CWE-502— Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.— MITRE CWE catalog
3,159 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-502page 57 of 64
- CVE-2026-39474HIGHCVSS 8.8EG 8.82026-06-15
Contributor PHP Object Injection in Post Duplicator <= 3.0.10 versions.
- CVE-2026-39478HIGHCVSS 8.8EG 8.82026-06-15
Contributor PHP Object Injection in Anti-Malware Security and Brute-Force Firewall <= 4.23.87 versions.
- CVE-2026-39481HIGHCVSS 7.2EG 7.22026-06-15
Author PHP Object Injection in Modula Image Gallery <= 2.14.18 versions.
- CVE-2026-39498HIGHCVSS 7.2EG 7.22026-06-15
Shop manager PHP Object Injection in YayMail <= 4.3.3 versions.
- CVE-2026-39499HIGHCVSS 7.2EG 7.22026-06-15
Shop manager PHP Object Injection in Advanced Product Fields (Product Addons) for WooCommerce <= 1.6.19 versions.
- CVE-2026-39529CRITICALCVSS 9.8EG 9.82026-06-17
Unauthenticated PHP Object Injection in Elementra <= 1.0.9 versions.
- CVE-2026-39532HIGHCVSS 8.8EG 8.82026-06-15
Contributor PHP Object Injection in Events Calendar for GeoDirectory <= 2.3.25 versions.
- CVE-2026-39539HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in Alloggio - Hotel Booking <= 2.1.2 versions.
- CVE-2026-39545HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in Zermatt <= 1.6.1 versions.
- CVE-2026-39550HIGHCVSS 8.1EG 8.12026-06-02
Deserialization of Untrusted Data vulnerability in Elated-Themes Aperitif allows Object Injection. This issue affects Aperitif: from n/a through 1.6.
- CVE-2026-39551HIGHCVSS 8.1EG 8.12026-06-02
Deserialization of Untrusted Data vulnerability in Elated-Themes Töbel allows Object Injection. This issue affects Töbel: from n/a through 1.8.1.
- CVE-2026-39554HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in Fidalgo <= 1.2.2 versions.
- CVE-2026-39555HIGHCVSS 8.1EG 8.12026-06-02
Deserialization of Untrusted Data vulnerability in Elated-Themes Askka allows Object Injection. This issue affects Askka: from n/a through 1.3.1.
- CVE-2026-39556HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in Konsept <= 1.9 versions.
- CVE-2026-39557HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in NeoBeat <= 1.7 versions.
- CVE-2026-39560HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in Hiroshi <= 1.5.1 versions.
- CVE-2026-39567HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in Santé <= 1.5.1 versions.
- CVE-2026-39573HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in Mildhill <= 1.5 versions.
- CVE-2026-39576HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in SingleMalt <= 1.5 versions.
- CVE-2026-39577MEDIUMCVSS 5.5EG 5.52026-06-17
Unauthenticated PHP Object Injection in Playroom <= 1.4.1 versions.
- CVE-2026-39578MEDIUMCVSS 5.5EG 5.52026-06-17
Unauthenticated PHP Object Injection in Valiance <= 1.2 versions.
- CVE-2026-39580HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in Micdrop <= 1.3.1 versions.
- CVE-2026-3967MEDIUMCVSS 6.3EG 6.32026-03-12
A flaw has been found in Alfresco Activiti up to 7.19/8.8.0. Affected by this issue is the function deserialize/createObjectInputStream of the file activiti-core/activiti-engine/src/main/java/org/activiti/engine/impl/variable/SerializableT…
- CVE-2026-39832CRITICALCVSS 9.1EG 9.12026-05-22
When adding a key to a remote agent constraint extensions such as [email protected] were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of t…
- CVE-2026-3989HIGHCVSS 7.8EG 7.82026-03-12
SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization. An attacker can take advantage of this by providing a malicious .pkl file, which will execute the attackers code on the devi…
- CVE-2026-39890CRITICALCVSS 9.8EG 9.82026-04-08
PraisonAI is a multi-agent teams system. Prior to 4.5.115, the AgentService.loadAgentFromFile method uses the js-yaml library to parse YAML files without disabling dangerous tags (such as !!js/function and !!js/undefined). This allows an a…
- CVE-2026-40044CRITICALCVSS 9.8EG 9.82026-04-13
Pachno 1.0.6 contains a deserialization vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting malicious serialized objects into cache files. Attackers can write PHP object payloads to world-writable cac…
- CVE-2026-40048HIGHCVSS 7.8EG 7.82026-04-27
The Camel-PQC FileBasedKeyLifecycleManager class deserializes the contents of `<keyId>.key` files in the configured key directory using java.io.ObjectInputStream without applying any ObjectInputFilter or class-loading restrictions. The cas…
- CVE-2026-40357HIGHCVSS 8.8EG 8.82026-05-12
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- CVE-2026-40368HIGHCVSS 8.0EG 8.02026-05-12
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- CVE-2026-40473HIGHCVSS 8.8EG 8.82026-04-27
The camel-mina component's MinaConverter.toObjectInput(IoBuffer) type converter wraps an IoBuffer in a java.io.ObjectInputStream without applying any ObjectInputFilter or class-loading restrictions. When a Camel route uses camel-mina as a …
- CVE-2026-40725CRITICALCVSS 9.8EG 9.82026-06-17
Unauthenticated PHP Object Injection in WooCommerce Product Filters < 2.0.6 versions.
- CVE-2026-40733HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in ShiftUp <= 1.3 versions.
- CVE-2026-40735HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in Reina <= 2.1 versions.
- CVE-2026-40736HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in Laurits <= 1.5.1 versions.
- CVE-2026-40738HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in Eldon <= 1.4.1 versions.
- CVE-2026-40739HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in LuxeDrive <= 1.4 versions.
- CVE-2026-40751HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in Ashtanga <= 1.2 versions.
- CVE-2026-40752HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in Manufaktur Solutions <= 1.1.1 versions.
- CVE-2026-40753HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in EasyMeals <= 1.5.1 versions.
- CVE-2026-40754HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in Roisin <= 1.4 versions.
- CVE-2026-40755HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in TechLink <= 1.3 versions.
- CVE-2026-40756HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in Zoya <= 1.4 versions.
- CVE-2026-40757HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in Château <= 1.2.1 versions.
- CVE-2026-40758HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in Léonie <= 1.2.1 versions.
- CVE-2026-40759HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in Esmée <= 1.4 versions.
- CVE-2026-40760HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in Behold <= 1.5 versions.
- CVE-2026-40761HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in Valeska <= 1.2.2 versions.
- CVE-2026-40858HIGHCVSS 8.8EG 8.82026-04-27
The camel-infinispan component's ProtoStream-based remote aggregation repository deserializes data read from a remote Infinispan cache using java.io.ObjectInputStream without applying any ObjectInputFilter. An attacker who can write to the…
- CVE-2026-40859HIGHCVSS 8.1EG 8.12026-07-06
Deserialization of Untrusted Data vulnerability in Apache Camel. The camel-vertx-http component deserializes HTTP response bodies carrying the Content-Type application/x-java-serialized-object using a raw java.io.ObjectInputStream, withou…
Map vulnerabilities like CWE-502 to your infrastructure
EchelonGraph correlates every CVE — across CWE-502 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →