CWE-502— Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.— MITRE CWE catalog
3,290 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-502page 65 of 66
- CVE-2026-7647HIGHCVSS 8.1EG 8.12026-05-02
The Profile Builder Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to and including 3.14.5. This is due to the use of PHP's maybe_unserialize() function on the attacker-controlled 'args' POST parameter wi…
- CVE-2026-7654HIGHCVSS 8.8EG 8.82026-06-05
The Admin Columns plugin for WordPress is vulnerable to PHP Object Injection leading to Remote Code Execution in versions up to and including 7.0.18. This is due to the use of `unserialize()` without an `allowed_classes` restriction in the…
- CVE-2026-76547MEDIUMCVSS 6.6EG 6.62026-08-29
The User Profile Builder WordPress plugin before 4.0.1 does not validate the type of data being deserialized when importing a configuration file, allowing high privilege users such as administrators to conduct PHP Object Injection. The af…
- CVE-2026-76834HIGHCVSS 8.1EG 8.12026-09-17
b2evolution CMS versions 6.7.8 through 7.2.5 contain an incomplete fix for CVE-2016-8901 where the serialized-array object check in param_check_serialized_array() fails to reject payloads with negative integer array keys. Unauthenticated a…
- CVE-2026-76843HIGHCVSS 7.8EG 7.82026-08-24
The official Flair wheels for 0.15.0 and 0.15.1 still contain flair/models/clustering.py, whose ClusteringModel.load static method returns pickle.loads(joblib.load(str(model_file))) and so executes arbitrary Python while loading a model fi…
- CVE-2026-76850CRITICALCVSS 9.8EG 9.82026-08-19
LMDeploy deserializes disaggregated-serving peer messages with pickle. The handle_zmq_recv coroutine in lmdeploy/pytorch/disagg/conn/engine_conn.py reads peer-to-peer cache-free requests with recv_pyobj(), which deserializes the received b…
- CVE-2026-76967HIGHCVSS 7.8EG 7.82026-09-08
SAP NetWeaver Business Client does not perform sufficient validation when processing certain locally stored data during application startup. An attacker with low privileges on the local system could replace this data with specially crafted…
- CVE-2026-77092CRITICALCVSS 9.8EG 9.82026-09-08
Content Extractor contained a deserialization of untrusted data issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update Content Extractor.
- CVE-2026-7712MEDIUMCVSS 6.3EG 6.32026-05-04
A security vulnerability has been detected in MindsDB up to 26.01. Affected is the function pickle.loads of the component Pickle Handler. The manipulation leads to deserialization. The attack is possible to be carried out remotely. The exp…
- CVE-2026-77138CRITICALCVSS 9.3EG 9.32026-08-25
The extension fails to safely process untrusted client input of an attacker-controlled cookie directly to PHP's unserialize(). A remote, unauthenticated attacker can supply a crafted serialized payload to trigger PHP Object Injection, lead…
- CVE-2026-77484HIGHCVSS 8.8EG 8.82026-09-08
Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network.
- CVE-2026-77645CRITICALCVSS 9.2EG 9.22026-08-20
A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.
- CVE-2026-77646HIGHCVSS 7.7EG 7.72026-08-20
A Server-Side Request Forgery (SSRF) vulnerability has been reported in PTC Windchill PDMLink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.
- CVE-2026-78006CRITICALCVSS 9.8EG 9.82026-09-12
The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.4 via the is_safe_widget_instance function. This is due to insufficient protection in is_safe_widget_instance, w…
- CVE-2026-78032CRITICALCVSS 9.8EG 9.82026-08-28
SOY CMS contains an issue with deserialization of untrusted data. An arbitrary code may be executed by an attacker with the web server privilege.
