CWE-502— Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.— MITRE CWE catalog
3,159 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-502page 63 of 64
- CVE-2026-73364CRITICALCVSS 9.8EG 9.82026-08-19
Customer PHP Object Injection in Flexible Subscriptions <= 1.8.1 versions.
- CVE-2026-73366CRITICALCVSS 9.8EG 9.82026-08-18
Unauthenticated PHP Object Injection in Easy Google Maps <= 1.13.0 versions.
- CVE-2026-73376CRITICALCVSS 9.8EG 9.82026-08-18
Unauthenticated PHP Object Injection in Ultimate Maps by Supsystic < 1.5.0 versions.
- CVE-2026-73380CRITICALCVSS 9.8EG 9.82026-08-18
Unauthenticated PHP Object Injection in Popup by Supsystic <= 1.13.0 versions.
- CVE-2026-73389CRITICALCVSS 9.8EG 9.82026-08-19
Unauthenticated PHP Object Injection in Kalles Addons <= 1.0.6 versions.
- CVE-2026-73397CRITICALCVSS 9.8EG 9.82026-08-18
Unauthenticated Deserialization of untrusted data in Youzify <= 1.3.7 versions.
- CVE-2026-73993CRITICALCVSS 9.8EG 9.82026-08-20
Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.
- CVE-2026-74012HIGHCVSS 8.8EG 8.82026-08-18
Deserialization of Untrusted Data vulnerability in TaxoPress allows Object Injection. This issue affects TaxoPress: from n/a through 3.51.0.
- CVE-2026-7566MEDIUMCVSS 6.6EG 6.62026-06-06
The LearnPress – Backup & Migration Tool plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.1.4 via deserialization of untrusted input . This makes it possible for authenticated attackers, …
- CVE-2026-7584HIGHCVSS 7.8EG 7.82026-05-01
The LabOne Q serialization framework uses a class-loading mechanism (import_cls) to dynamically import and instantiate Python classes during deserialization. Prior to the fix, this mechanism accepted arbitrary fully-qualified class names f…
- CVE-2026-7597MEDIUMCVSS 6.3EG 6.32026-05-01
A vulnerability was found in mem0ai mem0 up to 1.0.11. This affects the function pickle.load/pickle.dump of the file mem0/vector_stores/faiss.py. Performing a manipulation results in deserialization. It is possible to initiate the attack r…
- CVE-2026-75987HIGHCVSS 7.3EG 7.32026-08-19
A vulnerability was found in SPLWare esProc up to 20260507. This affects the function ObjectInputStream.readUnshared of the file src/main/java/com/scudata/parallel/SocketData.java. Performing a manipulation results in deserialization. Remo…
- CVE-2026-7635HIGHCVSS 8.1EG 8.12026-05-13
The coreActivity: Activity Logging for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.0. This is due to the plugin failing to validate or strip PHP serialization syntax from the…
- CVE-2026-7637CRITICALCVSS 9.8EG 9.82026-05-20
The Boost plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.0.3 via deserialization of untrusted input in the STYXKEY-BOOST_USER_LOCATION cookie. This makes it possible for unauthenticated attac…
- CVE-2026-76395HIGHCVSS 8.8EG 8.82026-08-19
In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could execute arbitrary code on the Splunk server by loading a model file containing crafted sparse matrix data. The deserialization of untrusted data is p…
- CVE-2026-76404CRITICALCVSS 9.1EG 9.12026-08-19
In Splunk MCP Server app versions below 1.2.1, a user who holds the "admin" Splunk role could execute arbitrary commands on the underlying operating system. The vulnerability is possible because of missing input validation in the app's cre…
- CVE-2026-7647HIGHCVSS 8.1EG 8.12026-05-02
