CWE-502
Deserialization of Untrusted Data
Description
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-586
CVEs mapped to this weakness (3,323)
page 59 of 167| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-84647 | Hig | 0.57 | 8.8 | 0.01 | Sep 2, 2026 | In Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Stapler does not restrict the types of objects that can be instantiated via form data binding to those compatible with the expected field… | ||
| CVE-2026-81772 | Hig | 0.57 | 8.8 | 0.00 | Sep 2, 2026 | Unauthenticated PHP Object Injection in Ninja Forms - Layout & Styles <= 3.0.31 versions. | ||
| CVE-2026-81283 | Hig | 0.57 | 8.8 | 0.01 | Sep 2, 2026 | Subscriber PHP Object Injection in WP User Frontend <= 4.3.10 versions. | ||
| CVE-2026-19116 | Hig | 0.57 | 8.8 | 0.00 | Sep 2, 2026 | The User Frontend WordPress plugin before 4.3.11 does not prevent user-supplied field values from being deserialized when a submitted post is reopened in its frontend editing form, allowing authenticated users with subscriber-level access and above to perform PHP Object… | ||
| CVE-2026-84202 | Hig | 0.57 | 8.8 | 0.01 | Sep 1, 2026 | ModelScope uses PyYAML's unsafe yaml.Loader to parse model configuration files, allowing arbitrary code execution through Python object construction tags. Attackers can craft malicious model repositories with poisoned configuration files that execute code when loaded by users. | ||
| CVE-2026-83497 | Hig | 0.57 | 8.8 | 0.01 | Aug 31, 2026 | Unrestricted deserialization of untrusted data in the cursor pagination component in the OpenSearch SQL plugin allows a remote authenticated user with basic read/search permissions to execute arbitrary code on the server by sending a crafted cursor parameter to the plugins/sql… | ||
| CVE-2026-78257 | Hig | 0.57 | 8.8 | 0.01 | Aug 27, 2026 | Contributor PHP Object Injection in Booking and Rental Manager <= 2.7.5 versions. | ||
| CVE-2026-79657 | Cri | 0.57 | 9.8 | 0.01 | Aug 25, 2026 | NLTK versions before 3.10.3 contain a remote code execution vulnerability in allowlisted pickle loaders that trust entire module namespaces instead of specific safe callables. Attackers can craft malicious pickle payloads invoking dangerous in-namespace functions like… | ||
| CVE-2026-78265 | Cri | 0.57 | 9.8 | 0.01 | Aug 24, 2026 | Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions. | ||
| CVE-2026-4703 | Cri | 0.57 | 9.8 | 0.01 | Aug 22, 2026 | The WS Form LITE – Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.10.80 via deserialization of untrusted input from form submission meta values. This makes it possible for unauthenticated… | ||
| CVE-2026-76850 | Cri | 0.57 | 9.8 | 0.01 | Aug 19, 2026 | LMDeploy deserializes disaggregated-serving peer messages with pickle. The handle_zmq_recv coroutine in lmdeploy/pytorch/disagg/conn/engine_conn.py reads peer-to-peer cache-free requests with recv_pyobj(), which deserializes the received bytes with pickle.loads(), and the… | ||
| CVE-2026-76395 | Hig | 0.57 | 8.8 | 0.01 | Aug 19, 2026 | In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could execute arbitrary code on the Splunk server by loading a model file containing crafted sparse matrix data. The deserialization of untrusted data is possible because a model codec in Splunk… | ||
| CVE-2026-74012 | Hig | 0.57 | 8.8 | 0.01 | Aug 18, 2026 | Deserialization of Untrusted Data vulnerability in TaxoPress allows Object Injection. This issue affects TaxoPress: from n/a through 3.51.0. | ||
| CVE-2026-32465 | Hig | 0.57 | 8.8 | 0.01 | Aug 18, 2026 | Customer PHP Object Injection in Essential Real Estate <= 5.3.3 versions. | ||
| CVE-2026-28176 | Hig | 0.57 | 8.8 | 0.00 | Aug 13, 2026 | Unauthenticated PHP Object Injection in Booking Activities <= 1.18.4 versions. | ||
| CVE-2026-70321 | Hig | 0.57 | 8.8 | 0.02 | Aug 11, 2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | ||
| CVE-2026-66808 | Hig | 0.57 | 8.8 | 0.02 | Aug 11, 2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | ||
| CVE-2026-66805 | Hig | 0.57 | 8.8 | 0.02 | Aug 11, 2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | ||
| CVE-2026-65815 | Hig | 0.57 | 8.8 | 0.02 | Aug 11, 2026 | Deserialization of untrusted data in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network. | ||
| CVE-2026-65665 | Hig | 0.57 | 8.8 | 0.02 | Aug 11, 2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. |
- risk 0.57cvss 8.8epss 0.01
In Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Stapler does not restrict the types of objects that can be instantiated via form data binding to those compatible with the expected field…
- risk 0.57cvss 8.8epss 0.00
Unauthenticated PHP Object Injection in Ninja Forms - Layout & Styles <= 3.0.31 versions.