- CVE-2026-78147HIGHCVSS 7.3EG 7.32026-08-23
A vulnerability was found in ggml-org llama.cpp bec4772f6. The impacted element is the function deserialize_tensor of the file ggml/src/ggml-rpc/ggml-rpc.cpp of the component ggml-RPC Server. Performing a manipulation of the argument op/op…
- CVE-2026-78175HIGHCVSS 8.8EG 8.82026-09-12
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.0.7 via the `withdraw_method_field` parameter of the `tutor_save_withdraw_account` AJ…
- CVE-2026-7818HIGHCVSS 7.0EG 7.02026-05-11
Deserialization of untrusted data (CWE-502) in pgAdmin 4 FileBackedSessionManager. The session manager performed unsafe deserialization of session-file contents (using Python's standard object-serialization module) before performing any H…
- CVE-2026-78257HIGHCVSS 8.8EG 8.82026-08-27
Contributor PHP Object Injection in Booking and Rental Manager <= 2.7.5 versions.
- CVE-2026-78262CRITICALCVSS 9.8EG 9.82026-08-24
Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions.
- CVE-2026-78265CRITICALCVSS 9.8EG 9.82026-08-24
Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions.
- CVE-2026-78276HIGHCVSS 7.2EG 7.22026-08-27
Editor PHP Object Injection in Fluent Boards Pro <= 2.0.11 versions.
- CVE-2026-78286CRITICALCVSS 9.8EG 9.82026-08-27
Unauthenticated PHP Object Injection in Geo Controller <= 8.9.8 versions.
- CVE-2026-78292CRITICALCVSS 9.8EG 9.82026-08-27
Unauthenticated PHP Object Injection in Hash Form <= 1.4.1 versions.
- CVE-2026-7858CRITICALCVSS 9.8EG 9.82026-06-01
A Deserialization of Untrusted Data vulnerability affecting Teamwork Cloud from No Magic Release 2022x through No Magic Release 2026x and Magic Collaboration Studio from CATIA Magic Release 2022x through CATIA Magic Release 2026x could lea…
- CVE-2026-7861CRITICALCVSS 9.8EG 9.82026-09-07
Deserialization of untrusted data vulnerability in Next4Biz Information Technologies Inc. CSM (Customer Service Management) allows Code Injection. This issue affects CSM (Customer Service Management): before 8.0.3.
- CVE-2026-78612HIGHCVSS 8.6EG 8.62026-08-27
WatchGuard Dimension contains an authenticated SQL injection vulnerability in the scheduled report feature which allows an authenticated user with report administration permissions gain arbitrary command execution as the Dimension WebUI pr…
- CVE-2026-78614HIGHCVSS 8.6EG 8.62026-08-27
WatchGuard Dimension contains an authenticated SQL injection vulnerability in the audit report feature which allows an authenticated user with report administration permissions gain arbitrary command execution as the Dimension WebUI proces…
- CVE-2026-78683CRITICALCVSS 9.6EG 9.62026-08-25
NLTK before 3.10.0 (affected versions <=3.9.4) contains an unsafe pickle deserialization vulnerability in the TransitionParser.parse() method (nltk/parse/transitionparser.py). The method calls pickle_load() with the default restricted=Fals…
- CVE-2026-7871CRITICALCVSS 9.8EG 9.82026-06-30
IBM Langflow OSS 1.0.0 through 1.10.0 allows users with Redis access to execute arbitrary code with full application privileges, compromising all secrets, data, and system integrity.
- CVE-2026-7888HIGHCVSS 8.4EG 8.42026-06-03
Concrete CMS below 9.5.3 is vulnerable to PHP Object Injection via unserialize() calls in the Workflow, Form block, and File/Set components that lack the allowed_classes restriction. The Form block and File/Set sinks were addressed in 9.5.…
- CVE-2026-79657CRITICALCVSS 9.8EG 9.82026-08-25
NLTK versions before 3.10.3 contain a remote code execution vulnerability in allowlisted pickle loaders that trust entire module namespaces instead of specific safe callables. Attackers can craft malicious pickle payloads invoking dangerou…
- CVE-2026-8024CRITICALCVSS 9.8EG 9.82026-06-18
A remote, unauthenticated attacker may exploit a deserialization of untrusted data vulnerability in ibaPDA or ibaDatCoordinator to gain full access to the affected systems.
- CVE-2026-80428CRITICALCVSS 9.8EG 9.82026-08-26
ILIAS before versions 9.22, 10.10, and 11.3 contains an unauthenticated PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting serialized objects through the LTI authentication endpo…
- CVE-2026-81283HIGHCVSS 8.8EG 8.82026-09-02
Subscriber PHP Object Injection in WP User Frontend <= 4.3.10 versions.
- CVE-2026-81319MEDIUMCVSS 5.9EG 5.92026-08-30
Deserialization of Untrusted Data vulnerability in ash-project ash_cloak allows an attacker who can influence the bytes of an encrypted column to crash the BEAM node, by triggering unbounded atom creation or a decompression bomb during dec…
- CVE-2026-8135HIGHCVSS 7.2EG 7.22026-05-21
Concrete CMS 9.5.0 and below is vulnerable to Remote Code Execution due to insecure deserialization occurring in the ExpressEntryList block controller. An rogue administrator with privileges to add blocks to an area can bypass the inten…
- CVE-2026-81385HIGHCVSS 8.8EG 8.82026-09-08
Deserialization of untrusted data in Microsoft Office Publisher allows an unauthorized attacker to execute code over a network.
- CVE-2026-81657CRITICALCVSS 9.8EG 9.82026-09-18
IBM Guardium Data Protection 12.2 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.
- CVE-2026-81757HIGHCVSS 7.2EG 7.22026-08-28
Author Remote Code Execution (RCE) in Rank Math SEO <= 1.0.276 versions.
- CVE-2026-81772HIGHCVSS 8.8EG 8.82026-09-02
Unauthenticated PHP Object Injection in Ninja Forms - Layout & Styles <= 3.0.31 versions.
- CVE-2026-81784HIGHCVSS 8.1EG 8.12026-09-10
Unauthenticated PHP Object Injection in Wise Chat <= 3.4 versions.
- CVE-2026-82222CRITICALCVSS 10.0EG 10.02026-08-28
Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP GiveWP allows Object Injection. This issue affects GiveWP: from n/a through 4.16.7.1.
- CVE-2026-82226CRITICALCVSS 9.8EG 9.82026-08-31
Unauthenticated PHP Object Injection in Tickera <= 3.6.0.2 versions.
- CVE-2026-82259HIGHCVSS 7.5EG 7.52026-08-28
SvelteKit versions from 2.49.0 through 2.53.2 (fixed in 2.53.3) contain a deserialization expansion issue in the experimental form remote function. When an application enables experimental.remoteFunctions and uses the form function to proc…
- CVE-2026-82845CRITICALCVSS 9.9EG 9.92026-09-12
The Masteriyo LMS WordPress plugin before 3.4.1 does not prevent user-supplied values held as metadata from being deserialized when they are read back, allowing users with a minimal account to inject arbitrary PHP objects and, by way of a…
- CVE-2026-82925HIGHCVSS 8.1EG 8.12026-09-10
The Site Reviews WordPress plugin before 8.3.0 does not prevent request data from being deserialized, and derives the key protecting that data by padding out the site's WordPress nonce key, which makes the key publicly computable on instal…
- CVE-2026-83497HIGHCVSS 8.8EG 8.82026-08-31
Unrestricted deserialization of untrusted data in the cursor pagination component in the OpenSearch SQL plugin allows a remote authenticated user with basic read/search permissions to execute arbitrary code on the server by sending a craft…
- CVE-2026-83557MEDIUMCVSS 5.6EG 5.62026-09-01
DefaultBaseTypeLimitingValidator is the PolymorphicTypeValidator applied automatically whenever @JsonTypeInfo is used without an explicitly configured custom validator. It denies polymorphic resolution only for a fixed set of "unsafe base …
- CVE-2026-8365HIGHCVSS 8.8EG 8.82026-06-09
The Blocksy theme for WordPress is vulnerable to PHP Object Injection leading to Remote Code Execution via the 'blocksy_meta' REST API field and the V200 database migration in versions up to and including 2.1.35. This is due to insufficien…
Map vulnerabilities like CWE-502 to your infrastructure
EchelonGraph correlates every CVE — across CWE-502 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →