VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,104)

page 146 of 156
  • CVE-2020-11982CriJul 17, 2020
    risk 0.01cvss 9.8epss 0.07

    An issue was found in Apache Airflow versions 1.10.10 and below. When using CeleryExecutor, if an attack can connect to the broker (Redis, RabbitMQ) directly, it was possible to insert a malicious payload directly to the broker which could lead to a deserialization attack (and…

  • CVE-2013-2185Jan 19, 2014
    risk 0.01cvss epss 0.07

    The readObject method in the DiskFileItem class in Apache Tomcat and JBoss Web, as used in Red Hat JBoss Enterprise Application Platform 6.1.0 and Red Hat JBoss Portal 6.0.0, allows remote attackers to write to arbitrary files via a NULL byte in a file name in a serialized…

  • CVE-2013-0277Feb 13, 2013
    risk 0.01cvss epss 0.07

    ActiveRecord in Ruby on Rails before 2.3.17 and 3.x before 3.1.0 allows remote attackers to cause a denial of service or execute arbitrary code via crafted serialized attributes that cause the +serialize+ helper to deserialize arbitrary YAML.

  • CVE-2026-18642HigAug 3, 2026
    risk 0.00cvss 7.8epss 0.00

    Deserialization of untrusted data vulnerability in TUBITAK BILGEM Software Technologies Research Institute eta-otp-lock allows Object Injection. This issue affects eta-otp-lock: before 1.0.4.

  • CVE-2026-16297MedAug 3, 2026
    risk 0.00cvss 4.1epss 0.00

    The Clearfy Cache WordPress plugin before 2.4.3 does not restrict the classes allowed when unserializing settings-import data, allowing users with administrator access to perform PHP Object Injection attacks, which may lead to remote code execution when a suitable gadget chain…

  • CVE-2025-15672HigAug 3, 2026
    risk 0.00cvss 8.1epss 0.00

    The ChamaWP WordPress plugin before 1.0.13 does not properly validate user input before passing it to a PHP deserialization function, allowing unauthenticated attackers to inject arbitrary PHP objects, which could lead to remote code execution when a suitable gadget chain is…

  • CVE-2026-3245HigAug 3, 2026
    risk 0.00cvss 7.5epss 0.00

    A deserialization vulnerability in PRISMAproduction Version 6.5 or earlier that may lead to arbitrary code execution.

  • CVE-2026-16062MedAug 2, 2026
    risk 0.00cvss 6.6epss 0.00

    The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not prevent the deserialization of user-controlled input in some of its event content fields, allowing users with Contributor-level access and above to inject PHP objects. No POP chain is present in…

  • CVE-2026-12720HigJul 31, 2026
    risk 0.00cvss 7.5epss 0.00

    The Kirki WordPress plugin before 6.0.13 does not restrict which classes may be instantiated when it deserialises data that unauthenticated users can store, leading to PHP Object Injection that is triggered when an administrator later reviews the stored data. With a suitable…

  • CVE-2026-15976CriJul 30, 2026
    risk 0.00cvss 9.8epss 0.00

    SGLang contains a RCE vulnerability when attempting to load model weights from a HuggingFace repository, specifically within the /update_weights_from_disk, where torch.load(..., weights_only=False) fallback enables pickle deserialization of .bin files.

  • CVE-2026-15969CriJul 30, 2026
    risk 0.00cvss 9.8epss 0.01

    SGLang contains an unauthenticated RCE in /load_lora_adapter_from_tensors via bypass of SafeUnpickler’s incomplete denylist, allowing arbitrary command execution through crafted base64-encoded pickle payloads.

  • CVE-2026-1360HigJul 30, 2026
    risk 0.00cvss 7.5epss 0.01

    The BuddyPress plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and including, 14.5.0 This is due to the `bp_unserialize_profile_field()` function using `@unserialize()` without the `allowed_classes` parameter on user-controlled…

  • CVE-2026-11756CriJul 28, 2026
    risk 0.00cvss 10.0epss 0.00

    A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could lead to an unauthenticated remote code execution.

  • CVE-2026-65617HigJul 27, 2026
    risk 0.00cvss 8.8epss 0.00

    A deserialization weakness in JFrog Artifactory package handling could allow a low-privileged user to impact confidentiality, integrity, and availability under specific repository conditions.

  • CVE-2026-15962HigJul 26, 2026
    risk 0.00cvss 8.8epss 0.00

    The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.2.6 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a…

  • CVE-2026-50517CriJul 24, 2026
    risk 0.00cvss 9.9epss 0.01

    Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.

  • CVE-2026-65497HigJul 23, 2026
    risk 0.00cvss 7.2epss 0.00

    Administrator PHP Object Injection in Complianz <= 7.5.0 versions.

  • CVE-2026-65493HigJul 23, 2026
    risk 0.00cvss 7.5epss 0.00

    Subscriber PHP Object Injection in Dokan Pro <= 5.0.2 versions.

  • CVE-2026-59544CriJul 23, 2026
    risk 0.00cvss 9.8epss 0.00

    Unauthenticated PHP Object Injection in Thrive Quiz Builder <= 10.9.3.0 versions.

  • CVE-2026-16723CriJul 23, 2026
    risk 0.00cvss 9.0epss 0.00

    A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement required, no classpath gadget required.