The Profile Builder Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to and including 3.14.5. This is due to the use of PHP's maybe_unserialize() function on the attacker-controlled 'args' POST parameter wi…
- CVE-2026-7654HIGHCVSS 8.8EG 8.82026-06-05
The Admin Columns plugin for WordPress is vulnerable to PHP Object Injection leading to Remote Code Execution in versions up to and including 7.0.18. This is due to the use of `unserialize()` without an `allowed_classes` restriction in the…
- CVE-2026-76843HIGHCVSS 7.8EG 7.82026-08-24
The official Flair wheels for 0.15.0 and 0.15.1 still contain flair/models/clustering.py, whose ClusteringModel.load static method returns pickle.loads(joblib.load(str(model_file))) and so executes arbitrary Python while loading a model fi…
- CVE-2026-76850CRITICALCVSS 9.8EG 9.82026-08-19
LMDeploy deserializes disaggregated-serving peer messages with pickle. The handle_zmq_recv coroutine in lmdeploy/pytorch/disagg/conn/engine_conn.py reads peer-to-peer cache-free requests with recv_pyobj(), which deserializes the received b…
- CVE-2026-7712MEDIUMCVSS 6.3EG 6.32026-05-04
A security vulnerability has been detected in MindsDB up to 26.01. Affected is the function pickle.loads of the component Pickle Handler. The manipulation leads to deserialization. The attack is possible to be carried out remotely. The exp…
- CVE-2026-77138CRITICALCVSS 9.3EG 9.32026-08-25
The extension fails to safely process untrusted client input of an attacker-controlled cookie directly to PHP's unserialize(). A remote, unauthenticated attacker can supply a crafted serialized payload to trigger PHP Object Injection, lead…
- CVE-2026-77645CRITICALCVSS 9.2EG 9.22026-08-20
A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.
- CVE-2026-77646HIGHCVSS 7.7EG 7.72026-08-20
A Server-Side Request Forgery (SSRF) vulnerability has been reported in PTC Windchill PDMLink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.
- CVE-2026-78032CRITICALCVSS 9.8EG 9.82026-08-28
SOY CMS contains an issue with deserialization of untrusted data. An arbitrary code may be executed by an attacker with the web server privilege.
- CVE-2026-78147HIGHCVSS 7.3EG 7.32026-08-23
A vulnerability was found in ggml-org llama.cpp bec4772f6. The impacted element is the function deserialize_tensor of the file ggml/src/ggml-rpc/ggml-rpc.cpp of the component ggml-RPC Server. Performing a manipulation of the argument op/op…
- CVE-2026-7818HIGHCVSS 7.0EG 7.02026-05-11
Deserialization of untrusted data (CWE-502) in pgAdmin 4 FileBackedSessionManager. The session manager performed unsafe deserialization of session-file contents (using Python's standard object-serialization module) before performing any H…
- CVE-2026-78257HIGHCVSS 8.8EG 8.82026-08-27
Contributor PHP Object Injection in Booking and Rental Manager <= 2.7.5 versions.
- CVE-2026-78262CRITICALCVSS 9.8EG 9.82026-08-24
Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions.
- CVE-2026-78265CRITICALCVSS 9.8EG 9.82026-08-24
Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions.
- CVE-2026-78276HIGHCVSS 7.2EG 7.22026-08-27
Editor PHP Object Injection in Fluent Boards Pro <= 2.0.11 versions.
- CVE-2026-78286CRITICALCVSS 9.8EG 9.82026-08-27
Unauthenticated PHP Object Injection in Geo Controller <= 8.9.8 versions.
- CVE-2026-78292CRITICALCVSS 9.8EG 9.82026-08-27
Unauthenticated PHP Object Injection in Hash Form <= 1.4.1 versions.
- CVE-2026-78572HIGHCVSS 8.1EG 8.12026-08-25
The Kalles Addons plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.6 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. N…
- CVE-2026-7858CRITICALCVSS 9.8EG 9.82026-06-01
A Deserialization of Untrusted Data vulnerability affecting Teamwork Cloud from No Magic Release 2022x through No Magic Release 2026x and Magic Collaboration Studio from CATIA Magic Release 2022x through CATIA Magic Release 2026x could lea…
- CVE-2026-78612HIGHCVSS 8.6EG 8.62026-08-27
WatchGuard Dimension contains an authenticated SQL injection vulnerability in the scheduled report feature which allows an authenticated user with report administration permissions gain arbitrary command execution as the Dimension WebUI pr…
- CVE-2026-78614HIGHCVSS 8.6EG 8.62026-08-27
WatchGuard Dimension contains an authenticated SQL injection vulnerability in the audit report feature which allows an authenticated user with report administration permissions gain arbitrary command execution as the Dimension WebUI proces…
- CVE-2026-78683CRITICALCVSS 9.6EG 9.62026-08-25
NLTK before 3.10.0 (affected versions <=3.9.4) contains an unsafe pickle deserialization vulnerability in the TransitionParser.parse() method (nltk/parse/transitionparser.py). The method calls pickle_load() with the default restricted=Fals…
- CVE-2026-7871CRITICALCVSS 9.8EG 9.82026-06-30
IBM Langflow OSS 1.0.0 through 1.10.0 allows users with Redis access to execute arbitrary code with full application privileges, compromising all secrets, data, and system integrity.
- CVE-2026-7888HIGHCVSS 8.4EG 8.42026-06-03
Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the Workflow, Form block, and File/Set components that lack the allowed_classes restriction. An unauthenticated attacker may trigger arbitrary PHP ob…
- CVE-2026-79657CRITICALCVSS 9.8EG 9.82026-08-25
NLTK versions before 3.10.3 contain a remote code execution vulnerability in allowlisted pickle loaders that trust entire module namespaces instead of specific safe callables. Attackers can craft malicious pickle payloads invoking dangerou…
- CVE-2026-8024CRITICALCVSS 9.8EG 9.82026-06-18
A remote, unauthenticated attacker may exploit a deserialization of untrusted data vulnerability in ibaPDA or ibaDatCoordinator to gain full access to the affected systems.
- CVE-2026-80428CRITICALCVSS 9.8EG 9.82026-08-26
ILIAS deserialises stored session data for an unauthenticated caller. The Shibboleth back-channel endpoint at components/ILIAS/AuthShibboleth/resources/shib_logout.php runs in a context that ilInitialisation exempts from authentication, an…
- CVE-2026-8135HIGHCVSS 7.2EG 7.22026-05-21
Concrete CMS 9.5.0 and below is vulnerable to Remote Code Execution due to insecure deserialization occurring in the ExpressEntryList block controller. An rogue administrator with privileges to add blocks to an area can bypass the inten…
- CVE-2026-81757HIGHCVSS 7.2EG 7.22026-08-28
Author Remote Code Execution (RCE) in Rank Math SEO <= 1.0.276 versions.
- CVE-2026-82222CRITICALCVSS 10.0EG 10.02026-08-28
Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP GiveWP allows Object Injection. This issue affects GiveWP: from n/a through 4.16.7.1.
- CVE-2026-82259HIGHCVSS 7.5EG 7.52026-08-28
SvelteKit versions from 2.49.0 through 2.53.2 (fixed in 2.53.3) contain a deserialization expansion issue in the experimental form remote function. When an application enables experimental.remoteFunctions and uses the form function to proc…
- CVE-2026-8365HIGHCVSS 8.8EG 8.82026-06-09
The Blocksy theme for WordPress is vulnerable to PHP Object Injection leading to Remote Code Execution via the 'blocksy_meta' REST API field and the V200 database migration in versions up to and including 2.1.35. This is due to insufficien…
- CVE-2026-8476CRITICALCVSS 9.9EG 9.92026-07-17
IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the disk-based caching mechanism. The AsyncDiskCache class uses Python's unsafe pickle.loads() function to deserialize cached objects from dis…
- CVE-2026-8612MEDIUMCVSS 5.3EG 5.32026-05-15
WWW::Mechanize::Cached versions before 2.00 for Perl deserialize cached HTTP responses from a world-writable on-disk cache, enabling local response forgery and code execution. With no explicit cache backend, WWW::Mechanize::Cached constru…
Map vulnerabilities like CWE-502 to your infrastructure
EchelonGraph correlates every CVE — across CWE-502 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →