CWE-502: Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.
Yearly Trend
Top Affected Vendors
All Deserialization of Untrusted Data CVEs (974)
This vulnerability allows remote attackers to execute arbitrary code through deserialization of untrusted data in the ThemeREX Sound | Musical Instrum...
Jan 22, 2026CVE-2025-67617 is a PHP object injection vulnerability in the Consult Aid WordPress theme that allows attackers to execute arbitrary code by exploitin...
Jan 22, 2026CVE-2026-23524 is a critical deserialization vulnerability in Laravel Reverb that allows remote code execution when horizontal scaling is enabled. Att...
Jan 21, 2026CVE-2025-56005 is a critical vulnerability in the PLY (Python Lex-Yacc) library that allows remote code execution via an undocumented 'picklefile' par...
Jan 20, 2026This CVE describes a critical .NET deserialization vulnerability in Changjetong T+ software that allows remote attackers to execute arbitrary code on ...
Jan 15, 2026This CVE describes a PHP object injection vulnerability in Tribulant Software's Newsletters WordPress plugin. Attackers can exploit insecure deseriali...
Jan 8, 2026This CVE describes a PHP object injection vulnerability in the DZS Video Gallery WordPress plugin that allows attackers to execute arbitrary code thro...
Jan 7, 2026This vulnerability allows attackers to execute arbitrary code through PHP object injection by exploiting unsafe deserialization in Icegram Express Pro...
Dec 24, 2025This CVE describes a PHP object injection vulnerability in the Client Invoicing by Sprout Invoices WordPress plugin. Attackers can exploit insecure de...
Dec 18, 2025This CVE describes a PHP object injection vulnerability in the BoldThemes Codiqa WordPress theme. Attackers can exploit insecure deserialization to ex...
Dec 18, 2025This vulnerability allows remote attackers to execute arbitrary code through PHP object injection by exploiting unsafe deserialization in the Jannah W...
Dec 18, 2025This vulnerability allows remote attackers to execute arbitrary code through deserialization of untrusted data in the WP Gravity Forms FreshDesk Plugi...
Dec 18, 2025This vulnerability allows remote attackers to execute arbitrary code on WordPress sites using the WP Gravity Forms Insightly plugin. Attackers can exp...
Dec 18, 2025This vulnerability allows remote attackers to execute arbitrary code through deserialization of untrusted data in the WP Gravity Forms Zoho CRM and Bi...
Dec 18, 2025This vulnerability allows attackers to execute arbitrary code on WordPress sites using the Gravity Forms Constant Contact plugin by exploiting insecur...
Dec 18, 2025This vulnerability allows remote attackers to execute arbitrary code on WordPress sites using the WP Gravity Forms HubSpot plugin (gf-hubspot) through...
Dec 18, 2025This vulnerability allows attackers to execute arbitrary PHP code through insecure deserialization in the WP Gravity Forms Salesforce plugin. It affec...
Dec 18, 2025This vulnerability allows attackers to inject malicious objects via untrusted data deserialization in the BoldThemes DentiCare WordPress theme, potent...
Dec 18, 2025This CVE describes a critical remote code execution vulnerability in MooreThreads torch_musa where unsafe deserialization via pickle.load() allows arb...
Dec 15, 2025Barracuda Service Center in the RMM solution prior to version 2025.1.1 exposes a .NET Remoting service that allows deserialization of arbitrary types,...
Dec 10, 2025CVE-2025-51745 is a critical deserialization vulnerability in jishenghua JSH_ERP 2.3.1 that allows remote code execution via the /role/addcan endpoint...
Nov 25, 2025CVE-2025-51746 is a critical deserialization vulnerability in jishenghua JSH_ERP 2.3.1 that allows remote code execution via the /serialNumber/addSeri...
Nov 25, 2025This vulnerability allows remote attackers to execute arbitrary code on JSH_ERP systems through fastjson deserialization attacks targeting the /materi...
Nov 25, 2025This vulnerability allows remote attackers to execute arbitrary code on JSH_ERP systems by exploiting a Fastjson deserialization flaw. Attackers can s...
Nov 25, 2025This critical vulnerability in Microsoft SharePoint Online allows authenticated attackers to elevate their privileges within SharePoint environments. ...
Nov 20, 2025CVE-2025-11367 allows remote attackers to execute arbitrary code on systems running vulnerable versions of N-central Software Probe via insecure deser...
Nov 12, 2025This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the WP User Manager WordPress plugin. Suc...
Nov 6, 2025This CVE describes a PHP object injection vulnerability in the s2Member WordPress plugin that allows attackers to execute arbitrary code by deserializ...
Nov 6, 2025This vulnerability allows attackers to execute arbitrary code on WordPress sites using the WP Gravity Forms Keap/Infusionsoft plugin (gf-infusionsoft)...
Nov 6, 2025This vulnerability allows remote attackers to execute arbitrary code through PHP object injection via deserialization of untrusted data in the NooThem...
Nov 6, 2025This vulnerability allows remote attackers to execute arbitrary code through deserialization of untrusted data in the Seil WordPress theme. Attackers ...
Nov 6, 2025CVE-2025-49386 is a PHP object injection vulnerability in the WordPress Preserve Code Formatting plugin that allows attackers to execute arbitrary cod...
Nov 6, 2025This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the Fetch Designs Sign-up Sheets WordPres...
Nov 6, 2025This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the Ajax Search Lite WordPress plugin. It...
Nov 6, 2025This CVE describes a PHP object injection vulnerability in the JobSearch WordPress plugin that allows attackers to execute arbitrary code through dese...
Oct 22, 2025This CVE describes a PHP object injection vulnerability in the quantumcloud KBx Pro Ultimate WordPress plugin, allowing attackers to execute arbitrary...
Oct 22, 2025This CVE describes a PHP object injection vulnerability in the UNIVERSAM WordPress plugin that allows attackers to execute arbitrary code through dese...
Oct 22, 2025This CVE describes a PHP object injection vulnerability in the Captivate Sync WordPress plugin that allows attackers to execute arbitrary code through...
Oct 22, 2025This CVE describes a PHP object injection vulnerability in the WordPress Subscribe to Download plugin. Attackers can exploit insecure deserialization ...
Oct 22, 2025This vulnerability allows attackers to execute arbitrary code by exploiting insecure deserialization in the White Rabbit WordPress theme. Attackers ca...
Oct 22, 2025This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the Whitebox-Studio Scape WordPress theme...
Oct 22, 2025This vulnerability allows attackers to execute arbitrary code by exploiting insecure deserialization in the Goldenblatt WordPress theme. It affects al...
Oct 22, 2025This CVE describes a PHP object injection vulnerability in the BoldThemes Addison WordPress theme. Attackers can exploit insecure deserialization to e...
Oct 22, 2025This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the Connector for Gravity Forms and Googl...
Oct 22, 2025This vulnerability allows remote attackers to execute arbitrary code through PHP object injection via deserialization of untrusted data in the Noisa W...
Oct 22, 2025This vulnerability allows unauthenticated attackers to execute arbitrary PHP code on WordPress sites using vulnerable versions of the RegistrationMagi...
Oct 18, 2025The Appointments plugin for WordPress has a PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by dese...
Oct 18, 2025This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of pyquokka by sending malicious pickled p...
Oct 17, 2025This vulnerability allows arbitrary code execution when deserializing malicious Keras files containing a TorchModuleWrapper class, even with safe mode...
Oct 17, 2025A deserialization vulnerability in Apache ActiveMQ NMS AMQP Client allows malicious AMQP servers to execute arbitrary code on client systems when conn...
Oct 16, 2025About Deserialization of Untrusted Data (CWE-502)
The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.
Our database tracks 974 CVEs classified as CWE-502, with 474 rated critical and 444 rated high severity. The average CVSS score for Deserialization of Untrusted Data vulnerabilities is 8.8.
External reference: View CWE-502 on MITRE CWE →
Monitor Deserialization of Untrusted Data Vulnerabilities
Get alerted when new Deserialization of Untrusted Data CVEs affect your infrastructure.
Start Monitoring Free