CWE-502— Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.— MITRE CWE catalog
3,290 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-502page 50 of 66
- CVE-2026-0677HIGHCVSS 6.3EG 7.22026-03-20
Deserialization of Untrusted Data vulnerability in TotalSuite TotalContest Lite totalcontest-lite allows Object Injection.This issue affects TotalContest Lite: from n/a through <= 2.9.1.
- CVE-2026-0726HIGHCVSS 8.1EG 8.12026-01-20
The Nexter Extension – Site Enhancements Toolkit plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.4.6 via deserialization of untrusted input in the 'nxt_unserialize_replace' function. Thi…
- CVE-2026-0760CRITICALCVSS 9.8EG 9.82026-01-23
Foundation Agents MetaGPT deserialize_message Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foundation Agents MetaGP…
- CVE-2026-0762HIGHCVSS 8.1EG 8.12026-01-23
GPT Academic stream_daas Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GPT Academic. Interaction with a malicious DA…
- CVE-2026-0763CRITICALCVSS 9.8EG 9.82026-01-23
GPT Academic run_in_subprocess_wrapper_func Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GPT Academic. Authenticati…
- CVE-2026-0764CRITICALCVSS 9.8EG 9.82026-01-23
GPT Academic upload Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GPT Academic. Authentication is not required to ex…
- CVE-2026-0772HIGHCVSS 7.5EG 7.52026-01-23
Langflow Disk Cache Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Authentication is required to exploit th…
- CVE-2026-0773CRITICALCVSS 9.8EG 9.82026-01-23
Upsonic Cloudpickle Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Upsonic. Authentication is not required to exploit…
- CVE-2026-0859HIGHCVSS 7.8EG 7.82026-01-13
TYPO3's mail‑file spool deserialization flaw lets local users with write access to the spool directory craft a malicious file that is deserialized during the mailer:spool:send command, enabling arbitrary PHP code execution on the web ser…
- CVE-2026-0895MEDIUMCVSS 5.2EG 5.22026-01-20
The extension extends TYPO3’ FileSpool component, which was vulnerable to Insecure Deserialization prior to TYPO3-CORE-SA-2026-004 https://typo3.org/security/advisory/typo3-core-sa-2026-004 . Since the related fix is overwritten by the …
- CVE-2026-0910HIGHCVSS 8.8EG 8.82026-02-11
The wpForo Forum plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.4.13 via deserialization of untrusted input in the 'wpforo_display_array_data' function. This makes it possible for authent…
- CVE-2026-10035MEDIUMCVSS 6.6EG 6.62026-08-16
The Turnkey bbPress by WeaverTheme plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.7.1 via deserialization of untrusted input in the wvrbbp_set_to_serialized_values() function (reached thr…
- CVE-2026-10036HIGHCVSS 8.8EG 8.82026-08-27
SpeechBrain before 1.1.1 contains an arbitrary code execution vulnerability that allows attackers to execute arbitrary code by supplying a crafted CKPT.yaml checkpoint metadata file parsed with PyYAML's unsafe loader during candidate enume…
- CVE-2026-10042CRITICALCVSS 9.8EG 9.82026-05-29
manga-image-translator contains a remote code execution vulnerability in the shared API server mode due to unsafe deserialization of untrusted pickle data in the share.py module, where the /execute/{method_name} and /simple_execute/{method…
- CVE-2026-10043HIGHCVSS 7.8EG 7.82026-06-24
MosaicML Composer Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of MosaicML Composer. User interaction is required to e…
- CVE-2026-10196CRITICALCVSS 9.8EG 9.82026-09-05
The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.31.0 via deserialization of untrusted input in the 'han…
- CVE-2026-10532LOWCVSS 2.9EG 2.92026-06-01
Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-core) modules) allows Object Injection, albeit heavily restricted. More precisely, an attacker able to influence seria…
- CVE-2026-10538HIGHCVSS 8.0EG 8.02026-07-01
Messaging consumer functionality allows deserialization of user-controlled data without sufficient restriction of allowed object types in the out of support Control-M/Server and Control-M/Enterprise Manager versions 9.0.20.x and potentiall…
- CVE-2026-10566MEDIUMCVSS 5.3EG 5.32026-06-02
A weakness has been identified in FoundationAgents MetaGPT up to 0.8.2. This affects the function Message.check_instruct_content of the file metagpt/schema.py. Executing a manipulation of the argument mapping can lead to deserialization. T…
- CVE-2026-10571MEDIUMCVSS 5.3EG 5.72026-08-13
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by a denial of service caused by insecure deserialization. A low-privileged, administrative user could exploit this vulnerability to consume system resources …
- CVE-2026-10721HIGHCVSS 8.4EG 8.42026-06-10
Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the in Permission, Cache, and Search components. An unauthenticated attacker may trigger arbitrary PHP object instantiation if a malicious seri…
- CVE-2026-10748HIGHCVSS 8.6EG 8.62026-06-16
An authenticated user with the nx-licensing-create privilege can upload a specially crafted license file to execute arbitrary operating system commands as the Nexus process user in Sonatype Nexus Repository 3 versions before 3.92.0.
- CVE-2026-10751HIGHCVSS 7.5EG 7.52026-09-18
IBM MQ Java and JMS client libraries could allow an authenticated attacker to execute arbitrary code on client applications due to a deserialization filter bypass in exception handling.
- CVE-2026-11363MEDIUMCVSS 6.6EG 6.62026-09-09
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.14.6 via deserialization of untrusted input . This makes it possible for au…
- CVE-2026-11536HIGHCVSS 8.5EG 8.52026-07-30
IBM WebSphere Application Server 9.0, and 8.5 is affected by a remote code execution vulnerability in the SOAP/JMX connector.
- CVE-2026-11711MEDIUMCVSS 6.5EG 6.52026-09-18
IBM WebSphere Application Server 9.0 and 8.5 is affected by a deserialization vulnerability in the Name Service component.
- CVE-2026-11729HIGHCVSS 8.5EG 8.52026-09-15
IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker to ex…
- CVE-2026-11756CRITICALCVSS 10.0EG 10.02026-07-28
A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could lead to an unauthenticated remote code execution.
- CVE-2026-11815MEDIUMCVSS 5.3EG 5.32026-06-10
An attacker who intercepts and tampers with traffic between the client application and the API Gateway server could potentially deserialize arbitrary objects. This vulnerability could lead to broken security expectations or remote code exe…
- CVE-2026-1184MEDIUMCVSS 6.5EG 6.52026-05-14
GitLab has remediated an issue in GitLab EE affecting all versions from 11.9 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an unauthenticated user to cause denial of service by uploading a specially …
- CVE-2026-11857HIGHCVSS 8.4EG 8.42026-06-17
Quanos SCHEMA ST4 on-premises contains a local privilege escalation vulnerability in the Client Update Service due to insecure deserialization in the .NET Remoting service. The service is configured with TypeFilterLevel.Full and is bound t…
- CVE-2026-11860HIGHCVSS 7.5EG 7.52026-06-15
Quick.CMS deserializes user-controlled data received over plaintext HTTP without ensuring integrity or authenticity. This allows attackers to tamper with serialized payloads in transit and inject malicious objects. Because deserialization …
- CVE-2026-12046CRITICALCVSS 9.0EG 9.02026-06-19
Two state-mutating endpoints in pgAdmin 4's SQL Editor blueprint -- DELETE /sqleditor/close/<trans_id> and POST /sqleditor/initialize/sqleditor/update_connection/<sgid>/<sid>/<did> -- were the only routes in the module missing the @pga_log…
- CVE-2026-12115MEDIUMCVSS 6.6EG 6.62026-06-17
The Counter Box – Add Countdowns, Timers & Dynamic Counters to WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.0.13 via deserialization of untrusted input . This makes it possi…
- CVE-2026-12118CRITICALCVSS 9.8EG 9.82026-07-30
IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to execute arbitrary code on the system due to the deserialization of untrusted data.
- CVE-2026-12191HIGHCVSS 7.8EG 7.82026-06-14
A vulnerability was found in Comma AI Openpilot 0.11. This issue affects the function pickle.load/pickle.loads of the file selfdrive/modeld/modeld.py of the component Pickle Module. The manipulation results in deserialization. The attack i…
- CVE-2026-12240HIGHCVSS 8.0EG 8.02026-06-30
The Export User Data plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the unserialize function in all versions up to, and including, 2.2.6. This makes it possible for authenticated a…
- CVE-2026-12256HIGHCVSS 8.8EG 8.82026-06-17
Contributor PHP Object Injection in Avada <= 3.15.3 versions.
- CVE-2026-1235MEDIUMCVSS 6.5EG 6.52026-02-11
The WP eCommerce WordPress plugin through 3.15.1 unserializes user input via ajax actions, which could allow unauthenticated users to perform PHP Object Injection when a suitable gadget is present on the blog.
- CVE-2026-12481CRITICALCVSS 9.8EG 9.82026-07-03
A vulnerability in keras-team/keras version 3.14.0 allows for arbitrary code execution due to improper handling of deserialization in the `Lambda` layer. Specifically, the `_raise_for_lambda_deserialization()` function fails to enforce the…
- CVE-2026-12484HIGHCVSS 7.8EG 7.82026-07-19
A vulnerability in keras-team/keras version 3.15.0 allows unsafe deserialization of attacker-controlled PyTorch pickle data through the public `keras.layers.TorchModuleWrapper.from_config` method. This method invokes `torch.load(..., weigh…
- CVE-2026-12569CRITICALCVSS 9.8EG 9.8⚠ KEV2026-06-18
A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data. * This advisory also applies to all CPS …
- CVE-2026-12578HIGHCVSS 8.4EG 8.42026-06-30
The affected product is vulnerable to a deserialization of untrusted data, which may allow an attacker to execute arbitrary code.
- CVE-2026-12583HIGHCVSS 8.1EG 8.12026-07-14
The Newsletters WordPress plugin before 4.15 does not prevent deserialization of untrusted input that is stored through a public form, allowing unauthenticated attackers to inject a PHP object and, via a property-oriented gadget chain bund…
- CVE-2026-12648HIGHCVSS 8.8EG 8.82026-09-08
A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.
- CVE-2026-12650CRITICALCVSS 8.8EG 9.92026-09-08
A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.
- CVE-2026-12651HIGHCVSS 8.8EG 8.82026-09-08
A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.
- CVE-2026-12720HIGHCVSS 7.5EG 7.52026-07-31
The Kirki WordPress plugin before 6.0.13 does not restrict which classes may be instantiated when it deserialises data that unauthenticated users can store, leading to PHP Object Injection that is triggered when an administrator later rev…
- CVE-2026-12728HIGHCVSS 8.8EG 8.82026-09-15
IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker to ex…
- CVE-2026-12744CRITICALCVSS 9.8EG 9.82026-09-08
A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticated attacker to execute arbitrary code on the server.
Map vulnerabilities like CWE-502 to your infrastructure
EchelonGraph correlates every CVE — across CWE-502 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →