CWE-502— Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.— MITRE CWE catalog
3,465 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-502page 6 of 70
- CVE-2026-12745CRITICALCVSS 9.8EG 9.82026-09-08
A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticated attacker to execute arbitrary code on the server.
- CVE-2026-12744CRITICALCVSS 9.8EG 9.82026-09-08
A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticated attacker to execute arbitrary code on the server.
- CVE-2026-77092CRITICALCVSS 9.8EG 9.82026-09-08
Content Extractor contained a deserialization of untrusted data issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update Content Extractor.
- CVE-2026-71374CRITICALCVSS 9.8EG 9.82026-09-08
Deserialization of untrusted data vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 throu…
- CVE-2026-7861CRITICALCVSS 9.8EG 9.82026-09-07
Deserialization of untrusted data vulnerability in Next4Biz Information Technologies Inc. CSM (Customer Service Management) allows Code Injection. This issue affects CSM (Customer Service Management): before 8.0.3.
- CVE-2026-10196CRITICALCVSS 9.8EG 9.82026-09-05
The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.31.0 via deserialization of untrusted input in the 'han…
- CVE-2026-84834CRITICALCVSS 9.8EG 9.82026-09-03
Unauthenticated PHP Object Injection in JobSearch <= 3.2.0 versions.
- CVE-2026-84753CRITICALCVSS 9.8EG 9.82026-09-03
Unauthenticated PHP Object Injection in Mail Mint <= 1.31.0 versions.
- CVE-2026-82226CRITICALCVSS 9.8EG 9.82026-08-31
Unauthenticated PHP Object Injection in Tickera <= 3.6.0.2 versions.
- CVE-2026-78032CRITICALCVSS 9.8EG 9.82026-08-28
SOY CMS contains an issue with deserialization of untrusted data. An arbitrary code may be executed by an attacker with the web server privilege.
- CVE-2026-78292CRITICALCVSS 9.8EG 9.82026-08-27
Unauthenticated PHP Object Injection in Hash Form <= 1.4.1 versions.
- CVE-2026-78286CRITICALCVSS 9.8EG 9.82026-08-27
Unauthenticated PHP Object Injection in Geo Controller <= 8.9.8 versions.
- CVE-2026-47875CRITICALCVSS 9.8EG 9.82026-08-27
Applications that deserialize execution contexts with Jackson2ExecutionContextStringSerializer are vulnerable to a deserialization attack if they use an untrusted data source for the job repository. The JobParameterDeserializer does not pr…
- CVE-2026-47864CRITICALCVSS 9.8EG 9.82026-08-27
SerializingHttpMessageConverter deserializes the body of incoming HTTP requests with a raw java.io.ObjectInputStream and no class filtering. Any request with Content-Type application/x-java-serialized-object whose body resolves to a Serial…
- CVE-2026-80428CRITICALCVSS 9.8EG 9.82026-08-26
ILIAS before versions 9.22, 10.10, and 11.3 contains an unauthenticated PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting serialized objects through the LTI authentication endpo…
- CVE-2026-79657CRITICALCVSS 9.8EG 9.82026-08-25
NLTK versions before 3.10.3 contain a remote code execution vulnerability in allowlisted pickle loaders that trust entire module namespaces instead of specific safe callables. Attackers can craft malicious pickle payloads invoking dangerou…
- CVE-2026-51368CRITICALCVSS 9.8EG 9.82026-08-25
An issue in Beijing Tongtech Co., Ltd tongweb v.7.0.24 in the Spring HttpInovkerServiceExporter component allows a remote attacker to execute arbitrary code via a crafted request to the console/heimdall endpoint
- CVE-2026-78265CRITICALCVSS 9.8EG 9.82026-08-24
Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions.
- CVE-2026-78262CRITICALCVSS 9.8EG 9.82026-08-24
Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions.
- CVE-2026-32563CRITICALCVSS 9.8EG 9.82026-08-24
Subscriber PHP Object Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.
- CVE-2026-66650CRITICALCVSS 9.8EG 9.82026-08-24
Unauthenticated PHP Object Injection in FreightCo <= 1.1.15 versions.
- CVE-2026-4703CRITICALCVSS 9.8EG 9.82026-08-22
The WS Form LITE – Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.10.80 via deserialization of untrusted input from form submission meta values. This ma…
- CVE-2026-73993CRITICALCVSS 9.8EG 9.82026-08-20
Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.
- CVE-2026-66672CRITICALCVSS 9.8EG 9.82026-08-20
Unauthenticated PHP Object Injection in Flatastic <= 2.0 versions.
- CVE-2026-66583CRITICALCVSS 9.8EG 9.82026-08-20
Unauthenticated PHP Object Injection in Forminator <= 1.57.0 versions.
- CVE-2026-76850CRITICALCVSS 9.8EG 9.82026-08-19
LMDeploy deserializes disaggregated-serving peer messages with pickle. The handle_zmq_recv coroutine in lmdeploy/pytorch/disagg/conn/engine_conn.py reads peer-to-peer cache-free requests with recv_pyobj(), which deserializes the received b…
- CVE-2026-73389CRITICALCVSS 9.8EG 9.82026-08-19
Unauthenticated PHP Object Injection in Kalles Addons <= 1.0.6 versions.
- CVE-2026-73364CRITICALCVSS 9.8EG 9.82026-08-19
Customer PHP Object Injection in Flexible Subscriptions <= 1.8.1 versions.
- CVE-2026-73397CRITICALCVSS 9.8EG 9.82026-08-18
Unauthenticated Deserialization of untrusted data in Youzify <= 1.3.7 versions.
- CVE-2026-73380CRITICALCVSS 9.8EG 9.82026-08-18
Unauthenticated PHP Object Injection in Popup by Supsystic <= 1.13.0 versions.
- CVE-2026-73376CRITICALCVSS 9.8EG 9.82026-08-18
Unauthenticated PHP Object Injection in Ultimate Maps by Supsystic < 1.5.0 versions.
- CVE-2026-73366CRITICALCVSS 9.8EG 9.82026-08-18
Unauthenticated PHP Object Injection in Easy Google Maps <= 1.13.0 versions.
- CVE-2026-73341CRITICALCVSS 9.8EG 9.82026-08-18
Unauthenticated PHP Object Injection in RegistrationMagic <= 6.0.9.7 versions.
- CVE-2026-32470CRITICALCVSS 9.8EG 9.82026-08-18
Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.
- CVE-2024-13784CRITICALCVSS 9.8EG 9.82026-08-16
The Contact Form, Survey, Quiz & Popup Form Builder – ARForms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.8.5 via deserialization of untrusted input from form submissions. This makes…
- CVE-2026-28149CRITICALCVSS 9.8EG 9.82026-08-13
Unauthenticated PHP Object Injection in Headless Single Sign On <= 1.6 versions.
- CVE-2026-59124CRITICALCVSS 9.8EG 9.82026-08-11
Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to execute code over a network.
- CVE-2026-71558CRITICALCVSS 9.8EG 9.82026-08-07
Heap type confusion vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0. A crafted input payload can bypass type compatibility checks during polymorphic smart-pointer dese…
- CVE-2026-16258CRITICALCVSS 9.8EG 9.82026-08-07
The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deserialization of untrusted input, allowing unauthenticated attackers to perform PHP Object Injection. When a suitable POP chain is present via another installed Aj…
- CVE-2026-65581CRITICALCVSS 9.8EG 9.82026-08-06
Unauthenticated PHP Object Injection in AI ANN <= 1.29.0 versions.
- CVE-2026-65579CRITICALCVSS 9.8EG 9.82026-08-06
Unauthenticated PHP Object Injection in Agricola <= 1.21.0 versions.
- CVE-2026-65578CRITICALCVSS 9.8EG 9.82026-08-06
Unauthenticated PHP Object Injection in Agora <= 1.9 versions.
- CVE-2026-65577CRITICALCVSS 9.8EG 9.82026-08-06
Unauthenticated PHP Object Injection in Advice <= 1.18.0 versions.
- CVE-2026-65576CRITICALCVSS 9.8EG 9.82026-08-06
Unauthenticated PHP Object Injection in Adrena <= 1.2.14 versions.
- CVE-2026-65575CRITICALCVSS 9.8EG 9.82026-08-06
Unauthenticated PHP Object Injection in Accalia <= 1.5.3 versions.
- CVE-2026-65574CRITICALCVSS 9.8EG 9.82026-08-06
Unauthenticated PHP Object Injection in Abogado <= 1.18 versions.
- CVE-2026-65573CRITICALCVSS 9.8EG 9.82026-08-06
Unauthenticated PHP Object Injection in Abelle <= 1.22 versions.
- CVE-2026-65572CRITICALCVSS 9.8EG 9.82026-08-06
Unauthenticated PHP Object Injection in A.Williams <= 1.3.1 versions.
- CVE-2026-65571CRITICALCVSS 9.8EG 9.82026-08-06
Unauthenticated PHP Object Injection in 69 Clothing <= 1.2.11.1 versions.
- CVE-2026-65556CRITICALCVSS 9.8EG 9.82026-08-06
Unauthenticated PHP Object Injection in WPBruiser {no- Captcha anti-Spam} <= 3.1.43 versions.
Map vulnerabilities like CWE-502 to your infrastructure
EchelonGraph correlates every CVE — across CWE-502 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →