CWE-502— Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.— MITRE CWE catalog
3,290 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-502page 55 of 66
- CVE-2026-27082CRITICALCVSS 9.8EG 9.82026-03-25
Deserialization of Untrusted Data vulnerability in ThemeREX Love Story lovestory allows Object Injection.This issue affects Love Story: from n/a through <= 1.3.12.
- CVE-2026-27083CRITICALCVSS 9.8EG 9.82026-03-25
Deserialization of Untrusted Data vulnerability in ThemeREX Work & Travel Company work-travel-company allows Object Injection.This issue affects Work & Travel Company: from n/a through <= 1.2.
- CVE-2026-27084CRITICALCVSS 9.8EG 9.82026-03-25
Deserialization of Untrusted Data vulnerability in ThemeREX Buisson buisson allows Object Injection.This issue affects Buisson: from n/a through <= 1.1.11.
- CVE-2026-27095CRITICALCVSS 9.8EG 9.82026-03-25
Deserialization of Untrusted Data vulnerability in magepeopleteam Bus Ticket Booking with Seat Reservation bus-ticket-booking-with-seat-reservation allows Object Injection.This issue affects Bus Ticket Booking with Seat Reservation: from n…
- CVE-2026-27096HIGHCVSS 8.1EG 8.12026-03-19
Deserialization of Untrusted Data vulnerability in BuddhaThemes ColorFolio - Freelance Designer WordPress Theme allows Object Injection.This issue affects ColorFolio - Freelance Designer WordPress Theme: from n/a through 1.3.
- CVE-2026-27098HIGHCVSS 8.1EG 8.12026-03-05
Deserialization of Untrusted Data vulnerability in axiomthemes Au Pair Agency - Babysitting & Nanny Theme au-pair-agency allows Object Injection.This issue affects Au Pair Agency - Babysitting & Nanny Theme: from n/a through <= 1.2.2.
- CVE-2026-27172HIGHCVSS 8.8EG 8.82026-04-27
The ConsulRegistry in the camel-consul component (class org.apache.camel.component.consul.ConsulRegistry and its inner ConsulRegistryUtils.deserialize method) read Java-serialized values from the Consul KV store and passed them to ObjectIn…
- CVE-2026-27206HIGHCVSS 8.1EG 8.12026-02-21
Zumba Json Serializer is a library to serialize PHP variables in JSON format. In versions 3.2.2 and below, the library allows deserialization of PHP objects from JSON using a special @type field. The deserializer instantiates any class spe…
- CVE-2026-27303CRITICALCVSS 9.6EG 9.62026-04-14
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user i…
- CVE-2026-27333HIGHCVSS 8.1EG 8.12026-06-15
Unauthenticated Deserialization of untrusted data in Paid Videochat Turnkey Site <= 7.3.23 versions.
- CVE-2026-27338HIGHCVSS 8.8EG 8.82026-03-05
Deserialization of Untrusted Data vulnerability in AivahThemes Car Zone carzone allows Object Injection.This issue affects Car Zone: from n/a through <= 3.7.
- CVE-2026-27369HIGHCVSS 8.1EG 8.12026-03-05
Deserialization of Untrusted Data vulnerability in BoldThemes Celeste celeste allows Object Injection.This issue affects Celeste: from n/a through <= 1.3.6.
- CVE-2026-27379HIGHCVSS 8.8EG 8.82026-03-05
Deserialization of Untrusted Data vulnerability in NextScripts NextScripts social-networks-auto-poster-facebook-twitter-g allows Object Injection.This issue affects NextScripts: from n/a through <= 4.4.7.
- CVE-2026-27380HIGHCVSS 7.2EG 7.22026-08-13
Editor PHP Object Injection in Car Rental Manager <= 1.3.9 versions.
- CVE-2026-27410MEDIUMCVSS 6.5EG 6.52026-06-17
Unauthenticated Deserialization of untrusted data in Slimstat Analytics < 5.4.0 versions.
- CVE-2026-27414HIGHCVSS 8.8EG 8.82026-07-02
Contributor PHP Object Injection in Werkstatt <= 4.8.3 versions.
- CVE-2026-27417CRITICALCVSS 9.8EG 9.82026-03-05
Deserialization of Untrusted Data vulnerability in SeventhQueen Sweet Date sweetdate allows Object Injection.This issue affects Sweet Date: from n/a through < 4.0.1.
- CVE-2026-27429CRITICALCVSS 9.8EG 9.82026-06-17
Unauthenticated PHP Object Injection in Nifty <= 1.4.1 versions.
- CVE-2026-27437CRITICALCVSS 9.8EG 9.82026-03-05
Deserialization of Untrusted Data vulnerability in ThemeREX Tennis Club tennis-sportclub allows Object Injection.This issue affects Tennis Club: from n/a through <= 1.2.3.
- CVE-2026-27438CRITICALCVSS 9.8EG 9.82026-03-05
Deserialization of Untrusted Data vulnerability in ThemeREX Kingler kingler allows Object Injection.This issue affects Kingler: from n/a through <= 1.7.
- CVE-2026-27439CRITICALCVSS 9.8EG 9.82026-03-05
Deserialization of Untrusted Data vulnerability in ThemeREX Dentario dentario allows Object Injection.This issue affects Dentario: from n/a through <= 1.5.
- CVE-2026-27475HIGHCVSS 8.1EG 8.12026-02-19
SPIP before 4.4.9 allows Insecure Deserialization in the public area through the table_valeur filter and the DATA iterator, which accept serialized data. An attacker who can place malicious serialized content (a pre-condition requiring pri…
- CVE-2026-27685CRITICALCVSS 9.1EG 9.12026-03-10
SAP NetWeaver Enterprise Portal Administration is vulnerable if a privileged user uploads untrusted or malicious content that, upon deserialization, could result in a high impact on the confidentiality, integrity, and availability of the h…
- CVE-2026-27727CRITICALCVSS 9.8EG 9.82026-02-25
mchange-commons-java, a library that provides Java utilities, includes code that mirrors early implementations of JNDI functionality, including support for remote `factoryClassLocation` values, by which code can be downloaded and invoked w…
- CVE-2026-27749HIGHCVSS 7.8EG 7.82026-03-05
Avira Internet Security contains a deserialization of untrusted data vulnerability in the System Speedup component. The Avira.SystemSpeedup.RealTimeOptimizer.exe process, which runs with SYSTEM privileges, deserializes data from a file loc…
- CVE-2026-27776HIGHCVSS 8.8EG 8.82026-02-27
IM-LogicDesigner module of intra-mart Accel Platform contains insecure deserialization issue. This can be exploited only when IM-LogicDesigner is deployed on the system. Arbitrary code may be executed when some crafted file is imported by …
- CVE-2026-27794MEDIUMCVSS 6.6EG 6.62026-02-25
LangGraph Checkpoint defines the base interface for LangGraph checkpointers. Prior to version 4.0.0, a Remote Code Execution vulnerability exists in LangGraph's caching layer when applications enable cache backends that inherit from `BaseC…
- CVE-2026-27830HIGHCVSS 8.0EG 8.02026-02-26
c3p0, a JDBC Connection pooling library, is vulnerable to attack via maliciously crafted Java-serialized objects and `javax.naming.Reference` instances. Several c3p0 `ConnectionPoolDataSource` implementations have a property called `userOv…
- CVE-2026-27971CRITICALCVSS 9.8EG 9.82026-03-03
Qwik is a performance focused javascript framework. qwik <=1.19.0 is vulnerable to RCE due to an unsafe deserialization vulnerability in the server$ RPC mechanism that allows any unauthenticated user to execute arbitrary code on the server…
- CVE-2026-28074CRITICALCVSS 9.8EG 9.82026-03-05
Deserialization of Untrusted Data vulnerability in ThemeREX Pizza House pizzahouse allows Object Injection.This issue affects Pizza House: from n/a through <= 1.4.0.
- CVE-2026-28105CRITICALCVSS 9.8EG 9.82026-03-05
Deserialization of Untrusted Data vulnerability in ThemeREX Good Energy goodenergy allows Object Injection.This issue affects Good Energy: from n/a through <= 1.7.7.
- CVE-2026-28138HIGHCVSS 7.2EG 7.22026-02-26
Deserialization of Untrusted Data vulnerability in Stylemix uListing ulisting allows Object Injection.This issue affects uListing: from n/a through <= 2.2.0.
- CVE-2026-28139CRITICALCVSS 9.8EG 9.82026-08-06
Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions.
- CVE-2026-28149CRITICALCVSS 9.8EG 9.82026-08-13
Unauthenticated PHP Object Injection in Headless Single Sign On <= 1.6 versions.
- CVE-2026-28176HIGHCVSS 8.8EG 8.82026-08-13
Unauthenticated PHP Object Injection in Booking Activities <= 1.18.4 versions.
- CVE-2026-28220CRITICALCVSS 9.1EG 9.12026-07-20
Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to version 4.14.5, issues in the Cluster Distributed API (DAPI) handling allow a cluster peer, or any actor able to authenticate to the clu…
- CVE-2026-28277HIGHCVSS 7.2EG 7.22026-03-05
LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). In version 1.0.9 and prior, LangGraph checkpointers can load msgpack-encoded checkpoints that reconstru…
- CVE-2026-2898MEDIUMCVSS 6.5EG 6.52026-02-22
A vulnerability was detected in funadmin up to 7.1.0-rc4. This issue affects the function getMember of the file app/common/service/AuthCloudService.php of the component Backend Endpoint. The manipulation of the argument cloud_account resul…
- CVE-2026-29109HIGHCVSS 7.2EG 7.22026-03-20
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions up to and including 8.9.2 contain an unsafe deserialization vulnerability in the SavedSearch filter processing component tha…
- CVE-2026-2970HIGHCVSS 7.5EG 7.52026-02-23
A vulnerability has been found in datapizza-labs datapizza-ai 0.0.2. Affected by this vulnerability is the function RedisCache of the file datapizza-ai-cache/redis/datapizza/cache/redis/cache.py. Such manipulation leads to deserialization.…
- CVE-2026-29782HIGHCVSS 7.2EG 7.22026-04-02
OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.10.2, the oauth2.php file in OpenSTAManager is an unauthenticated endpoint ($skip_permissions = true). It loads a record from t…
- CVE-2026-3017HIGHCVSS 7.2EG 7.22026-04-14
The Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.0.12 via deserialization of untrusted input in the import…
- CVE-2026-3048MEDIUMCVSS 5.1EG 5.12026-05-11
An authenticated administrator who configures or tests LDAP connectivity in Sonatype Nexus Repository Manager versions 3.0.0 through 3.91.1 may be able to initiate unintended server-side connections when interacting with a malicious LDAP s…
- CVE-2026-3059CRITICALCVSS 9.8EG 9.82026-03-12
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker, which deserializes untrusted data using pickle.loads() without authentication.
- CVE-2026-3060CRITICALCVSS 9.8EG 9.82026-03-12
SGLang' encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module, which deserializes untrusted data using pickle.loads() without authentication.
- CVE-2026-3071HIGHCVSS 8.4EG 8.42026-02-26
Deserialization of untrusted data in the LanguageModel class of Flair from versions 0.4.1 to latest are vulnerable to arbitrary code execution when loading a malicious model.
- CVE-2026-31072CRITICALCVSS 9.8EG 9.82026-05-19
The JSONSerializer and CBORSerializer in APScheduler (all versions including 3.10.x and 4.0.0a5) are vulnerable to Remote Code Execution (RCE) via Insecure Deserialization. The unmarshal_object function allows for arbitrary class instantia…
- CVE-2026-31214CRITICALCVSS 9.8EG 9.82026-05-12
The torch-checkpoint-shrink.py script in the ml-engineering project in commit 0099885db36a8f06556efe1faf552518852cb1e0 (2025-20-27) contains an insecure deserialization vulnerability (CWE-502). The script uses torch.load() to process PyTor…
- CVE-2026-31218HIGHCVSS 8.8EG 8.82026-05-12
The _load_model() function in the neural_magic_training.py script of the optimate project in commit a6d302f912b481c94370811af6b11402f51d377f (2024-07-21) is vulnerable to insecure deserialization (CWE-502). When loading a model state dicti…
- CVE-2026-31219HIGHCVSS 8.8EG 8.82026-05-12
The _load_model() function in the neural_magic_training.py script of the optimate project in commit a6d302f912b481c94370811af6b11402f51d377f (2024-07-21) is vulnerable to insecure deserialization (CWE-502). When a user provides a single mo…
Map vulnerabilities like CWE-502 to your infrastructure
EchelonGraph correlates every CVE — across CWE-502 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →