    Microsoft SharePoint Server Remote Code Execution Vulnerability

  • CVE-2022-2438HigSep 6, 2022
    risk 0.40cvss 7.2epss 0.02

    The Broken Link Checker plugin for WordPress is vulnerable to deserialization of untrusted input via the '$log_file' value in versions up to, and including 1.11.16. This makes it possible for authenticated attackers with administrative privileges and above to call files using a…

  • CVE-2020-7811MedOct 12, 2020
    risk 0.40cvss 6.2epss 0.01

    Samsung Update 3.0.2.0 ~ 3.0.32.0 has a vulnerability that allows privilege escalation as commands crafted by attacker are executed while the engine deserializes the data received during inter-process communication

  • CVE-2019-8141HigNov 6, 2019
    risk 0.40cvss 7.2epss 0.02

    A remote code execution vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3. An authenticated user with administrative privileges (system level import) can execute arbitrary code through a Phar deserialization…