CWE-502: Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.

998
Total CVEs
484
Critical
458
High
8.8
Avg CVSS
10
In CISA KEV

Yearly Trend

2026
83
2025
398
2024
223
2023
129
2022
34

Top Affected Vendors

1 Apache 57
2 Microsoft 35
3 Solarwinds 19
4 Ibm 16
5 Debian 14
6 Adobe 14
7 Oracle 12
8 Netapp 10
9 Givewp 9
10 Ivanti 9

All Deserialization of Untrusted Data CVEs (998)

CVE-2025-3623
9.1

The Uncanny Automator WordPress plugin contains a PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code t...

May 14, 2025
CVE-2025-42999
KEV EPSS 65.7% 9.1

CVE-2025-42999 is a deserialization vulnerability in SAP NetWeaver Visual Composer Metadata Uploader that allows privileged users to upload malicious ...

May 13, 2025
CVE-2025-24447
EPSS 28.4% 9.1

This CVE describes a deserialization vulnerability in Adobe ColdFusion that allows attackers to execute arbitrary code without user interaction. Syste...

Apr 8, 2025
CVE-2024-57763
9.1

This CVE describes a fastjson deserialization vulnerability in MSFM that allows remote code execution by sending malicious payloads to the system/tabl...

Jan 15, 2025
CVE-2024-57766
9.1

This vulnerability allows remote code execution through fastjson deserialization in MSFM's table editing component. Attackers can exploit this to exec...

Jan 15, 2025
CVE-2024-37285
9.1

A deserialization vulnerability in Kibana allows authenticated attackers with specific Elasticsearch and Kibana privileges to execute arbitrary code b...

Nov 14, 2024
CVE-2024-45758
9.1

This vulnerability in H2O.ai H2O allows attackers to set arbitrary JDBC URLs, leading to deserialization attacks, file reads, and remote code executio...

Sep 6, 2024
CVE-2024-8016
9.1

The Events Calendar Pro WordPress plugin is vulnerable to PHP object injection through deserialization of untrusted input in the 'filters' parameter. ...

Aug 30, 2024
CVE-2024-26580
9.1

This CVE describes a deserialization vulnerability in Apache InLong that allows attackers to read arbitrary files from the server. The vulnerability a...

Mar 6, 2024
CVE-2024-23328
9.1

This CVE describes a deserialization vulnerability in Dataease's MySQL datasource component that allows attackers to bypass JDBC attack blacklists. Su...

Feb 29, 2024
CVE-2023-52202
9.1

This CVE describes a PHP object injection vulnerability in the HTML5 MP3 Player with Folder Feedburner Playlist Free WordPress plugin. Attackers can e...

Jan 8, 2024
CVE-2023-52205
9.1

This CVE describes a PHP object injection vulnerability in the HTML5 SoundCloud Player with Playlist Free WordPress plugin. Attackers can exploit dese...

Jan 8, 2024
CVE-2023-52207
9.1

This vulnerability allows remote attackers to execute arbitrary code via PHP object injection through deserialization of untrusted data in the HTML5 M...

Jan 8, 2024
CVE-2023-49777
9.1

This vulnerability allows attackers to execute arbitrary PHP code through insecure deserialization in the YITH WooCommerce Product Add-Ons plugin. It ...

Dec 31, 2023
CVE-2021-41110
9.1

CVE-2021-41110 is a critical deserialization vulnerability in cwlviewer that allows remote code execution by parsing malicious YAML data. The vulnerab...

Oct 1, 2021
CVE-2021-29508
9.1

CVE-2021-29508 is a deserialization vulnerability in Wire serialization library that allows attackers to execute arbitrary code by sending malicious p...

May 11, 2021
CVE-2025-62368
EPSS 61.1% 9.0

This CVE describes a remote code execution vulnerability in Taiga project management platform due to unsafe deserialization of untrusted data in the A...

Oct 28, 2025
CVE-2025-47579
9.0

This vulnerability allows unauthenticated attackers to execute arbitrary PHP code through deserialization of untrusted data in the Photography WordPre...

Sep 9, 2025
CVE-2025-53690
KEV 9.0

This CVE describes a deserialization vulnerability in Sitecore Experience Manager (XM) and Experience Platform (XP) that allows attackers to inject an...

Sep 3, 2025
CVE-2025-30023
9.0

This vulnerability allows authenticated users to execute arbitrary code remotely on affected systems by exploiting a flaw in the client-server communi...

Jul 11, 2025
CVE-2025-36038
9.0

CVE-2025-36038 is a critical deserialization vulnerability in IBM WebSphere Application Server that allows remote attackers to execute arbitrary code ...

Jun 25, 2025
CVE-2025-5086
KEV EPSS 45.7% 9.0

CVE-2025-5086 is a deserialization vulnerability in Dassault Systèmes DELMIA Apriso that allows remote attackers to execute arbitrary code by sending...

Jun 2, 2025
CVE-2025-26873
9.0

This vulnerability allows remote attackers to execute arbitrary code via PHP object injection in the Traveler WordPress theme. It affects WordPress si...

Mar 27, 2025
CVE-2025-29783
9.0

CVE-2025-29783 is a remote code execution vulnerability in vLLM when configured with Mooncake for distributed key-value storage. Attackers can exploit...

