CWE-502— Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.— MITRE CWE catalog
3,465 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-502page 31 of 70
- CVE-2026-95531HIGHCVSS 8.8EG 8.82026-09-30
Subscriber PHP Object Injection in Conversational Forms for ChatBot <= 1.5.0 versions.
- CVE-2026-94683HIGHCVSS 8.8EG 8.82026-09-30
Contributor PHP Object Injection in DesignSetGo <= 2.8.0 versions.
- CVE-2026-94678HIGHCVSS 8.8EG 8.82026-09-30
Contributor PHP Object Injection in Go Live Update Urls <= 7.0.8 versions.
- CVE-2026-94121HIGHCVSS 8.8EG 8.82026-09-30
Contributor PHP Object Injection in 10Web Booster – Website speed optimization, Cache & Page Speed optimizer <= 2.33.6 versions.
- CVE-2026-94076HIGHCVSS 8.8EG 8.82026-09-30
Contributor PHP Object Injection in SEO Plugin by Squirrly SEO <= 14.2.5 versions.
- CVE-2026-100846HIGHCVSS 8.8EG 8.82026-09-27
MONAI before 1.5.2 contains a deserialization of untrusted data vulnerability in the algo_from_pickle function in monai/auto3dseg/utils.py. The function reads a .pkl file and passes its contents to pickle.loads without validating the data …
- CVE-2026-82093HIGHCVSS 8.8EG 8.82026-09-24
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to unsafe deserialization of untrusted data.
- CVE-2026-96804HIGHCVSS 8.8EG 8.82026-09-23
MLflow's statsmodel flavor, versions 2.1.0 to 3.14.0, omits the MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False security control entirely in _load_model(), which allows a remote attacker to execute arbitrary code via a crafted MLmodel artifact.
- CVE-2026-96775HIGHCVSS 8.8EG 8.82026-09-23
MLflow's dspy flavor, versions >= 2.0, applies the MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False security control only when the model_path ends in .pkl, which allows a remote attacker to execute arbitrary code via a crafted MLmodel artifact.
- CVE-2026-18490HIGHCVSS 8.8EG 8.82026-09-23
IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to unauthenticated remote code execution via Java native deserialization on the PayDir Business Rules Manager RMI SSL endpoint (BrmRMISSLServerSocketFactory.java:95…
- CVE-2026-17637HIGHCVSS 8.8EG 8.82026-09-22
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow an adjacent-network attacker to execute arbitrary code due to deserialization of untrusted data.
- CVE-2026-67615HIGHCVSS 8.8EG 8.82026-09-22
openEQUELLA before 2026.1.0 contains an authenticated remote code execution vulnerability that allows any authenticated non-guest user to execute arbitrary code by exploiting Java deserialization in the HTTP invoker endpoint at /invoker/*.…
- CVE-2026-28325HIGHCVSS 8.8EG 8.82026-09-22
SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability stemming from deserialization of untrusted data when the application is configured to use a specific communication mode.
- CVE-2026-65179HIGHCVSS 8.8EG 8.82026-09-22
NVIDIA NeMo contains a vulnerability in the TabularTokenizer class where it deserializes an untrusted, attacker-controlled .pkl file via pickle.load() without validation. A successful exploit of this vulnerability may lead to code executio…
- CVE-2026-17086HIGHCVSS 8.8EG 8.82026-09-18
The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.5.5 via deserialization of untrusted input . This makes it possible …
- CVE-2026-20340HIGHCVSS 8.8EG 8.82026-09-16
A vulnerability in Cisco Secure FMC Software could allow an authenticated, remote attacker to execute arbitrary commands at the root privilege level. This vulnerability is due to unsecured deserialization of web-management user-con…
- CVE-2026-12728HIGHCVSS 8.8EG 8.82026-09-15
IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker to ex…
- CVE-2026-13293HIGHCVSS 8.8EG 8.82026-09-14
IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow a remote authenticated attacker…
- CVE-2026-61701HIGHCVSS 8.8EG 8.82026-09-14
Laravel MagicLink creates links for authentication without a password or for accessing private content. From 2.0.0 until 2.25.1, MagicLink stores serialized action objects in the magic_links.action database column and deserializes them thr…
- CVE-2026-90777HIGHCVSS 8.8EG 8.82026-09-13
ESPnet before 202609 deserializes pretrained model checkpoints using torch.load with weights_only=False, allowing arbitrary code execution from attacker-supplied files. Attackers can craft malicious checkpoint files that execute code durin…
- CVE-2026-78175HIGHCVSS 8.8EG 8.82026-09-12
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.0.7 via the `withdraw_method_field` parameter of the `tutor_save_withdraw_account` AJ…
- CVE-2026-62107HIGHCVSS 8.8EG 8.82026-09-11
Unauthenticated PHP Object Injection in Masteriyo - LMS <= 3.4.0 versions.
- CVE-2026-81385HIGHCVSS 8.8EG 8.82026-09-08
Deserialization of untrusted data in Microsoft Office Publisher allows an unauthorized attacker to execute code over a network.
- CVE-2026-77484HIGHCVSS 8.8EG 8.82026-09-08
Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network.
- CVE-2026-65772HIGHCVSS 8.8EG 8.82026-09-08
Deserialization of untrusted data in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network.
- CVE-2026-12648HIGHCVSS 8.8EG 8.82026-09-08
A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.
- CVE-2026-12651HIGHCVSS 8.8EG 8.82026-09-08
A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.
- CVE-2026-16502HIGHCVSS 8.8EG 8.82026-09-08
The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.1.18 via deserialization of untrusted input . This makes it possible for authenticated …
- CVE-2026-86404HIGHCVSS 8.8EG 8.82026-09-07
EAP's Artemis deserialization configuration permits deserialization by default. ObjectMessage.getObject() uses ObjectInputStreamWithClassLoader, which implements allow-list/block-list filtering via its checkSecurity()/isTrustedType() metho…
- CVE-2026-19887HIGHCVSS 8.8EG 8.82026-09-05
The Welcart e-Commerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.12.1 via deserialization of untrusted input in the Telecom EDY payment callback (usces_action_acting_transaction). Un…
- CVE-2026-84752HIGHCVSS 8.8EG 8.82026-09-03
Contributor PHP Object Injection in RTMKit <= 2.1.5 versions.
- CVE-2026-84670HIGHCVSS 8.8EG 8.82026-09-02
Jenkins Performance Plugin 1015.v09ca_52b_3370e and earlier does not restrict the classes that can be instantiated when deserializing cached performance reports stored in the build directory on the Jenkins controller, allowing attackers wi…
- CVE-2026-84650HIGHCVSS 8.8EG 8.82026-09-02
In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, transient fields cannot be excluded from deserialization, allowing attackers able to submit configuration updates to specify the values of transient fields that will be deserialized, t…
- CVE-2026-84647HIGHCVSS 8.8EG 8.82026-09-02
In Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Stapler does not restrict the types of objects that can be instantiated via form data binding to t…
- CVE-2026-81772HIGHCVSS 8.8EG 8.82026-09-02
Unauthenticated PHP Object Injection in Ninja Forms - Layout & Styles <= 3.0.31 versions.
- CVE-2026-81283HIGHCVSS 8.8EG 8.82026-09-02
Subscriber PHP Object Injection in WP User Frontend <= 4.3.10 versions.
- CVE-2026-19116HIGHCVSS 8.8EG 8.82026-09-02
The User Frontend WordPress plugin before 4.3.11 does not prevent user-supplied field values from being deserialized when a submitted post is reopened in its frontend editing form, allowing authenticated users with subscriber-level access…
- CVE-2026-71981HIGHCVSS 8.8EG 8.82026-09-01
Cypht before 2.12.2 contains a PHP object injection vulnerability that allows authenticated attackers to execute arbitrary operating system commands by supplying a crafted PHP object graph in the back_query GET parameter of the logout hand…
- CVE-2026-72649HIGHCVSS 8.8EG 8.82026-09-01
Deserialization of Untrusted Data (CWE-502) in the Elasticsearch machine learning component can lead to remote code execution via Object Injection (CAPEC-586). A specially crafted trained model artifact could cause attacker-controlled logi…
- CVE-2026-84202HIGHCVSS 8.8EG 8.82026-09-01
ModelScope uses PyYAML's unsafe yaml.Loader to parse model configuration files, allowing arbitrary code execution through Python object construction tags. Attackers can craft malicious model repositories with poisoned configuration files t…
- CVE-2026-83497HIGHCVSS 8.8EG 8.82026-08-31
Unrestricted deserialization of untrusted data in the cursor pagination component in the OpenSearch SQL plugin allows a remote authenticated user with basic read/search permissions to execute arbitrary code on the server by sending a craft…
- CVE-2026-10036HIGHCVSS 8.8EG 8.82026-08-27
SpeechBrain before 1.1.1 contains an arbitrary code execution vulnerability that allows attackers to execute arbitrary code by supplying a crafted CKPT.yaml checkpoint metadata file parsed with PyYAML's unsafe loader during candidate enume…
- CVE-2026-78257HIGHCVSS 8.8EG 8.82026-08-27
Contributor PHP Object Injection in Booking and Rental Manager <= 2.7.5 versions.
- CVE-2026-0551HIGHCVSS 8.8EG 8.82026-08-22
The PPWP – Password Protect Pages plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.9.18 via deserialization of untrusted input from the 'post_protection_roles' vulnerable parameter. This …
- CVE-2026-71513HIGHCVSS 8.8EG 8.82026-08-22
NLTK before 3.10.3 contains a remote code execution vulnerability in AllowlistUnpickler that validates only the pickle module string and not the global name, allowing attackers to resolve dotted names by attribute traversal to callables ou…
- CVE-2026-76395HIGHCVSS 8.8EG 8.82026-08-19
In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could execute arbitrary code on the Splunk server by loading a model file containing crafted sparse matrix data. The deserialization of untrusted data is p…
- CVE-2026-74012HIGHCVSS 8.8EG 8.82026-08-18
Deserialization of Untrusted Data vulnerability in TaxoPress allows Object Injection. This issue affects TaxoPress: from n/a through 3.51.0.
- CVE-2026-32465HIGHCVSS 8.8EG 8.82026-08-18
Customer PHP Object Injection in Essential Real Estate <= 5.3.3 versions.
- CVE-2026-16099HIGHCVSS 8.8EG 8.82026-08-16
The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the create_link_item function in all versions up to, and including, 4.5.3. This makes it possible for a…
- CVE-2026-28176HIGHCVSS 8.8EG 8.82026-08-13
Unauthenticated PHP Object Injection in Booking Activities <= 1.18.4 versions.
Map vulnerabilities like CWE-502 to your infrastructure
EchelonGraph correlates every CVE — across CWE-502 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →