CWE-502: Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.

1,050
Total CVEs
518
Critical
476
High
8.8
Avg CVSS
10
In CISA KEV

Yearly Trend

2026
83
2025
398
2024
223
2023
129
2022
34

Top Affected Vendors

1 Apache 63
2 Microsoft 36
3 Debian 24
4 Oracle 22
5 Ibm 21
6 Solarwinds 19
7 Netapp 17
8 Adobe 14
9 Fasterxml 13
10 Ivanti 9

All Deserialization of Untrusted Data CVEs (1,050)

CVE-2025-27300
7.2

This vulnerability in the giuliopanda ADFO WordPress plugin allows attackers to inject malicious objects through deserialization of untrusted data. It...

Feb 24, 2025
CVE-2025-27301
7.2

This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the NHR Options Table Manager WordPress p...

Feb 24, 2025
CVE-2024-13899
7.2

The Mambo Importer WordPress plugin is vulnerable to PHP object injection via deserialization of untrusted input, allowing authenticated administrator...

Feb 22, 2025
CVE-2024-9664
7.2

The WP All Import Pro plugin for WordPress is vulnerable to PHP object injection through deserialization of untrusted import files. This allows authen...

Feb 7, 2025
CVE-2024-12600
7.2

This vulnerability allows authenticated attackers with Shop Manager or higher privileges to perform PHP object injection via the 'frs_woo_product_tabs...

Jan 25, 2025
CVE-2025-0428
7.2

The AI Power: Complete AI Pack WordPress plugin up to version 1.8.96 contains a PHP object injection vulnerability that allows authenticated administr...

Jan 22, 2025
CVE-2025-0429
7.2

This vulnerability allows authenticated WordPress administrators to perform PHP object injection through the 'AI Power: Complete AI Pack' plugin. Atta...

Jan 22, 2025
CVE-2025-22510
EPSS 31.3% 7.2

This CVE describes a PHP object injection vulnerability in the WC Price History for Omnibus WordPress plugin, allowing attackers to execute arbitrary ...

Jan 9, 2025
CVE-2024-11465
7.2

The Custom Product Tabs for WooCommerce WordPress plugin is vulnerable to PHP object injection via insecure deserialization of the 'yikes_woo_products...

Jan 7, 2025
CVE-2024-12721
7.2

This vulnerability allows authenticated attackers with Shop Manager or higher privileges to perform PHP object injection via the 'wb_custom_tabs' para...

Dec 21, 2024
CVE-2024-54282
7.2

This vulnerability allows attackers to inject malicious PHP objects through untrusted data deserialization in the WP Mega Menu WordPress plugin. Succe...

Dec 13, 2024
CVE-2024-5580
7.2

This vulnerability allows authenticated remote attackers to execute arbitrary code on affected Allegra installations by exploiting a deserialization f...

Nov 22, 2024
CVE-2024-11409
7.2

The Grid View Gallery WordPress plugin is vulnerable to PHP object injection through deserialization of untrusted input. This allows authenticated att...

Nov 21, 2024
CVE-2024-49684
7.2

This CVE describes a PHP object injection vulnerability in the WordPress plugin 'Backup and Staging by WP Time Capsule' due to unsafe deserialization ...

Oct 23, 2024
CVE-2024-9314
7.2

This vulnerability in the Rank Math SEO WordPress plugin allows authenticated attackers with Administrator privileges to perform PHP object injection ...

Oct 5, 2024
CVE-2022-2446
7.2

This vulnerability in the WP Editor WordPress plugin allows authenticated attackers with administrative privileges to execute arbitrary PHP code via d...

Sep 13, 2024
CVE-2022-2440
7.2

The Theme Editor WordPress plugin (versions ≤2.8) contains a PHP object injection vulnerability via the 'images_array' parameter. Authenticated atta...

Aug 29, 2024
CVE-2024-7351
7.2

The Simple Job Board WordPress plugin is vulnerable to PHP object injection through deserialization of untrusted input when editing job applications. ...

Aug 24, 2024
CVE-2024-7560
7.2

The News Flash WordPress theme is vulnerable to PHP object injection through deserialization of untrusted input in the newsflash_post_meta value. This...

Aug 8, 2024
CVE-2024-38023
7.2

This vulnerability allows remote attackers to execute arbitrary code on Microsoft SharePoint Server by exploiting insecure deserialization. It affects...

Jul 9, 2024
CVE-2024-30044
7.2

CVE-2024-30044 is a remote code execution vulnerability in Microsoft SharePoint Server that allows authenticated attackers to execute arbitrary code o...

May 14, 2024
CVE-2024-3054
7.2

The WPvivid Backup & Migration WordPress plugin is vulnerable to PHAR deserialization, allowing authenticated attackers with admin access to potential...

Apr 12, 2024
CVE-2023-4971
7.2

This vulnerability in the Weaver Xtreme Theme Support WordPress plugin allows authenticated attackers with high privileges to execute arbitrary PHP co...

Oct 16, 2023
CVE-2023-20878
7.2

This CVE describes a deserialization vulnerability in VMware Aria Operations that allows authenticated administrators to execute arbitrary commands on...

May 12, 2023
CVE-2023-1347
7.2

This vulnerability in the Customizer Export/Import WordPress plugin allows authenticated administrators to perform PHP Object Injection by exploiting ...