Mar 19, 2025
CVE-2024-52577
9.0

This vulnerability allows remote code execution on Apache Ignite servers by bypassing class serialization filters. Attackers can craft malicious messa...

Feb 14, 2025
CVE-2024-28991
9.0

SolarWinds Access Rights Manager (ARM) contains a deserialization vulnerability (CWE-502) that allows authenticated users to execute arbitrary code re...

Sep 12, 2024
CVE-2024-43252
9.0

CVE-2024-43252 is a PHP object injection vulnerability in the Crew HRM WordPress plugin that allows attackers to execute arbitrary code through deseri...

Aug 19, 2024
CVE-2024-4371
9.0

This vulnerability allows unauthenticated attackers to perform PHP object injection via the recently_viewed_products cookie in the CoDesigner WooComme...

Jun 13, 2024
CVE-2024-3300
9.0

An unsafe .NET object deserialization vulnerability in DELMIA Apriso allows attackers to execute arbitrary code without authentication. This affects a...

May 30, 2024
CVE-2024-28075
9.0

This vulnerability allows authenticated users of SolarWinds Access Rights Manager to execute arbitrary code remotely on affected systems. Attackers wi...

May 14, 2024
CVE-2024-33553
9.0

CVE-2024-33553 is an unauthenticated PHP object injection vulnerability in the XStore Core WordPress plugin. Attackers can exploit deserialization of ...

Apr 29, 2024
CVE-2024-30223
9.0

CVE-2024-30223 is an unauthenticated PHP object injection vulnerability in the ARMember WordPress plugin. Attackers can exploit this by sending specia...

Mar 28, 2024
CVE-2024-30227
9.0

This CVE describes a PHP object injection vulnerability in the INFINITUM FORM Geo Controller WordPress plugin due to insecure deserialization of untru...

Mar 28, 2024
CVE-2023-45146
9.0

CVE-2023-45146 is a critical remote code execution vulnerability in XXL-RPC when configured with Netty and Hessian serialization. Attackers can send m...

Oct 18, 2023
CVE-2021-35215
8.9

This vulnerability allows authenticated attackers to execute arbitrary code on SolarWinds Orion Platform servers through insecure deserialization. It ...

Sep 1, 2021
CVE-2021-35218
8.9

This vulnerability allows remote code execution through deserialization of untrusted data in the SolarWinds Orion Patch Manager Web Console. An attack...

Sep 1, 2021
CVE-2026-2036
8.8

This vulnerability allows remote authenticated attackers to bypass authentication and execute arbitrary code with SYSTEM privileges on GFI Archiver in...

Feb 20, 2026
CVE-2026-22354
8.8

This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the Dotstore Woocommerce Category Banner ...

Feb 20, 2026
CVE-2026-22346
8.8

This CVE describes a PHP object injection vulnerability in the WordPress Slider Responsive Slideshow plugin, allowing attackers to execute arbitrary c...

Feb 20, 2026
CVE-2025-69294
8.8

This CVE describes a PHP object injection vulnerability in the PeakShops WordPress theme caused by unsafe deserialization of user-controlled data. Att...

Feb 20, 2026
CVE-2025-68853
8.8

This CVE describes a PHP object injection vulnerability in the Kleor Contact Manager WordPress plugin. Attackers can exploit insecure deserialization ...

Feb 20, 2026
CVE-2025-68531
8.8

This CVE describes a PHP object injection vulnerability in the ModelTheme Addons for WPBakery and Elementor WordPress plugin. Attackers can exploit in...

Feb 20, 2026
CVE-2026-23544
8.8

This CVE describes a PHP object injection vulnerability in the Valenti WordPress theme caused by unsafe deserialization of untrusted data. Attackers c...

Feb 19, 2026
CVE-2026-1426
8.8

The Advanced AJAX Product Filters WordPress plugin is vulnerable to PHP object injection via deserialization of untrusted input in the Live Composer c...

Feb 18, 2026
CVE-2025-61880
8.8

This vulnerability in Infoblox NIOS allows attackers to execute arbitrary code remotely through insecure deserialization. It affects all Infoblox NIOS...

Feb 12, 2026
CVE-2026-24954
8.8

This vulnerability allows attackers to execute arbitrary code on WordPress sites running the vulnerable WpEvently plugin by exploiting insecure deseri...

Feb 3, 2026
CVE-2025-69099
8.8

This vulnerability allows attackers to execute arbitrary code through PHP object injection by exploiting insecure deserialization in the North WordPre...

Jan 22, 2026
CVE-2025-69035
8.8

This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the Dental Care CPT WordPress plugin. Suc...

Jan 22, 2026
CVE-2025-69036
8.8

This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the Tech Life CPT WordPress plugin. Succe...

Jan 22, 2026
CVE-2025-69002
8.8

This vulnerability allows remote attackers to execute arbitrary code through PHP object injection in the OneLife WordPress theme. Attackers can exploi...

Jan 22, 2026

About Deserialization of Untrusted Data (CWE-502)

The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.

Our database tracks 998 CVEs classified as CWE-502, with 484 rated critical and 458 rated high severity. The average CVSS score for Deserialization of Untrusted Data vulnerabilities is 8.8.

External reference: View CWE-502 on MITRE CWE →

Monitor Deserialization of Untrusted Data Vulnerabilities

Get alerted when new Deserialization of Untrusted Data CVEs affect your infrastructure.

Start Monitoring Free