VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,308)

page 15 of 166
  • CVE-2026-73366CriAug 18, 2026
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated PHP Object Injection in Easy Google Maps <= 1.13.0 versions.

  • CVE-2026-73341CriAug 18, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated PHP Object Injection in RegistrationMagic <= 6.0.9.7 versions.

  • CVE-2026-59940CriAug 18, 2026
    risk 0.64cvss 9.8epss 0.01

    Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. Prior to 1.5.3, seroval.fromJSON() allows attacker-controlled JSON Promise control nodes to operate on values from the general deserialization reference table without…

  • CVE-2026-32470CriAug 18, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.

  • CVE-2024-13784CriAug 16, 2026
    risk 0.64cvss 9.8epss 0.01

    The Contact Form, Survey, Quiz & Popup Form Builder – ARForms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.8.5 via deserialization of untrusted input from form submissions. This makes it possible for unauthenticated…

  • CVE-2026-28149CriAug 13, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated PHP Object Injection in Headless Single Sign On <= 1.6 versions.

  • CVE-2026-59124CriAug 11, 2026
    risk 0.64cvss 9.8epss 0.02

    Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to execute code over a network.

  • CVE-2026-18948CriAug 10, 2026
    risk 0.64cvss 9.9epss 0.01

    A flaw was found in Feast. The system improperly deserializes user-defined functions (UDFs) stored in its registry, which are serialized using the 'dill' library. This allows a remote attacker to store a malicious UDF, leading to unauthenticated arbitrary code execution on the…

  • CVE-2026-16258CriAug 7, 2026
    risk 0.64cvss 9.8epss 0.00

    The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deserialization of untrusted input, allowing unauthenticated attackers to perform PHP Object Injection. When a suitable POP chain is present via another installed Ajax Search Lite WordPress plugin before…

  • CVE-2026-50515CriAug 7, 2026
    risk 0.64cvss 9.9epss 0.01

    Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network.

  • CVE-2026-65581CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated PHP Object Injection in AI ANN <= 1.29.0 versions.

  • CVE-2026-65579CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated PHP Object Injection in Agricola <= 1.21.0 versions.

  • CVE-2026-65578CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated PHP Object Injection in Agora <= 1.9 versions.

  • CVE-2026-65577CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated PHP Object Injection in Advice <= 1.18.0 versions.

  • CVE-2026-65576CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated PHP Object Injection in Adrena <= 1.2.14 versions.

  • CVE-2026-65575CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated PHP Object Injection in Accalia <= 1.5.3 versions.

  • CVE-2026-65574CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated PHP Object Injection in Abogado <= 1.18 versions.

  • CVE-2026-65573CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated PHP Object Injection in Abelle <= 1.22 versions.

  • CVE-2026-65572CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated PHP Object Injection in A.Williams <= 1.3.1 versions.

  • CVE-2026-65571CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated PHP Object Injection in 69 Clothing <= 1.2.11.1 versions.