CWE-502
Deserialization of Untrusted Data
Description
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-586
CVEs mapped to this weakness (3,323)
page 88 of 167| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-82925 | Hig | 0.53 | 8.1 | 0.00 | Sep 10, 2026 | The Site Reviews WordPress plugin before 8.3.0 does not prevent request data from being deserialized, and derives the key protecting that data by padding out the site's WordPress nonce key, which makes the key publicly computable on installs where that key is absent, left at its… | ||
| CVE-2026-87930 | Hig | 0.53 | 8.1 | 0.01 | Sep 9, 2026 | MaxSite CMS through 109.6 passes the ci_session cookie to unserialize() without class restrictions, allowing unauthenticated attackers to inject PHP objects. Attackers can forge valid session cookies using the hardcoded encryption key to trigger magic methods and corrupt… | ||
| CVE-2026-87874 | Hig | 0.53 | 8.1 | 0.01 | Sep 9, 2026 | A flaw was found in the memcached cache plugin of the community.general Ansible collection. Although its documentation states that records are stored in JSON format, the plugin performs no explicit serialization and relies on python-memcached, which pickles values on write and… | ||
| CVE-2026-47297 | Hig | 0.53 | 8.1 | 0.01 | Sep 8, 2026 | Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-59285 | Hig | 0.53 | 8.1 | 0.00 | Aug 27, 2026 | Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries. Spring for GraphQL 2.0.0 - 2.0.4 | ||
| CVE-2026-16267 | Hig | 0.53 | 8.1 | 0.00 | Aug 8, 2026 | The Newsletters WordPress plugin before 4.16 does not restrict the classes allowed when unserialising a value taken from a public form submission, allowing unauthenticated attackers to inject arbitrary PHP objects. | ||
| CVE-2026-47623 | Hig | 0.53 | 8.2 | 0.01 | Aug 4, 2026 | NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to denial of service and data tampering. | ||
| CVE-2025-15672 | Hig | 0.53 | 8.1 | 0.01 | Aug 3, 2026 | The ChamaWP WordPress plugin before 1.0.13 does not properly validate user input before passing it to a PHP deserialization function, allowing unauthenticated attackers to inject arbitrary PHP objects, which could lead to remote code execution when a suitable gadget chain is… | ||
| CVE-2026-14974 | Hig | 0.53 | 8.1 | 0.01 | Jul 28, 2026 | IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code caused by unsafe deserialization of untrusted data. | ||
| CVE-2026-13190 | Hig | 0.53 | 8.1 | 0.01 | Jul 22, 2026 | In Progress® Telerik® UI for AJAX prior to v2026.2.708, a deserialization vulnerability in the persistence utilities allows unsafe type instantiation from attacker-influenced persisted state, which can lead to remote code execution. | ||
| CVE-2026-13185 | Hig | 0.53 | 8.1 | 0.01 | Jul 22, 2026 | In Progress® Telerik® UI for AJAX prior to v2026.2.708, applications using cookie-based storage in RadPersistenceManager or RadDockLayout deserialize attacker-controlled cookie content, allowing unauthenticated remote code execution. | ||
| CVE-2026-39253 | Hig | 0.53 | 8.1 | 0.01 | Jun 23, 2026 | An issue in Pivotal CRM v.6.6.04.08 allows a remote attacker to execute arbitrary code via the Pivotal.Core.Common.dll and Pivotal.Engine.Client.Services.Conversion.dll components. | ||
| CVE-2026-45034 | Cri | 0.53 | — | 0.00 | Jun 22, 2026 | PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Prior to 1.30.5, CVE-2026-34084 was patched by the helper File::prohibitWrappers. The helper calls parse_url($filename, PHP_URL_SCHEME) and then checks is_string($scheme) && strlen($scheme) > 1 to… | ||
| CVE-2026-40761 | Hig | 0.53 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated PHP Object Injection in Valeska <= 1.2.2 versions. | ||
| CVE-2026-40760 | Hig | 0.53 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated PHP Object Injection in Behold <= 1.5 versions. | ||
| CVE-2026-40759 | Hig | 0.53 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated PHP Object Injection in Esmée <= 1.4 versions. | ||
| CVE-2026-40758 | Hig | 0.53 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated PHP Object Injection in Léonie <= 1.2.1 versions. | ||
| CVE-2026-40755 | Hig | 0.53 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated PHP Object Injection in TechLink <= 1.3 versions. | ||
| CVE-2026-40754 | Hig | 0.53 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated PHP Object Injection in Roisin <= 1.4 versions. | ||
| CVE-2026-40753 | Hig | 0.53 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated PHP Object Injection in EasyMeals <= 1.5.1 versions. |
- risk 0.53cvss 8.1epss 0.00
The Site Reviews WordPress plugin before 8.3.0 does not prevent request data from being deserialized, and derives the key protecting that data by padding out the site's WordPress nonce key, which makes the key publicly computable on installs where that key is absent, left at its…
- risk 0.53cvss 8.1epss 0.01
MaxSite CMS through 109.6 passes the ci_session cookie to unserialize() without class restrictions, allowing unauthenticated attackers to inject PHP objects. Attackers can forge valid session cookies using the hardcoded encryption key to trigger magic methods and corrupt…
- risk 0.53cvss 8.1epss 0.01
A flaw was found in the memcached cache plugin of the community.general Ansible collection. Although its documentation states that records are stored in JSON format, the plugin performs no explicit serialization and relies on python-memcached, which pickles values on write and…
- risk 0.53cvss 8.1epss 0.01
Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.
- risk 0.53cvss 8.1epss 0.00
Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries. Spring for GraphQL 2.0.0 - 2.0.4
- risk 0.53cvss 8.1epss 0.00
The Newsletters WordPress plugin before 4.16 does not restrict the classes allowed when unserialising a value taken from a public form submission, allowing unauthenticated attackers to inject arbitrary PHP objects.
- risk 0.53cvss 8.2epss 0.01
NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to denial of service and data tampering.
- risk 0.53cvss 8.1epss 0.01
The ChamaWP WordPress plugin before 1.0.13 does not properly validate user input before passing it to a PHP deserialization function, allowing unauthenticated attackers to inject arbitrary PHP objects, which could lead to remote code execution when a suitable gadget chain is…
- risk 0.53cvss 8.1epss 0.01
IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code caused by unsafe deserialization of untrusted data.
- risk 0.53cvss 8.1epss 0.01
In Progress® Telerik® UI for AJAX prior to v2026.2.708, a deserialization vulnerability in the persistence utilities allows unsafe type instantiation from attacker-influenced persisted state, which can lead to remote code execution.
- risk 0.53cvss 8.1epss 0.01
In Progress® Telerik® UI for AJAX prior to v2026.2.708, applications using cookie-based storage in RadPersistenceManager or RadDockLayout deserialize attacker-controlled cookie content, allowing unauthenticated remote code execution.
- risk 0.53cvss 8.1epss 0.01
An issue in Pivotal CRM v.6.6.04.08 allows a remote attacker to execute arbitrary code via the Pivotal.Core.Common.dll and Pivotal.Engine.Client.Services.Conversion.dll components.
- risk 0.53cvss —epss 0.00
PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Prior to 1.30.5, CVE-2026-34084 was patched by the helper File::prohibitWrappers. The helper calls parse_url($filename, PHP_URL_SCHEME) and then checks is_string($scheme) && strlen($scheme) > 1 to…
- risk 0.53cvss 8.1epss 0.00
Unauthenticated PHP Object Injection in Valeska <= 1.2.2 versions.
- risk 0.53cvss 8.1epss 0.00
Unauthenticated PHP Object Injection in Behold <= 1.5 versions.
- risk 0.53cvss 8.1epss 0.00
Unauthenticated PHP Object Injection in Esmée <= 1.4 versions.
- risk 0.53cvss 8.1epss 0.00
Unauthenticated PHP Object Injection in Léonie <= 1.2.1 versions.
- risk 0.53cvss 8.1epss 0.00
Unauthenticated PHP Object Injection in TechLink <= 1.3 versions.
- risk 0.53cvss 8.1epss 0.00
Unauthenticated PHP Object Injection in Roisin <= 1.4 versions.
- risk 0.53cvss 8.1epss 0.00
Unauthenticated PHP Object Injection in EasyMeals <= 1.5.1 versions.