VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,323)

page 59 of 167
  • CVE-2026-84647HigSep 2, 2026
    risk 0.57cvss 8.8epss 0.01

    In Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Stapler does not restrict the types of objects that can be instantiated via form data binding to those compatible with the expected field…

  • CVE-2026-81772HigSep 2, 2026
    risk 0.57cvss 8.8epss 0.00

    Unauthenticated PHP Object Injection in Ninja Forms - Layout & Styles <= 3.0.31 versions.

  • CVE-2026-81283HigSep 2, 2026
    risk 0.57cvss 8.8epss 0.01

    Subscriber PHP Object Injection in WP User Frontend <= 4.3.10 versions.

  • CVE-2026-19116HigSep 2, 2026
    risk 0.57cvss 8.8epss 0.00

    The User Frontend WordPress plugin before 4.3.11 does not prevent user-supplied field values from being deserialized when a submitted post is reopened in its frontend editing form, allowing authenticated users with subscriber-level access and above to perform PHP Object…

  • CVE-2026-84202HigSep 1, 2026
    risk 0.57cvss 8.8epss 0.01

    ModelScope uses PyYAML's unsafe yaml.Loader to parse model configuration files, allowing arbitrary code execution through Python object construction tags. Attackers can craft malicious model repositories with poisoned configuration files that execute code when loaded by users.

  • CVE-2026-83497HigAug 31, 2026
    risk 0.57cvss 8.8epss 0.01

    Unrestricted deserialization of untrusted data in the cursor pagination component in the OpenSearch SQL plugin allows a remote authenticated user with basic read/search permissions to execute arbitrary code on the server by sending a crafted cursor parameter to the plugins/sql…

  • CVE-2026-78257HigAug 27, 2026
    risk 0.57cvss 8.8epss 0.01

    Contributor PHP Object Injection in Booking and Rental Manager <= 2.7.5 versions.

  • CVE-2026-79657CriAug 25, 2026
    risk 0.57cvss 9.8epss 0.01

    NLTK versions before 3.10.3 contain a remote code execution vulnerability in allowlisted pickle loaders that trust entire module namespaces instead of specific safe callables. Attackers can craft malicious pickle payloads invoking dangerous in-namespace functions like…

  • CVE-2026-78265CriAug 24, 2026
    risk 0.57cvss 9.8epss 0.01

    Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions.

  • CVE-2026-4703CriAug 22, 2026
    risk 0.57cvss 9.8epss 0.01

    The WS Form LITE – Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.10.80 via deserialization of untrusted input from form submission meta values. This makes it possible for unauthenticated…

  • CVE-2026-76850CriAug 19, 2026
    risk 0.57cvss 9.8epss 0.01

    LMDeploy deserializes disaggregated-serving peer messages with pickle. The handle_zmq_recv coroutine in lmdeploy/pytorch/disagg/conn/engine_conn.py reads peer-to-peer cache-free requests with recv_pyobj(), which deserializes the received bytes with pickle.loads(), and the…

  • CVE-2026-76395HigAug 19, 2026
    risk 0.57cvss 8.8epss 0.01

    In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could execute arbitrary code on the Splunk server by loading a model file containing crafted sparse matrix data. The deserialization of untrusted data is possible because a model codec in Splunk…

  • CVE-2026-74012HigAug 18, 2026
    risk 0.57cvss 8.8epss 0.01

    Deserialization of Untrusted Data vulnerability in TaxoPress allows Object Injection. This issue affects TaxoPress: from n/a through 3.51.0.

  • CVE-2026-32465HigAug 18, 2026
    risk 0.57cvss 8.8epss 0.01

    Customer PHP Object Injection in Essential Real Estate <= 5.3.3 versions.

  • CVE-2026-28176HigAug 13, 2026
    risk 0.57cvss 8.8epss 0.00

    Unauthenticated PHP Object Injection in Booking Activities <= 1.18.4 versions.

  • CVE-2026-70321HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.02

    Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

  • CVE-2026-66808HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.02

    Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

  • CVE-2026-66805HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.02

    Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

  • CVE-2026-65815HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.02

    Deserialization of untrusted data in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.

  • CVE-2026-65665HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.02

    Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.