CWE-502— Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.— MITRE CWE catalog
3,465 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-502page 10 of 70
- CVE-2025-60237CRITICALCVSS 9.8EG 9.82026-03-19
Deserialization of Untrusted Data vulnerability in Themeton Finag allows Object Injection.This issue affects Finag: from n/a through 1.5.0.
- CVE-2025-60233CRITICALCVSS 9.8EG 9.82026-03-19
Deserialization of Untrusted Data vulnerability in Themeton Zuut allows Object Injection.This issue affects Zuut: from n/a through 1.4.2.
- CVE-2026-25873CRITICALCVSS 9.8EG 9.82026-03-18
OmniGen2-RL contains an unauthenticated remote code execution vulnerability in the reward server component that allows remote attackers to execute arbitrary commands by sending malicious HTTP POST requests. Attackers can exploit insecure p…
- CVE-2026-25449CRITICALCVSS 9.8EG 9.82026-03-18
Deserialization of Untrusted Data vulnerability in shinetheme Traveler traveler allows Object Injection.This issue affects Traveler: from n/a through < 3.2.8.1.
- CVE-2026-3060CRITICALCVSS 9.8EG 9.82026-03-12
SGLang' encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module, which deserializes untrusted data using pickle.loads() without authentication.
- CVE-2026-3059CRITICALCVSS 9.8EG 9.82026-03-12
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker, which deserializes untrusted data using pickle.loads() without authentication.
- CVE-2025-56422CRITICALCVSS 9.8EG 9.82026-03-10
A deserialization vulnerability in LimeSurvey before v6.15.0+250623 allows a remote attacker to execute arbitrary code on the server.
- CVE-2026-2599CRITICALCVSS 9.8EG 9.82026-03-05
The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.7 via deserialization of untrusted input in the 'download_csv' function. This ma…
- CVE-2026-28105CRITICALCVSS 9.8EG 9.82026-03-05
Deserialization of Untrusted Data vulnerability in ThemeREX Good Energy goodenergy allows Object Injection.This issue affects Good Energy: from n/a through <= 1.7.7.
- CVE-2026-28074CRITICALCVSS 9.8EG 9.82026-03-05
Deserialization of Untrusted Data vulnerability in ThemeREX Pizza House pizzahouse allows Object Injection.This issue affects Pizza House: from n/a through <= 1.4.0.
- CVE-2026-27439CRITICALCVSS 9.8EG 9.82026-03-05
Deserialization of Untrusted Data vulnerability in ThemeREX Dentario dentario allows Object Injection.This issue affects Dentario: from n/a through <= 1.5.
- CVE-2026-27438CRITICALCVSS 9.8EG 9.82026-03-05
Deserialization of Untrusted Data vulnerability in ThemeREX Kingler kingler allows Object Injection.This issue affects Kingler: from n/a through <= 1.7.
- CVE-2026-27437CRITICALCVSS 9.8EG 9.82026-03-05
Deserialization of Untrusted Data vulnerability in ThemeREX Tennis Club tennis-sportclub allows Object Injection.This issue affects Tennis Club: from n/a through <= 1.2.3.
- CVE-2026-27417CRITICALCVSS 9.8EG 9.82026-03-05
Deserialization of Untrusted Data vulnerability in SeventhQueen Sweet Date sweetdate allows Object Injection.This issue affects Sweet Date: from n/a through < 4.0.1.
- CVE-2026-22501CRITICALCVSS 9.8EG 9.82026-03-05
Deserialization of Untrusted Data vulnerability in axiomthemes Mounthood mounthood allows Object Injection.This issue affects Mounthood: from n/a through <= 1.3.2.
- CVE-2026-22497CRITICALCVSS 9.8EG 9.82026-03-05
Deserialization of Untrusted Data vulnerability in AncoraThemes Jardi jardi allows Object Injection.This issue affects Jardi: from n/a through <= 1.7.2.
- CVE-2026-22475CRITICALCVSS 9.8EG 9.82026-03-05
Deserialization of Untrusted Data vulnerability in axiomthemes Estate estate allows Object Injection.This issue affects Estate: from n/a through <= 1.3.4.
- CVE-2026-22474CRITICALCVSS 9.8EG 9.82026-03-05
Deserialization of Untrusted Data vulnerability in ThemeREX Equestrian Centre equestrian-centre allows Object Injection.This issue affects Equestrian Centre: from n/a through <= 1.5.
- CVE-2026-22454CRITICALCVSS 9.8EG 9.82026-03-05
Deserialization of Untrusted Data vulnerability in ThemeREX Solaris solaris allows Object Injection.This issue affects Solaris: from n/a through <= 2.5.
- CVE-2026-22453CRITICALCVSS 9.8EG 9.82026-03-05
Deserialization of Untrusted Data vulnerability in ThemeREX Pets Club petclub allows Object Injection.This issue affects Pets Club: from n/a through <= 2.3.
- CVE-2026-22451CRITICALCVSS 9.8EG 9.82026-03-05
Deserialization of Untrusted Data vulnerability in AncoraThemes Handyman handyman-services allows Object Injection.This issue affects Handyman: from n/a through <= 1.4.7.
- CVE-2026-22417CRITICALCVSS 9.8EG 9.82026-03-05
Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Wedding grandwedding allows Object Injection.This issue affects Grand Wedding: from n/a through < 3.1.11.
- CVE-2025-54001CRITICALCVSS 9.8EG 9.82026-03-05
Deserialization of Untrusted Data vulnerability in ThemeREX Classter classter allows Object Injection.This issue affects Classter: from n/a through <= 2.5.
- CVE-2026-27971CRITICALCVSS 9.8EG 9.82026-03-03
Qwik is a performance focused javascript framework. qwik <=1.19.0 is vulnerable to RCE due to an unsafe deserialization vulnerability in the server$ RPC mechanism that allows any unauthenticated user to execute arbitrary code on the server…
- CVE-2025-57622CRITICALCVSS 9.8EG 9.82026-03-03
An issue in Step-Video-T2V allows a remote attacker to execute arbitrary code via the /vae-api , /caption-api , feature = pickle.loads(request.get_data()) component
- CVE-2025-52998CRITICALCVSS 9.8EG 9.82026-03-02
Chamilo is a learning management system. Prior to version 1.11.30, in the application, deserialization of data is performed, the data can be spoofed. An attacker can create objects of arbitrary classes, as well as fully control their prope…
- CVE-2026-3422CRITICALCVSS 9.8EG 9.82026-03-02
U-Office Force developed by e-Excellence has a Insecure Deserialization vulnerability, allowing unauthenticated remote attackers to execute arbitrary code on the server by sending maliciously crafted serialized content.
- CVE-2026-27727CRITICALCVSS 9.8EG 9.82026-02-25
mchange-commons-java, a library that provides Java utilities, includes code that mirrors early implementations of JNDI functionality, including support for remote `factoryClassLocation` values, by which code can be downloaded and invoked w…
- CVE-2026-26222CRITICALCVSS 9.8EG 9.82026-02-24
Altec DocLink (now maintained by Beyond Limits Inc.) version 4.0.336.0 exposes insecure .NET Remoting endpoints over TCP and HTTP/SOAP via Altec.RDCHostService.exe using the ObjectURI "doclinkServer.soap". The service does not require auth…
- CVE-2026-22384CRITICALCVSS 9.8EG 9.82026-02-20
Deserialization of Untrusted Data vulnerability in leafcolor Applay - Shortcodes applay-shortcodes allows Object Injection.This issue affects Applay - Shortcodes: from n/a through <= 3.7.
- CVE-2025-69405CRITICALCVSS 9.8EG 9.82026-02-20
Deserialization of Untrusted Data vulnerability in ThemeREX Lorem Ipsum | Books & Media Store lorem-ipsum-books-media-store allows Object Injection.This issue affects Lorem Ipsum | Books & Media Store: from n/a through <= 1.2.11.
- CVE-2025-69404CRITICALCVSS 9.8EG 9.82026-02-20
Deserialization of Untrusted Data vulnerability in ThemeREX Extreme Store extremestore allows Object Injection.This issue affects Extreme Store: from n/a through <= 1.5.10.
- CVE-2025-69382CRITICALCVSS 9.8EG 9.82026-02-20
Deserialization of Untrusted Data vulnerability in themesflat Themesflat Elementor themesflat-elementor allows Object Injection.This issue affects Themesflat Elementor: from n/a through <= 1.0.1.
- CVE-2025-69372CRITICALCVSS 9.8EG 9.82026-02-20
Deserialization of Untrusted Data vulnerability in AncoraThemes SevenHills sevenhills allows Object Injection.This issue affects SevenHills: from n/a through <= 1.6.2.
- CVE-2025-69371CRITICALCVSS 9.8EG 9.82026-02-20
Deserialization of Untrusted Data vulnerability in AncoraThemes KindlyCare kindlycare allows Object Injection.This issue affects KindlyCare: from n/a through <= 1.6.1.
- CVE-2025-69370CRITICALCVSS 9.8EG 9.82026-02-20
Deserialization of Untrusted Data vulnerability in ThemeGoods Capella capella allows Object Injection.This issue affects Capella: from n/a through <= 2.5.5.
- CVE-2025-69329CRITICALCVSS 9.8EG 9.82026-02-20
Deserialization of Untrusted Data vulnerability in Jthemes Prestige prestige allows Object Injection.This issue affects Prestige: from n/a through < 1.4.1.
- CVE-2025-69301CRITICALCVSS 9.8EG 9.82026-02-20
Deserialization of Untrusted Data vulnerability in ThemeGoods PhotoMe photome allows Object Injection.This issue affects PhotoMe: from n/a through <= 5.6.11.
- CVE-2025-68541CRITICALCVSS 9.8EG 9.82026-02-20
Deserialization of Untrusted Data vulnerability in BoldThemes Ippsum ippsum allows Object Injection.This issue affects Ippsum: from n/a through <= 1.2.0.
- CVE-2025-67997CRITICALCVSS 9.8EG 9.82026-02-20
Deserialization of Untrusted Data vulnerability in BoldThemes Travelicious travelicious allows Object Injection.This issue affects Travelicious: from n/a through < 1.6.7.
- CVE-2025-67996CRITICALCVSS 9.8EG 9.82026-02-20
Deserialization of Untrusted Data vulnerability in BoldThemes Nestin nestin allows Object Injection.This issue affects Nestin: from n/a through < 1.2.6.
- CVE-2025-67995CRITICALCVSS 9.8EG 9.82026-02-20
Deserialization of Untrusted Data vulnerability in LoftOcean PatioTime patiotime allows Object Injection.This issue affects PatioTime: from n/a through < 2.1.
- CVE-2026-23549CRITICALCVSS 9.8EG 9.82026-02-19
Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection.This issue affects WpEvently: from n/a through <= 5.1.1.
- CVE-2026-23542CRITICALCVSS 9.8EG 9.82026-02-19
Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Restaurant grandrestaurant allows Object Injection.This issue affects Grand Restaurant: from n/a through <= 7.0.10.
- CVE-2026-26221CRITICALCVSS 9.8EG 9.82026-02-13
Hyland OnBase contains an unauthenticated .NET Remoting exposure in the OnBase Workflow Timer Service (Hyland.Core.Workflow.NTService.exe). An attacker who can reach the service can send crafted .NET Remoting requests to default HTTP chann…
- CVE-2025-69872CRITICALCVSS 9.8EG 9.82026-02-11
DiskCache (python-diskcache) through 5.6.3 uses Python pickle for serialization by default. An attacker with write access to the cache directory can achieve arbitrary code execution when a victim application reads from the cache.
- CVE-2026-21531CRITICALCVSS 9.8EG 9.82026-02-10
Deserialization of untrusted data in Azure SDK allows an unauthorized attacker to execute code over a network.
- CVE-2026-2113CRITICALCVSS 9.8EG 9.82026-02-07
A security vulnerability has been detected in yuan1994 tpadmin up to 1.3.12. This affects an unknown part in the library /public/static/admin/lib/webuploader/0.1.5/server/preview.php of the component WebUploader. The manipulation leads to …
- CVE-2020-37071CRITICALCVSS 9.8EG 9.82026-02-03
CraftCMS 3 vCard Plugin 1.0.0 contains a deserialization vulnerability that allows unauthenticated attackers to execute arbitrary PHP code through a crafted payload. Attackers can generate a malicious serialized payload that triggers remot…
- CVE-2025-61140CRITICALCVSS 9.8EG 9.82026-01-28
The value function in jsonpath 1.1.1 lib/index.js is vulnerable to Prototype Pollution.
Map vulnerabilities like CWE-502 to your infrastructure
EchelonGraph correlates every CVE — across CWE-502 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →