VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,323)

page 88 of 167
  • CVE-2026-82925HigSep 10, 2026
    risk 0.53cvss 8.1epss 0.00

    The Site Reviews WordPress plugin before 8.3.0 does not prevent request data from being deserialized, and derives the key protecting that data by padding out the site's WordPress nonce key, which makes the key publicly computable on installs where that key is absent, left at its…

  • CVE-2026-87930HigSep 9, 2026
    risk 0.53cvss 8.1epss 0.01

    MaxSite CMS through 109.6 passes the ci_session cookie to unserialize() without class restrictions, allowing unauthenticated attackers to inject PHP objects. Attackers can forge valid session cookies using the hardcoded encryption key to trigger magic methods and corrupt…

  • CVE-2026-87874HigSep 9, 2026
    risk 0.53cvss 8.1epss 0.01

    A flaw was found in the memcached cache plugin of the community.general Ansible collection. Although its documentation states that records are stored in JSON format, the plugin performs no explicit serialization and relies on python-memcached, which pickles values on write and…

  • CVE-2026-47297HigSep 8, 2026
    risk 0.53cvss 8.1epss 0.01

    Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.

  • CVE-2026-59285HigAug 27, 2026
    risk 0.53cvss 8.1epss 0.00

    Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries. Spring for GraphQL 2.0.0 - 2.0.4

  • CVE-2026-16267HigAug 8, 2026
    risk 0.53cvss 8.1epss 0.00

    The Newsletters WordPress plugin before 4.16 does not restrict the classes allowed when unserialising a value taken from a public form submission, allowing unauthenticated attackers to inject arbitrary PHP objects.

  • CVE-2026-47623HigAug 4, 2026
    risk 0.53cvss 8.2epss 0.01

    NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to denial of service and data tampering.

  • CVE-2025-15672HigAug 3, 2026
    risk 0.53cvss 8.1epss 0.01

    The ChamaWP WordPress plugin before 1.0.13 does not properly validate user input before passing it to a PHP deserialization function, allowing unauthenticated attackers to inject arbitrary PHP objects, which could lead to remote code execution when a suitable gadget chain is…

  • CVE-2026-14974HigJul 28, 2026
    risk 0.53cvss 8.1epss 0.01

    IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code caused by unsafe deserialization of untrusted data.

  • CVE-2026-13190HigJul 22, 2026
    risk 0.53cvss 8.1epss 0.01

    In Progress® Telerik® UI for AJAX prior to v2026.2.708, a deserialization vulnerability in the persistence utilities allows unsafe type instantiation from attacker-influenced persisted state, which can lead to remote code execution.

  • CVE-2026-13185HigJul 22, 2026
    risk 0.53cvss 8.1epss 0.01

    In Progress® Telerik® UI for AJAX prior to v2026.2.708, applications using cookie-based storage in RadPersistenceManager or RadDockLayout deserialize attacker-controlled cookie content, allowing unauthenticated remote code execution.

  • CVE-2026-39253HigJun 23, 2026
    risk 0.53cvss 8.1epss 0.01

    An issue in Pivotal CRM v.6.6.04.08 allows a remote attacker to execute arbitrary code via the Pivotal.Core.Common.dll and Pivotal.Engine.Client.Services.Conversion.dll components.

  • CVE-2026-45034CriJun 22, 2026
    risk 0.53cvss —epss 0.00

    PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Prior to 1.30.5, CVE-2026-34084 was patched by the helper File::prohibitWrappers. The helper calls parse_url($filename, PHP_URL_SCHEME) and then checks is_string($scheme) && strlen($scheme) > 1 to…

  • CVE-2026-40761HigJun 17, 2026
    risk 0.53cvss 8.1epss 0.00

    Unauthenticated PHP Object Injection in Valeska <= 1.2.2 versions.

  • CVE-2026-40760HigJun 17, 2026
    risk 0.53cvss 8.1epss 0.00

    Unauthenticated PHP Object Injection in Behold <= 1.5 versions.

  • CVE-2026-40759HigJun 17, 2026
    risk 0.53cvss 8.1epss 0.00

    Unauthenticated PHP Object Injection in Esmée <= 1.4 versions.

  • CVE-2026-40758HigJun 17, 2026
    risk 0.53cvss 8.1epss 0.00

    Unauthenticated PHP Object Injection in Léonie <= 1.2.1 versions.

  • CVE-2026-40755HigJun 17, 2026
    risk 0.53cvss 8.1epss 0.00

    Unauthenticated PHP Object Injection in TechLink <= 1.3 versions.

  • CVE-2026-40754HigJun 17, 2026
    risk 0.53cvss 8.1epss 0.00

    Unauthenticated PHP Object Injection in Roisin <= 1.4 versions.

  • CVE-2026-40753HigJun 17, 2026
    risk 0.53cvss 8.1epss 0.00

    Unauthenticated PHP Object Injection in EasyMeals <= 1.5.1 versions.