- risk 0.57cvss 8.8epss 0.01
Subscriber PHP Object Injection in WP User Frontend <= 4.3.10 versions.
- risk 0.57cvss 8.8epss 0.00
The User Frontend WordPress plugin before 4.3.11 does not prevent user-supplied field values from being deserialized when a submitted post is reopened in its frontend editing form, allowing authenticated users with subscriber-level access and above to perform PHP Object…
- risk 0.57cvss 8.8epss 0.01
ModelScope uses PyYAML's unsafe yaml.Loader to parse model configuration files, allowing arbitrary code execution through Python object construction tags. Attackers can craft malicious model repositories with poisoned configuration files that execute code when loaded by users.
- risk 0.57cvss 8.8epss 0.01
Unrestricted deserialization of untrusted data in the cursor pagination component in the OpenSearch SQL plugin allows a remote authenticated user with basic read/search permissions to execute arbitrary code on the server by sending a crafted cursor parameter to the plugins/sql…
- risk 0.57cvss 8.8epss 0.01
Contributor PHP Object Injection in Booking and Rental Manager <= 2.7.5 versions.
- risk 0.57cvss 9.8epss 0.01
NLTK versions before 3.10.3 contain a remote code execution vulnerability in allowlisted pickle loaders that trust entire module namespaces instead of specific safe callables. Attackers can craft malicious pickle payloads invoking dangerous in-namespace functions like…
- risk 0.57cvss 9.8epss 0.01
Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions.
- risk 0.57cvss 9.8epss 0.01
The WS Form LITE – Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.10.80 via deserialization of untrusted input from form submission meta values. This makes it possible for unauthenticated…
- risk 0.57cvss 9.8epss 0.01
LMDeploy deserializes disaggregated-serving peer messages with pickle. The handle_zmq_recv coroutine in lmdeploy/pytorch/disagg/conn/engine_conn.py reads peer-to-peer cache-free requests with recv_pyobj(), which deserializes the received bytes with pickle.loads(), and the…
- risk 0.57cvss 8.8epss 0.01
In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could execute arbitrary code on the Splunk server by loading a model file containing crafted sparse matrix data. The deserialization of untrusted data is possible because a model codec in Splunk…
- risk 0.57cvss 8.8epss 0.01
Deserialization of Untrusted Data vulnerability in TaxoPress allows Object Injection. This issue affects TaxoPress: from n/a through 3.51.0.
- risk 0.57cvss 8.8epss 0.01
Customer PHP Object Injection in Essential Real Estate <= 5.3.3 versions.
- risk 0.57cvss 8.8epss 0.00
Unauthenticated PHP Object Injection in Booking Activities <= 1.18.4 versions.
- risk 0.57cvss 8.8epss 0.02
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.02
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.02
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.02
Deserialization of untrusted data in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.02
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.