VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,116)

page 68 of 156
  • CVE-2024-31277HigApr 7, 2024
    risk 0.57cvss 8.7epss 0.00

    Deserialization of Untrusted Data vulnerability in PickPlugins Product Designer.This issue affects Product Designer: from n/a through 1.0.32.

  • CVE-2024-2008HigApr 4, 2024
    risk 0.57cvss 8.8epss 0.01

    The Modal Popup Box – Popup Builder, Show Offers And News in Popup plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.5.2 via deserialization of untrusted input in the awl_modal_popup_box_shortcode function. This makes it…

  • CVE-2024-1872HigMar 29, 2024
    risk 0.57cvss 8.8epss 0.01

    The Button plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1.27 via deserialization of untrusted input in the button_shortcode function. This makes it possible for authenticated attackers, with contributor-level access and…

  • CVE-2024-24842HigMar 27, 2024
    risk 0.57cvss 8.7epss 0.00

    Deserialization of Untrusted Data vulnerability in Echo Plugins Knowledge Base for Documentation, FAQs with AI Assistance.This issue affects Knowledge Base for Documentation, FAQs with AI Assistance: from n/a through 11.30.2.

  • CVE-2024-1685HigMar 16, 2024
    risk 0.57cvss 8.8epss 0.01

    The Social Media Share Buttons plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.1.0 via deserialization of untrusted input through the attachmentUrl parameter. This makes it possible for authenticated attackers, with…

  • CVE-2024-2006HigMar 13, 2024
    risk 0.57cvss 8.8epss 0.01

    The Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.6.7 via deserialization of untrusted input in the outpost_shortcode_metabox_markup…

  • CVE-2024-1772HigMar 13, 2024
    risk 0.57cvss 8.8epss 0.01

    The Play.ht – Make Your Blog Posts Accessible With Text to Speech Audio plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.6.4 via deserialization of untrusted input from the play_podcast_data post meta. This makes it possible…

  • CVE-2024-1773HigMar 7, 2024
    risk 0.57cvss 8.8epss 0.01

    The PDF Invoices and Packing Slips For WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3.7 via deserialization of untrusted input via the order_id parameter. This makes it possible for authenticated attackers, with…

  • CVE-2024-28213CriMar 7, 2024
    risk 0.57cvss 9.8epss 0.01

    nGrinder before 3.5.9 allows to accept serialized Java objects from unauthenticated users, which could allow remote attacker to execute arbitrary code via unsafe Java objects deserialization.

  • CVE-2024-1731HigMar 5, 2024
    risk 0.57cvss 8.8epss 0.01

    The Auto Refresh Single Page plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1 via deserialization of untrusted input from the arsp_options post meta option. This makes it possible for authenticated attackers, with…

  • CVE-2024-0825HigMar 5, 2024
    risk 0.57cvss 8.8epss 0.01

    The Vimeography: Vimeo Video Gallery WordPress Plugin plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.3.2 via deserialization of untrusted input via the vimeography_duplicate_gallery_serialized in the duplicate_gallery function.…

  • CVE-2024-1859HigMar 1, 2024
    risk 0.57cvss 8.8epss 0.01

    The Slider Responsive Slideshow – Image slider, Gallery slideshow plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3.8 via deserialization of untrusted input to the awl_slider_responsive_shortcode function. This makes it…

  • CVE-2024-23114CriFeb 20, 2024
    risk 0.57cvss 9.8epss 0.01

    Deserialization of Untrusted Data vulnerability in Apache Camel CassandraQL Component AggregationRepository which is vulnerable to unsafe deserialization. Under specific conditions it is possible to deserialize malicious payload.This issue affects Apache Camel: from 3.0.0 before…

  • CVE-2024-23512HigFeb 12, 2024
    risk 0.57cvss 8.7epss 0.01

    Deserialization of Untrusted Data vulnerability in wpxpo ProductX – WooCommerce Builder & Gutenberg WooCommerce Blocks.This issue affects ProductX – WooCommerce Builder & Gutenberg WooCommerce Blocks: from n/a through 3.1.4.

  • CVE-2024-23513HigFeb 12, 2024
    risk 0.57cvss 8.7epss 0.01

    Deserialization of Untrusted Data vulnerability in PropertyHive.This issue affects PropertyHive: from n/a through 2.0.5.

  • CVE-2024-22309HigJan 24, 2024
    risk 0.57cvss 8.7epss 0.01

    Deserialization of Untrusted Data vulnerability in QuantumCloud ChatBot with AI.This issue affects ChatBot with AI: from n/a through 5.1.0.

  • CVE-2024-23636CriJan 23, 2024
    risk 0.57cvss 9.8epss 0.01

    SOFARPC is a Java RPC framework. SOFARPC defaults to using the SOFA Hessian protocol to deserialize received data, while the SOFA Hessian protocol uses a blacklist mechanism to restrict deserialization of potentially dangerous classes for security protection. But, prior to…

  • CVE-2017-20189CriJan 22, 2024
    risk 0.57cvss 9.8epss 0.01

    In Clojure before 1.9.0, classes can be used to construct a serialized object that executes arbitrary code upon deserialization. This is relevant if a server deserializes untrusted objects.

  • CVE-2024-23730CriJan 21, 2024
    risk 0.57cvss 9.8epss 0.01

    The OpenAPI and ChatGPT plugin loaders in LlamaHub (aka llama-hub) before 0.0.67 allow attackers to execute arbitrary code because safe_load is not used for YAML.

  • CVE-2023-6528HigJan 8, 2024
    risk 0.57cvss 8.8epss 0.01

    The Slider Revolution WordPress plugin before 6.6.19 does not prevent users with at least the Author role from unserializing arbitrary content when importing sliders, potentially leading to Remote Code Execution.