CWE-502: Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.
Yearly Trend
Top Affected Vendors
All Deserialization of Untrusted Data CVEs (994)
This vulnerability in the VEDA WordPress theme allows authenticated attackers with Subscriber-level access or higher to inject PHP objects through ins...
Mar 5, 2025The Donations Widget WordPress plugin contains a PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code on...
Mar 4, 2025CVE-2025-0767 is a PHP object injection vulnerability in WP Activity Log plugin that allows remote code execution. Attackers can exploit unvalidated u...
Feb 27, 2025This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the Flexmls® IDX WordPress plugin. Succe...
Feb 25, 2025The ravpage WordPress plugin is vulnerable to PHP object injection via deserialization of untrusted input in the 'paramsv2' parameter. This allows una...
Feb 20, 2025The s2Member Pro WordPress plugin is vulnerable to PHP object injection via deserialization of untrusted input in the 's2member_pro_remote_op' paramet...
Feb 15, 2025This vulnerability allows attackers to achieve remote code execution on Apache EventMesh servers by sending malicious messages that trigger unsafe des...
Feb 14, 2025The iControlWP WordPress plugin is vulnerable to PHP object injection via deserialization of untrusted input in the reqpars parameter. This allows una...
Jan 30, 2025This vulnerability allows authenticated attackers to execute arbitrary code within CVAT's Nuclio function containers by exploiting unsafe serializatio...
Jan 28, 2025This CVE describes a PHP object injection vulnerability in the Pdfcrowd Save as PDF WordPress plugin. Attackers can exploit insecure deserialization t...
Jan 27, 2025This vulnerability allows attackers to execute arbitrary code on WordPress sites running the vulnerable FundPress plugin by exploiting PHP object inje...
Jan 27, 2025A critical pre-authentication deserialization vulnerability in SonicWall SMA1000 management consoles allows remote unauthenticated attackers to execut...
Jan 23, 2025This vulnerability allows attackers to execute arbitrary code through PHP object injection by exploiting unsafe deserialization in the Muzaara Google ...
Jan 22, 2025This vulnerability allows unauthenticated attackers to perform PHP object injection through deserialization of untrusted data in the ARPrice WordPress...
Jan 21, 2025CVE-2025-22777 is a critical PHP object injection vulnerability in the GiveWP WordPress plugin that allows attackers to execute arbitrary code by expl...
Jan 13, 2025This vulnerability in the GiveWP WordPress plugin allows unauthenticated attackers to perform PHP object injection via donation form fields, leading t...
Jan 11, 2025Apache OpenMeetings versions 2.1.0 through 7.x have insecure default clustering configurations that allow deserialization of untrusted data via OpenJP...
Jan 8, 2025CVE-2024-55556 is a critical remote command execution vulnerability in Crater Invoice that allows unauthenticated attackers to execute arbitrary code ...
Jan 7, 2025This vulnerability in Apache MINA allows attackers to send malicious serialized data that can lead to remote code execution through insecure Java dese...
Dec 25, 2024This CVE describes a PHP object injection vulnerability in the Gueststream VRPConnector WordPress plugin that allows attackers to execute arbitrary co...
Dec 18, 2024This CVE describes a deserialization vulnerability in PlexTrac's Runbooks modules that allows attackers to inject malicious objects and write arbitrar...
Dec 16, 2024This vulnerability allows attackers to execute arbitrary code through PHP object injection by exploiting unsafe deserialization in ForumWP WordPress p...
Dec 16, 2024CVE-2024-54273 is a PHP object injection vulnerability in the WordPress Mail Picker plugin caused by unsafe deserialization of untrusted data. Attacke...
Dec 13, 2024This CVE describes a PHP deserialization vulnerability in ClipBucket V5 video hosting software that allows attackers to execute arbitrary code by send...
Dec 6, 2024CVE-2024-51363 is an insecure deserialization vulnerability in Hodoku versions 2.3.0 to 2.3.2 that allows attackers to execute arbitrary code on affec...
Dec 3, 2024JFinal CMS 5.1.0 contains a deserialization vulnerability in ApiForm.java that allows unauthenticated attackers to execute arbitrary commands on the s...
Dec 2, 2024This vulnerability allows arbitrary code execution through deserialization of untrusted data in Apache Arrow R package's IPC and Parquet readers. It a...
Nov 28, 2024CVE-2024-11145 is a critical deserialization vulnerability in Valor Apps Easy Folder Listing Pro for Joomla! that allows unauthenticated remote attack...
Nov 26, 2024This vulnerability allows remote attackers to execute arbitrary code on Veritas Enterprise Vault servers by sending malicious data to a .NET Remoting ...
Nov 24, 2024This vulnerability allows remote attackers to execute arbitrary code on Veritas Enterprise Vault servers by sending malicious data to a .NET Remoting ...
Nov 24, 2024This vulnerability allows remote attackers to execute arbitrary code on Veritas Enterprise Vault servers by sending malicious data to a .NET Remoting ...
Nov 24, 2024The FluentSMTP WordPress plugin is vulnerable to PHP object injection via deserialization of untrusted input, allowing unauthenticated attackers to in...
Nov 23, 2024This CVE describes a PHP object injection vulnerability in the Geolocator WordPress plugin caused by unsafe deserialization of untrusted data. Attacke...
Nov 20, 2024This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the WordPress Team Rosters plugin. All Wo...
Nov 20, 2024This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the My Geo Posts Free WordPress plugin. S...
Nov 18, 2024This vulnerability allows attackers to inject malicious PHP objects through deserialization of untrusted data in the Xin WordPress theme. Successful e...
Nov 16, 2024This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the WDES Responsive Mobile Menu WordPress...
Nov 16, 2024CVE-2024-52410 is a PHP object injection vulnerability in the Phoenixheart Referrer Detector WordPress plugin. Attackers can exploit insecure deserial...
Nov 16, 2024CVE-2021-3838 is a PHAR deserialization vulnerability in DomPDF that allows attackers to achieve remote code execution by uploading malicious files. T...
Nov 15, 2024Delta Electronics InfraSuite Device Master versions before 1.0.12 have a deserialization vulnerability in the Device-Gateway component that allows una...
Oct 30, 2024This CVE describes a PHP object injection vulnerability in the DS.DownloadList WordPress plugin caused by unsafe deserialization of untrusted data. At...
Oct 30, 2024This vulnerability allows remote code execution through deserialization in PyTorch's RemoteModule feature. It affects users running PyTorch distribute...
Oct 29, 2024This CVE describes a PHP object injection vulnerability in the Smartdevth Advanced Advertising System WordPress plugin. Attackers can exploit insecure...
Oct 20, 2024CVE-2024-49332 is a PHP object injection vulnerability in the Giveaway Boost WordPress plugin that allows attackers to execute arbitrary code through ...
Oct 20, 2024This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the My Reading Library WordPress plugin. ...
Oct 17, 2024CVE-2024-49218 is a PHP object injection vulnerability in the Recently WordPress plugin that allows attackers to execute arbitrary code through deseri...
Oct 16, 2024This CVE describes a PHP object injection vulnerability in the Telecash Ricaricaweb WordPress plugin. Attackers can exploit deserialization of untrust...
Oct 16, 2024This vulnerability allows unauthenticated attackers to perform PHP object injection via the give_company_name parameter in the GiveWP WordPress plugin...
Oct 16, 2024This CVE describes a PHP object injection vulnerability in the Talkback WordPress plugin caused by unsafe deserialization of untrusted data. Attackers...
Oct 11, 2024This vulnerability in DataEase allows attackers to execute arbitrary system commands by exploiting PostgreSQL JDBC deserialization through unfiltered ...
Oct 11, 2024About Deserialization of Untrusted Data (CWE-502)
The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.
Our database tracks 994 CVEs classified as CWE-502, with 480 rated critical and 458 rated high severity. The average CVSS score for Deserialization of Untrusted Data vulnerabilities is 8.8.
External reference: View CWE-502 on MITRE CWE →
Monitor Deserialization of Untrusted Data Vulnerabilities
Get alerted when new Deserialization of Untrusted Data CVEs affect your infrastructure.
Start Monitoring Free