CWE-502: Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.
Yearly Trend
Top Affected Vendors
All Deserialization of Untrusted Data CVEs (1,006)
The Advanced AJAX Product Filters WordPress plugin is vulnerable to PHP object injection via deserialization of untrusted input in the Live Composer c...
Feb 18, 2026This vulnerability in Infoblox NIOS allows attackers to execute arbitrary code remotely through insecure deserialization. It affects all Infoblox NIOS...
Feb 12, 2026This vulnerability allows attackers to execute arbitrary code on WordPress sites running the vulnerable WpEvently plugin by exploiting insecure deseri...
Feb 3, 2026This vulnerability allows attackers to execute arbitrary code through PHP object injection by exploiting insecure deserialization in the North WordPre...
Jan 22, 2026This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the Dental Care CPT WordPress plugin. Suc...
Jan 22, 2026This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the Tech Life CPT WordPress plugin. Succe...
Jan 22, 2026This vulnerability allows remote attackers to execute arbitrary code through PHP object injection in the OneLife WordPress theme. Attackers can exploi...
Jan 22, 2026This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the Anona WordPress theme. It affects all...
Jan 22, 2026This vulnerability allows attackers to inject malicious objects through insecure deserialization in the Vivagh WordPress theme. Attackers could execut...
Jan 22, 2026This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the Eventin WordPress plugin. Attackers c...
Jan 22, 2026This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the Kids Heaven WordPress theme. Attacker...
Jan 22, 2026This vulnerability allows an authorized attacker to execute arbitrary code on Microsoft SharePoint servers by exploiting insecure deserialization of u...
Jan 13, 2026A deserialization vulnerability in Broadcom DX NetOps Spectrum allows attackers to inject malicious objects by sending untrusted data to the applicati...
Jan 12, 2026This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the DZS Video Gallery WordPress plugin. S...
Jan 6, 2026LMDeploy versions before 0.11.1 have an insecure deserialization vulnerability where torch.load() is called without the weights_only=True parameter wh...
Dec 26, 2025This vulnerability allows remote code execution on Apache NiFi systems through unsafe Java deserialization in the GetAsanaObject Processor. Attackers ...
Dec 19, 2025This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the Booking and Rental Manager for WooCom...
Dec 18, 2025This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the PDF for Contact Form 7 WordPress plug...
Dec 18, 2025This vulnerability allows attackers to execute arbitrary code on WordPress sites using the PDF for WPForms plugin by exploiting insecure deserializati...
Dec 18, 2025This vulnerability allows attackers to execute arbitrary code on WooCommerce sites by exploiting insecure deserialization in the PDF Invoice Builder p...
Dec 18, 2025This vulnerability allows remote code execution through deserialization of untrusted JSON data in Pentaho's Community Dashboard Editor plugin. Attacke...
Dec 15, 2025This vulnerability in the Doubly WordPress plugin allows authenticated attackers with Subscriber-level access to execute arbitrary code through PHP ob...
Dec 13, 2025This CVE describes a remote code execution vulnerability in Apache HugeGraph's PD store where a malicious Raft node can exploit insecure Hessian deser...
Dec 12, 2025CVE-2025-33213 is a deserialization vulnerability in NVIDIA Merlin Transformers4Rec for Linux, allowing attackers to execute arbitrary code, cause den...
Dec 9, 2025NVIDIA NVTabular for Linux has a deserialization vulnerability in its Workflow component that could allow attackers to execute arbitrary code, cause d...
Dec 9, 2025This vulnerability in HummerRisk allows authenticated users with normal privileges to exploit a vulnerable Snakeyaml component via the /rule/add API e...
Dec 8, 2025This CVE describes a remote code execution vulnerability in Fugue's RPC server implementation. Attackers can send malicious pickle data that gets dese...
Nov 25, 2025This vulnerability in IBM webMethods Integration allows authenticated users to execute arbitrary code on affected systems through insecure deserializa...
Nov 20, 2025This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the Falang multilanguage WordPress plugin...
Nov 6, 2025This vulnerability allows remote attackers to execute arbitrary code through insecure deserialization in the NooTheme Yogi WordPress theme. Attackers ...
Nov 6, 2025This vulnerability in the Polylang WordPress plugin allows attackers to perform object injection through deserialization of untrusted data. Attackers ...
Oct 31, 2025This vulnerability allows attackers to execute arbitrary PHP code through insecure deserialization in the Product Table For WooCommerce WordPress plug...
Oct 22, 2025This CVE describes a PHP object injection vulnerability in the designthemes Knowledge Base WordPress theme. Attackers can exploit insecure deserializa...
Oct 22, 2025This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the VEDA WordPress theme. It affects all ...
Oct 22, 2025This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the Boldermail WordPress plugin. Attacker...
Oct 22, 2025This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the WP Store Locator WordPress plugin. Su...
Oct 22, 2025This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the Solar Energy WordPress theme. It affe...
Oct 22, 2025This vulnerability allows authenticated attackers to bypass JDBC driver restrictions in DataEase by providing a malicious jdbcUrl parameter. Attackers...
Oct 17, 2025This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the ThemeMove Core WordPress plugin. Succ...
Sep 9, 2025This CVE describes a PHP object injection vulnerability in the Constant Contact for WordPress plugin caused by unsafe deserialization of untrusted dat...
Sep 9, 2025This vulnerability in MONAI's pickle_operations function allows arbitrary code execution through unsafe deserialization of pickle data. Any system run...
Sep 9, 2025A deserialization vulnerability in Sitecore Experience Manager (XM) and Experience Platform (XP) allows remote attackers to execute arbitrary code by ...
Sep 3, 2025CVE-2025-58163 is a remote code execution vulnerability in FreeScout help desk software where authenticated attackers with knowledge of the applicatio...
Sep 3, 2025A PHP object injection vulnerability in PickPlugins Post Grid and Gutenberg Blocks WordPress plugins allows attackers to execute arbitrary code throug...
Aug 20, 2025This CVE describes a PHP object injection vulnerability in the Eventin WordPress plugin caused by unsafe deserialization of untrusted data. Attackers ...
Aug 14, 2025This vulnerability allows an authorized attacker to execute arbitrary code on systems running vulnerable versions of Web Deploy by exploiting insecure...
Aug 12, 2025CVE-2025-54366 is a critical deserialization vulnerability in FreeScout help desk software that allows authenticated attackers with knowledge of the A...
Jul 26, 2025A local privilege escalation vulnerability in Sophos Intercept X for Windows with Central Device Encryption allows attackers with local access to exec...
Jul 17, 2025This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the Visual Art | Gallery WordPress theme....
Jul 16, 2025This CVE describes a PHP object injection vulnerability in the Hillter WordPress theme due to unsafe deserialization of untrusted data. Attackers can ...
Jul 16, 2025About Deserialization of Untrusted Data (CWE-502)
The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.
Our database tracks 1,006 CVEs classified as CWE-502, with 491 rated critical and 459 rated high severity. The average CVSS score for Deserialization of Untrusted Data vulnerabilities is 8.8.
External reference: View CWE-502 on MITRE CWE →
Monitor Deserialization of Untrusted Data Vulnerabilities
Get alerted when new Deserialization of Untrusted Data CVEs affect your infrastructure.
Start Monitoring Free