CWE-502
Deserialization of Untrusted Data
Description
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-586
CVEs mapped to this weakness (3,104)
page 146 of 156| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-11982 | Cri | 0.01 | 9.8 | 0.07 | Jul 17, 2020 | An issue was found in Apache Airflow versions 1.10.10 and below. When using CeleryExecutor, if an attack can connect to the broker (Redis, RabbitMQ) directly, it was possible to insert a malicious payload directly to the broker which could lead to a deserialization attack (and… | ||
| CVE-2013-2185 | 0.01 | — | 0.07 | Jan 19, 2014 | The readObject method in the DiskFileItem class in Apache Tomcat and JBoss Web, as used in Red Hat JBoss Enterprise Application Platform 6.1.0 and Red Hat JBoss Portal 6.0.0, allows remote attackers to write to arbitrary files via a NULL byte in a file name in a serialized… | |||
| CVE-2013-0277 | 0.01 | — | 0.07 | Feb 13, 2013 | ActiveRecord in Ruby on Rails before 2.3.17 and 3.x before 3.1.0 allows remote attackers to cause a denial of service or execute arbitrary code via crafted serialized attributes that cause the +serialize+ helper to deserialize arbitrary YAML. | |||
| CVE-2026-18642 | Hig | 0.00 | 7.8 | 0.00 | Aug 3, 2026 | Deserialization of untrusted data vulnerability in TUBITAK BILGEM Software Technologies Research Institute eta-otp-lock allows Object Injection. This issue affects eta-otp-lock: before 1.0.4. | ||
| CVE-2026-16297 | Med | 0.00 | 4.1 | 0.00 | Aug 3, 2026 | The Clearfy Cache WordPress plugin before 2.4.3 does not restrict the classes allowed when unserializing settings-import data, allowing users with administrator access to perform PHP Object Injection attacks, which may lead to remote code execution when a suitable gadget chain… | ||
| CVE-2025-15672 | Hig | 0.00 | 8.1 | 0.00 | Aug 3, 2026 | The ChamaWP WordPress plugin before 1.0.13 does not properly validate user input before passing it to a PHP deserialization function, allowing unauthenticated attackers to inject arbitrary PHP objects, which could lead to remote code execution when a suitable gadget chain is… | ||
| CVE-2026-3245 | Hig | 0.00 | 7.5 | 0.00 | Aug 3, 2026 | A deserialization vulnerability in PRISMAproduction Version 6.5 or earlier that may lead to arbitrary code execution. | ||
| CVE-2026-16062 | Med | 0.00 | 6.6 | 0.00 | Aug 2, 2026 | The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not prevent the deserialization of user-controlled input in some of its event content fields, allowing users with Contributor-level access and above to inject PHP objects. No POP chain is present in… | ||
| CVE-2026-12720 | Hig | 0.00 | 7.5 | 0.00 | Jul 31, 2026 | The Kirki WordPress plugin before 6.0.13 does not restrict which classes may be instantiated when it deserialises data that unauthenticated users can store, leading to PHP Object Injection that is triggered when an administrator later reviews the stored data. With a suitable… | ||
| CVE-2026-15976 | Cri | 0.00 | 9.8 | 0.00 | Jul 30, 2026 | SGLang contains a RCE vulnerability when attempting to load model weights from a HuggingFace repository, specifically within the /update_weights_from_disk, where torch.load(..., weights_only=False) fallback enables pickle deserialization of .bin files. | ||
| CVE-2026-15969 | Cri | 0.00 | 9.8 | 0.01 | Jul 30, 2026 | SGLang contains an unauthenticated RCE in /load_lora_adapter_from_tensors via bypass of SafeUnpickler’s incomplete denylist, allowing arbitrary command execution through crafted base64-encoded pickle payloads. | ||
| CVE-2026-1360 | Hig | 0.00 | 7.5 | 0.01 | Jul 30, 2026 | The BuddyPress plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and including, 14.5.0 This is due to the `bp_unserialize_profile_field()` function using `@unserialize()` without the `allowed_classes` parameter on user-controlled… | ||
| CVE-2026-11756 | Cri | 0.00 | 10.0 | 0.00 | Jul 28, 2026 | A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could lead to an unauthenticated remote code execution. | ||
| CVE-2026-65617 | Hig | 0.00 | 8.8 | 0.00 | Jul 27, 2026 | A deserialization weakness in JFrog Artifactory package handling could allow a low-privileged user to impact confidentiality, integrity, and availability under specific repository conditions. | ||
| CVE-2026-15962 | Hig | 0.00 | 8.8 | 0.00 | Jul 26, 2026 | The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.2.6 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a… | ||
| CVE-2026-50517 | Cri | 0.00 | 9.9 | 0.01 | Jul 24, 2026 | Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network. | ||
| CVE-2026-65497 | Hig | 0.00 | 7.2 | 0.00 | Jul 23, 2026 | Administrator PHP Object Injection in Complianz <= 7.5.0 versions. | ||
| CVE-2026-65493 | Hig | 0.00 | 7.5 | 0.00 | Jul 23, 2026 | Subscriber PHP Object Injection in Dokan Pro <= 5.0.2 versions. | ||
| CVE-2026-59544 | Cri | 0.00 | 9.8 | 0.00 | Jul 23, 2026 | Unauthenticated PHP Object Injection in Thrive Quiz Builder <= 10.9.3.0 versions. | ||
| CVE-2026-16723 | Cri | 0.00 | 9.0 | 0.00 | Jul 23, 2026 | A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement required, no classpath gadget required. |
- risk 0.01cvss 9.8epss 0.07
An issue was found in Apache Airflow versions 1.10.10 and below. When using CeleryExecutor, if an attack can connect to the broker (Redis, RabbitMQ) directly, it was possible to insert a malicious payload directly to the broker which could lead to a deserialization attack (and…
- CVE-2013-2185Jan 19, 2014risk 0.01cvss —epss 0.07
The readObject method in the DiskFileItem class in Apache Tomcat and JBoss Web, as used in Red Hat JBoss Enterprise Application Platform 6.1.0 and Red Hat JBoss Portal 6.0.0, allows remote attackers to write to arbitrary files via a NULL byte in a file name in a serialized…
- CVE-2013-0277Feb 13, 2013risk 0.01cvss —epss 0.07
ActiveRecord in Ruby on Rails before 2.3.17 and 3.x before 3.1.0 allows remote attackers to cause a denial of service or execute arbitrary code via crafted serialized attributes that cause the +serialize+ helper to deserialize arbitrary YAML.
- risk 0.00cvss 7.8epss 0.00
Deserialization of untrusted data vulnerability in TUBITAK BILGEM Software Technologies Research Institute eta-otp-lock allows Object Injection. This issue affects eta-otp-lock: before 1.0.4.
- risk 0.00cvss 4.1epss 0.00
The Clearfy Cache WordPress plugin before 2.4.3 does not restrict the classes allowed when unserializing settings-import data, allowing users with administrator access to perform PHP Object Injection attacks, which may lead to remote code execution when a suitable gadget chain…
- risk 0.00cvss 8.1epss 0.00
The ChamaWP WordPress plugin before 1.0.13 does not properly validate user input before passing it to a PHP deserialization function, allowing unauthenticated attackers to inject arbitrary PHP objects, which could lead to remote code execution when a suitable gadget chain is…
- risk 0.00cvss 7.5epss 0.00
A deserialization vulnerability in PRISMAproduction Version 6.5 or earlier that may lead to arbitrary code execution.
- risk 0.00cvss 6.6epss 0.00
The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not prevent the deserialization of user-controlled input in some of its event content fields, allowing users with Contributor-level access and above to inject PHP objects. No POP chain is present in…
- risk 0.00cvss 7.5epss 0.00
The Kirki WordPress plugin before 6.0.13 does not restrict which classes may be instantiated when it deserialises data that unauthenticated users can store, leading to PHP Object Injection that is triggered when an administrator later reviews the stored data. With a suitable…
- risk 0.00cvss 9.8epss 0.00
SGLang contains a RCE vulnerability when attempting to load model weights from a HuggingFace repository, specifically within the /update_weights_from_disk, where torch.load(..., weights_only=False) fallback enables pickle deserialization of .bin files.
- risk 0.00cvss 9.8epss 0.01
SGLang contains an unauthenticated RCE in /load_lora_adapter_from_tensors via bypass of SafeUnpickler’s incomplete denylist, allowing arbitrary command execution through crafted base64-encoded pickle payloads.
- risk 0.00cvss 7.5epss 0.01
The BuddyPress plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and including, 14.5.0 This is due to the `bp_unserialize_profile_field()` function using `@unserialize()` without the `allowed_classes` parameter on user-controlled…
- risk 0.00cvss 10.0epss 0.00
A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could lead to an unauthenticated remote code execution.
- risk 0.00cvss 8.8epss 0.00
A deserialization weakness in JFrog Artifactory package handling could allow a low-privileged user to impact confidentiality, integrity, and availability under specific repository conditions.
- risk 0.00cvss 8.8epss 0.00
The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.2.6 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a…
- risk 0.00cvss 9.9epss 0.01
Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.
- risk 0.00cvss 7.2epss 0.00
Administrator PHP Object Injection in Complianz <= 7.5.0 versions.
- risk 0.00cvss 7.5epss 0.00
Subscriber PHP Object Injection in Dokan Pro <= 5.0.2 versions.
- risk 0.00cvss 9.8epss 0.00
Unauthenticated PHP Object Injection in Thrive Quiz Builder <= 10.9.3.0 versions.
- risk 0.00cvss 9.0epss 0.00
A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement required, no classpath gadget required.