CWE-502: Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.

1,047
Total CVEs
517
Critical
474
High
8.8
Avg CVSS
10
In CISA KEV

Yearly Trend

2026
83
2025
398
2024
223
2023
129
2022
34

Top Affected Vendors

1 Apache 62
2 Microsoft 36
3 Debian 23
4 Oracle 22
5 Ibm 20
6 Solarwinds 19
7 Netapp 17
8 Adobe 14
9 Fasterxml 13
10 Ivanti 9

All Deserialization of Untrusted Data CVEs (1,047)

CVE-2023-25558
7.5

DataHub's SSO authentication improperly processes id_token claims with {#sb64} prefixes, allowing unsafe Java deserialization via pac4j library. This ...

Feb 11, 2023
CVE-2022-0138
7.5

This vulnerability allows remote code execution through insecure deserialization in Cambium Networks wireless devices. Attackers can send specially cr...

Feb 18, 2022
CVE-2021-4104
7.5

CVE-2021-4104 is a deserialization vulnerability in Log4j 1.2's JMSAppender that allows remote code execution when attackers can modify Log4j configur...

Dec 14, 2021
CVE-2021-26558
7.5

CVE-2021-26558 is a deserialization vulnerability in Apache ShardingSphere-UI that allows attackers to inject malicious external resources through unt...

Nov 11, 2021
CVE-2021-33175
7.5

CVE-2021-33175 is a denial of service vulnerability in EMQ X Broker where specially crafted untrusted inputs cause excessive memory consumption, leadi...

Jun 8, 2021
CVE-2020-35939
7.5

This CVE describes a PHP object injection vulnerability in the Team Showcase WordPress plugin. Remote authenticated attackers can execute arbitrary co...

Jan 1, 2021
CVE-2025-30384
7.4

This vulnerability allows remote code execution on Microsoft SharePoint servers through deserialization of untrusted data. Attackers can execute arbit...

May 13, 2025
CVE-2024-49070
7.4

This vulnerability allows remote attackers to execute arbitrary code on Microsoft SharePoint servers by deserializing untrusted data. It affects organ...

Dec 12, 2024
CVE-2023-46147
7.4

This vulnerability allows authenticated attackers to perform PHP object injection via deserialization of untrusted data in the Themify Ultra WordPress...

Dec 20, 2023
CVE-2025-9906
7.3

CVE-2025-9906 is a critical vulnerability in Keras that allows arbitrary code execution when loading specially crafted .keras model files. Attackers c...

Sep 19, 2025
CVE-2023-32736
7.3

This vulnerability in Siemens industrial automation software allows attackers to execute arbitrary code through type confusion when parsing user setti...

Nov 12, 2024
CVE-2024-47561
7.3

This vulnerability in Apache Avro's Java SDK allows attackers to execute arbitrary code by exploiting schema parsing flaws. It affects all users of Ap...

Oct 3, 2024
CVE-2024-1032
7.3

CVE-2024-1032 is a critical deserialization vulnerability in openBI's testConnection function that allows remote attackers to execute arbitrary code. ...

Jan 30, 2024
CVE-2024-0739
7.3

This critical vulnerability in Hecheng Leadshop allows remote attackers to execute arbitrary code through deserialization of untrusted data in the /we...

Jan 19, 2024
CVE-2024-0603
7.3

This is a critical remote code execution vulnerability in ZhiCms CMS software. Attackers can exploit insecure deserialization in the giftcontroller.ph...

Jan 16, 2024
CVE-2023-21568
7.3

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of Microsoft SQL Server Integration Servic...

Feb 14, 2023
CVE-2020-12525
7.3

This vulnerability in M&M Software's fdtCONTAINER Component allows attackers to execute arbitrary code by deserializing untrusted data from project st...

Jan 22, 2021
CVE-2026-25615
7.2

This vulnerability in Blesta billing software allows attackers to perform object injection attacks by sending specially crafted data. This affects all...

Feb 3, 2026
CVE-2025-66055
7.2

This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the Icegram Email Subscribers & Newslette...

Nov 21, 2025
CVE-2025-13145
7.2

This vulnerability allows authenticated WordPress administrators to perform PHP object injection by uploading malicious CSV files through the WP Impor...

Nov 19, 2025
CVE-2025-12099
7.2

This vulnerability allows authenticated WordPress administrators to inject PHP objects through the Academy LMS plugin's import_all_courses function. T...

Nov 8, 2025
CVE-2025-58662
7.2

This CVE describes a deserialization vulnerability in the Awesome Support WordPress plugin that allows attackers to inject malicious objects through u...

Sep 22, 2025
CVE-2025-53465
7.2

This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the GSheets Connector WordPress plugin. S...

Sep 22, 2025
CVE-2025-58839
7.2

This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the eDS Responsive Menu WordPress plugin....

Sep 5, 2025
CVE-2025-58815
7.2

This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the Aitasi Coming Soon WordPress plugin. ...

Sep 5, 2025
CVE-2025-58644
7.2

This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the LTL Freight Quotes - TQL Edition Word...

Sep 3, 2025
CVE-2025-58642
7.2

This vulnerability allows attackers to inject malicious objects through untrusted data deserialization in the LTL Freight Quotes – Day & Ross Editio...

Sep 3, 2025
CVE-2025-54012
7.2

This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the Welcart e-Commerce WordPress plugin. ...

Aug 20, 2025
CVE-2025-49438
7.2

This CVE describes a PHP object injection vulnerability in the Simple Login Log WordPress plugin. Attackers can exploit insecure deserialization to ex...

Aug 20, 2025
CVE-2025-47536
7.2

A deserialization vulnerability in the Content Egg WordPress plugin allows attackers to inject malicious objects by manipulating serialized data. This...

Aug 14, 2025
CVE-2025-49083
7.2

CVE-2025-49083 is a deserialization vulnerability in Absolute Secure Access management console that allows authenticated administrators to execute arb...

Jul 31, 2025
CVE-2025-53990
7.2

This vulnerability allows attackers to inject malicious objects through untrusted data deserialization in JetFormBuilder WordPress plugin. Attackers c...

Jul 16, 2025
CVE-2025-4803
7.2

This vulnerability allows authenticated WordPress administrators to perform PHP object injection via deserialization of untrusted input in the Glossar...

May 21, 2025
CVE-2025-48134
7.2

This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the WP Tabs WordPress plugin. Successful ...

May 16, 2025
CVE-2025-47683
7.2

This vulnerability allows attackers to inject malicious PHP objects through deserialization of untrusted data in the WP Maintenance WordPress plugin. ...

May 7, 2025
CVE-2025-47629
7.2

This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the WP-CRM System WordPress plugin. Succe...

May 7, 2025
CVE-2025-46481
7.2

This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the Flickr Shortcode Importer WordPress p...

Apr 24, 2025
CVE-2025-46473
7.2

This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the djjmz Social Counter WordPress plugin...

Apr 24, 2025
CVE-2025-29793
EPSS 36% 7.2

This vulnerability allows an authenticated attacker to execute arbitrary code on Microsoft SharePoint servers by exploiting insecure deserialization o...

Apr 8, 2025
CVE-2025-30773
7.2

CVE-2025-30773 is a PHP object injection vulnerability in TranslatePress WordPress plugin caused by unsafe deserialization of untrusted data. Attacker...

Mar 27, 2025
CVE-2025-1913
7.2

This vulnerability allows authenticated WordPress administrators to inject PHP objects via deserialization of untrusted input in the Product Import Ex...

Mar 26, 2025
CVE-2024-13889
7.2

The WordPress Importer plugin is vulnerable to PHP object injection via deserialization of untrusted input. This allows authenticated attackers with A...

Mar 26, 2025
CVE-2025-1971
7.2

This CVE describes a PHP Object Injection vulnerability in the Export and Import Users and Customers WordPress plugin. Authenticated attackers with Ad...

Mar 22, 2025
CVE-2024-13921
7.2

This vulnerability allows authenticated WordPress administrators to inject PHP objects via deserialization of untrusted input in the Order Export & Or...

Mar 20, 2025
CVE-2025-26885
7.2

This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the Brent Jett Assistant WordPress plugin...

Mar 3, 2025
CVE-2024-13833
7.2

This vulnerability in the Album Gallery WordPress plugin allows authenticated attackers with Editor-level access or higher to inject PHP objects throu...

Mar 1, 2025
CVE-2024-13831
7.2

The Tabs for WooCommerce WordPress plugin is vulnerable to PHP object injection through deserialization of untrusted input. This allows authenticated ...

Feb 28, 2025
CVE-2025-27300
7.2

This vulnerability in the giuliopanda ADFO WordPress plugin allows attackers to inject malicious objects through deserialization of untrusted data. It...

Feb 24, 2025
CVE-2025-27301
7.2

This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the NHR Options Table Manager WordPress p...

Feb 24, 2025
CVE-2024-13899
7.2

The Mambo Importer WordPress plugin is vulnerable to PHP object injection via deserialization of untrusted input, allowing authenticated administrator...

Feb 22, 2025

About Deserialization of Untrusted Data (CWE-502)

The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.

Our database tracks 1,047 CVEs classified as CWE-502, with 517 rated critical and 474 rated high severity. The average CVSS score for Deserialization of Untrusted Data vulnerabilities is 8.8.

External reference: View CWE-502 on MITRE CWE →

Monitor Deserialization of Untrusted Data Vulnerabilities

Get alerted when new Deserialization of Untrusted Data CVEs affect your infrastructure.

Start Monitoring Free