VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,104)

page 151 of 156
  • CVE-2026-39576HigJun 17, 2026
    risk 0.00cvss 8.1epss 0.00

    Unauthenticated PHP Object Injection in SingleMalt <= 1.5 versions.

  • CVE-2026-39560HigJun 17, 2026
    risk 0.00cvss 8.1epss 0.00

    Unauthenticated PHP Object Injection in Hiroshi <= 1.5.1 versions.

  • CVE-2026-39556HigJun 17, 2026
    risk 0.00cvss 8.1epss 0.00

    Unauthenticated PHP Object Injection in Konsept <= 1.9 versions.

  • CVE-2026-39445HigJun 17, 2026
    risk 0.00cvss 8.1epss 0.00

    Unauthenticated PHP Object Injection in Alukas < 3.0.0 versions.

  • CVE-2026-39442HigJun 17, 2026
    risk 0.00cvss 8.1epss 0.00

    Unauthenticated PHP Object Injection in PressMart <= 1.2.26 versions.

  • CVE-2025-69130HigJun 17, 2026
    risk 0.00cvss 8.8epss 0.00

    Subscriber PHP Object Injection in Entrepreneur - Booking for Small Businesses WordPress Theme <= 3.1.3 versions.

  • CVE-2025-69127CriJun 17, 2026
    risk 0.00cvss 9.8epss 0.00

    Unauthenticated PHP Object Injection in Plumbing <= 1.6 versions.

  • CVE-2025-69111CriJun 17, 2026
    risk 0.00cvss 9.8epss 0.00

    Unauthenticated PHP Object Injection in Reisen <= 1.4.1 versions.

  • CVE-2025-60236CriJun 17, 2026
    risk 0.00cvss 9.8epss 0.00

    Deserialization of Untrusted Data vulnerability in EMV Creatify allows Object Injection. This issue affects Creatify: from n/a through 1.5.

  • CVE-2025-60231CriJun 17, 2026
    risk 0.00cvss 9.8epss 0.00

    Deserialization of Untrusted Data vulnerability in EMV The Hospital nrghospital allows Object Injection. This issue affects The Hospital: from n/a through 1.8.1.

  • CVE-2025-60230CriJun 17, 2026
    risk 0.00cvss 9.8epss 0.00

    Deserialization of Untrusted Data vulnerability in Themeton The Barber Shop allows Object Injection. This issue affects The Barber Shop: from n/a through 1.9.

  • CVE-2025-60229CriJun 17, 2026
    risk 0.00cvss 9.8epss 0.00

    Deserialization of Untrusted Data vulnerability in Themeton Lagom allows Object Injection. This issue affects Lagom: from n/a through 2.0.

  • CVE-2025-52998CriMar 2, 2026
    risk 0.00cvss 9.8epss 0.00

    Chamilo is a learning management system. Prior to version 1.11.30, in the application, deserialization of data is performed, the data can be spoofed. An attacker can create objects of arbitrary classes, as well as fully control their properties, and thus modify the logic of the…

  • CVE-2025-50198MedMar 2, 2026
    risk 0.00cvss 4.9epss 0.00

    Chamilo is a learning management system. Prior to version 1.11.30, Chamilo is vulnerable to deserialization of untrusted data in /plugin/vchamilo/views/import.php via POST configuration_file; POST course_path; POST home_path parameters. This issue has been patched in version…

  • CVE-2026-24892HigFeb 20, 2026
    risk 0.00cvss 7.5epss 0.01

    openITCOCKPIT is an open source monitoring tool built for different monitoring engines like Nagios, Naemon and Prometheus. openITCOCKPIT Community Edition 5.3.1 and earlier contains an unsafe PHP deserialization pattern in the processing of changelog entries. Serialized…

  • CVE-2025-13711HigDec 23, 2025
    risk 0.00cvss 7.8epss 0.00

    Tencent TFace eval Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Tencent TFace. User interaction is required to exploit this vulnerability in that the…

  • CVE-2025-13709HigDec 23, 2025
    risk 0.00cvss 7.8epss 0.00

    Tencent TFace restore_checkpoint Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Tencent TFace. User interaction is required to exploit this vulnerability in…

  • CVE-2025-34449CriDec 18, 2025
    risk 0.00cvss 9.1epss 0.00

    Genymobile/scrcpy versions up to and including 3.3.3, prior to commit 3e40b24, contain a buffer overflow vulnerability in the sc_device_msg_deserialize() function. A compromised device can send crafted messages that cause out-of-bounds reads, which may result in memory…

  • CVE-2025-64164CriNov 6, 2025
    risk 0.00cvss 9.8epss 0.01

    Dataease is an open source data visualization analysis tool. In versions 2.10.14 and below, DataEase did not properly filter when establishing JDBC connections to Oracle, resulting in a risk of JNDI injection (Java Naming and Directory Interface injection). This issue is fixed…

  • CVE-2025-62420HigOct 17, 2025
    risk 0.00cvss 8.8epss 0.01

    DataEase is a data visualization and analytics platform. In DataEase versions through 2.10.13, a JDBC driver bypass vulnerability exists in the H2 database connection handler. The getJdbc function in H2.java checks if the jdbcUrl starts with jdbc:h2 but returns a separate jdbc…