May 8, 2023
CVE-2023-1669
7.2

The SEOPress WordPress plugin before version 6.5.0.3 contains a PHP Object Injection vulnerability due to unsafe deserialization of user-controlled in...

May 2, 2023
CVE-2022-47503
7.2

This vulnerability in SolarWinds Platform allows remote attackers with Orion admin-level account access to execute arbitrary commands through deserial...

Feb 15, 2023
CVE-2023-0669
7.2

CVE-2023-0669 is a pre-authentication remote code execution vulnerability in Fortra GoAnywhere MFT that allows unauthenticated attackers to execute ar...

Feb 6, 2023
CVE-2022-22957
7.2

This vulnerability allows remote code execution in VMware Workspace ONE Access, Identity Manager, and vRealize Automation. An attacker with administra...

Apr 13, 2022
CVE-2022-21828
7.2

This vulnerability allows authenticated users with high privilege access to the Incapptic Connect web console to remotely execute arbitrary code on th...

Mar 4, 2022
CVE-2021-20318
7.2

This vulnerability allows remote attackers to execute arbitrary code by exploiting a deserialization flaw in HornetQ/Artemis JMS ObjectMessage handlin...

Dec 23, 2021
CVE-2021-33728
7.2

CVE-2021-33728 is a Java deserialization vulnerability in Siemens SINEC NMS that allows authenticated attackers to execute arbitrary code with root pr...

Oct 12, 2021
CVE-2021-36766
7.2

This vulnerability allows attackers to inject malicious PHP objects into Concrete5 applications through deserialization of untrusted data. Attackers c...

Jul 30, 2021
CVE-2021-32634
7.2

CVE-2021-32634 is an unsafe deserialization vulnerability in Emissary's WorkSpaceClientEnqueue REST endpoint that allows authenticated attackers to ex...

May 21, 2021
CVE-2021-25152
7.2

This CVE describes a remote insecure deserialization vulnerability in Aruba AirWave Management Platform that allows attackers to execute arbitrary cod...

Apr 28, 2021
CVE-2021-29654
7.2

CVE-2021-29654 is a deserialization vulnerability in AjaxSearchPro's administration panel import database feature that allows remote code execution. A...

Apr 14, 2021
CVE-2020-10657
7.2

CVE-2020-10657 is a remote code execution vulnerability in Proofpoint Insider Threat Management Server (formerly ObserveIT Server) that allows authent...

Jan 6, 2021
CVE-2020-14030
7.2

This vulnerability in Ozeki NG SMS Gateway allows attackers to achieve remote code execution by exploiting insecure .NET deserialization. Attackers ca...

Sep 30, 2020
CVE-2025-12844
7.1

The AI Engine WordPress plugin is vulnerable to PHP Object Injection via PHAR deserialization in functions handling audio transcription and vision que...

Nov 13, 2025
CVE-2024-45854
7.1

This vulnerability allows remote code execution on MindsDB servers through deserialization of untrusted data in uploaded models. Attackers can execute...

Sep 12, 2024
CVE-2023-6378
7.1

A serialization vulnerability in logback's receiver component (versions 1.4.11 and earlier) allows attackers to send maliciously crafted data that cau...

Nov 29, 2023
CVE-2025-66214
7.0

This vulnerability in Ladybug allows attackers to upload malicious XML files that get deserialized, leading to remote code execution on the server. An...

Dec 9, 2025
CVE-2025-59285
7.0

CVE-2025-59285 is a deserialization vulnerability in Azure Monitor Agent that allows authenticated attackers to execute arbitrary code with elevated p...

Oct 14, 2025
CVE-2023-38155
7.0

CVE-2023-38155 is a remote code execution vulnerability in Azure DevOps Server that allows authenticated attackers to execute arbitrary code on affect...

Sep 12, 2023
CVE-2026-28277
6.8

CVE-2026-28277 is a deserialization vulnerability in LangGraph SQLite Checkpoint that allows arbitrary code execution when loading maliciously crafted...

Mar 5, 2026
CVE-2025-59713
6.8

CVE-2025-59713 is an unsafe deserialization vulnerability in Snipe-IT versions before 8.1.18 that could allow remote code execution. This affects all ...

Sep 19, 2025
CVE-2024-39673
6.8

This vulnerability involves a serialization/deserialization mismatch in Huawei's iAware module that could allow attackers to access sensitive informat...

Jul 25, 2024
CVE-2025-24794
6.7

The Snowflake Connector for Python uses pickle for OCSP response cache serialization, allowing local attackers to execute arbitrary code via cache poi...

Jan 29, 2025
CVE-2026-27794
6.6

LangGraph Checkpoint versions before 4.0.0 contain a remote code execution vulnerability in the caching layer when applications enable cache backends ...

Feb 25, 2026
CVE-2025-39565
6.6

A PHP object injection vulnerability in Melapress Login Security WordPress plugin allows attackers to execute arbitrary code through deserialization o...

Apr 16, 2025

About Deserialization of Untrusted Data (CWE-502)

The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.

Our database tracks 1,050 CVEs classified as CWE-502, with 518 rated critical and 476 rated high severity. The average CVSS score for Deserialization of Untrusted Data vulnerabilities is 8.8.

External reference: View CWE-502 on MITRE CWE →

Monitor Deserialization of Untrusted Data Vulnerabilities

Get alerted when new Deserialization of Untrusted Data CVEs affect your infrastructure.

Start Monitoring Free