CWE-502: Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.

994
Total CVEs
480
Critical
458
High
8.8
Avg CVSS
10
In CISA KEV

Yearly Trend

2026
83
2025
398
2024
223
2023
129
2022
34

Top Affected Vendors

1 Apache 57
2 Microsoft 35
3 Solarwinds 19
4 Ibm 16
5 Debian 14
6 Adobe 14
7 Oracle 12
8 Netapp 10
9 Givewp 9
10 Ivanti 9

All Deserialization of Untrusted Data CVEs (994)

CVE-2024-13787
9.8

This vulnerability in the VEDA WordPress theme allows authenticated attackers with Subscriber-level access or higher to inject PHP objects through ins...

Mar 5, 2025
CVE-2025-0912
9.8

The Donations Widget WordPress plugin contains a PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code on...

Mar 4, 2025
CVE-2025-0767
9.8

CVE-2025-0767 is a PHP object injection vulnerability in WP Activity Log plugin that allows remote code execution. Attackers can exploit unvalidated u...

Feb 27, 2025
CVE-2025-26900
9.8

This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the Flexmls® IDX WordPress plugin. Succe...

Feb 25, 2025
CVE-2024-13789
9.8

The ravpage WordPress plugin is vulnerable to PHP object injection via deserialization of untrusted input in the 'paramsv2' parameter. This allows una...

Feb 20, 2025
CVE-2024-12562
9.8

The s2Member Pro WordPress plugin is vulnerable to PHP object injection via deserialization of untrusted input in the 's2member_pro_remote_op' paramet...

Feb 15, 2025
CVE-2024-56180
9.8

This vulnerability allows attackers to achieve remote code execution on Apache EventMesh servers by sending malicious messages that trigger unsafe des...

Feb 14, 2025
CVE-2024-13742
9.8

The iControlWP WordPress plugin is vulnerable to PHP object injection via deserialization of untrusted input in the reqpars parameter. This allows una...

Jan 30, 2025
CVE-2025-23045
9.8

This vulnerability allows authenticated attackers to execute arbitrary code within CVAT's Nuclio function containers by exploiting unsafe serializatio...

Jan 28, 2025
CVE-2025-24671
9.8

This CVE describes a PHP object injection vulnerability in the Pdfcrowd Save as PDF WordPress plugin. Attackers can exploit insecure deserialization t...

Jan 27, 2025
CVE-2025-24601
9.8

This vulnerability allows attackers to execute arbitrary code on WordPress sites running the vulnerable FundPress plugin by exploiting PHP object inje...

Jan 27, 2025
CVE-2025-23006
KEV EPSS 38.7% 9.8

A critical pre-authentication deserialization vulnerability in SonicWall SMA1000 management consoles allows remote unauthenticated attackers to execut...

Jan 23, 2025
CVE-2025-23914
9.8

This vulnerability allows attackers to execute arbitrary code through PHP object injection by exploiting unsafe deserialization in the Muzaara Google ...

Jan 22, 2025
CVE-2024-49688
9.8

This vulnerability allows unauthenticated attackers to perform PHP object injection through deserialization of untrusted data in the ARPrice WordPress...

Jan 21, 2025
CVE-2025-22777
9.8

CVE-2025-22777 is a critical PHP object injection vulnerability in the GiveWP WordPress plugin that allows attackers to execute arbitrary code by expl...

Jan 13, 2025
CVE-2024-12877
EPSS 32.9% 9.8

This vulnerability in the GiveWP WordPress plugin allows unauthenticated attackers to perform PHP object injection via donation form fields, leading t...

Jan 11, 2025
CVE-2024-54676
9.8

Apache OpenMeetings versions 2.1.0 through 7.x have insecure default clustering configurations that allow deserialization of untrusted data via OpenJP...

Jan 8, 2025
CVE-2024-55556
EPSS 86.9% 9.8

CVE-2024-55556 is a critical remote command execution vulnerability in Crater Invoice that allows unauthenticated attackers to execute arbitrary code ...

Jan 7, 2025
CVE-2024-52046
9.8

This vulnerability in Apache MINA allows attackers to send malicious serialized data that can lead to remote code execution through insecure Java dese...

Dec 25, 2024
CVE-2024-56058
9.8

This CVE describes a PHP object injection vulnerability in the Gueststream VRPConnector WordPress plugin that allows attackers to execute arbitrary co...

Dec 18, 2024
CVE-2024-12687
9.8

This CVE describes a deserialization vulnerability in PlexTrac's Runbooks modules that allows attackers to inject malicious objects and write arbitrar...

Dec 16, 2024
CVE-2024-54367
9.8

This vulnerability allows attackers to execute arbitrary code through PHP object injection by exploiting unsafe deserialization in ForumWP WordPress p...

Dec 16, 2024
CVE-2024-54273
9.8

CVE-2024-54273 is a PHP object injection vulnerability in the WordPress Mail Picker plugin caused by unsafe deserialization of untrusted data. Attacke...

Dec 13, 2024
CVE-2024-54135
9.8

This CVE describes a PHP deserialization vulnerability in ClipBucket V5 video hosting software that allows attackers to execute arbitrary code by send...

Dec 6, 2024
CVE-2024-51363
9.8

CVE-2024-51363 is an insecure deserialization vulnerability in Hodoku versions 2.3.0 to 2.3.2 that allows attackers to execute arbitrary code on affec...

Dec 3, 2024
CVE-2024-53477
9.8

JFinal CMS 5.1.0 contains a deserialization vulnerability in ApiForm.java that allows unauthenticated attackers to execute arbitrary commands on the s...

Dec 2, 2024
CVE-2024-52338
9.8

This vulnerability allows arbitrary code execution through deserialization of untrusted data in Apache Arrow R package's IPC and Parquet readers. It a...

Nov 28, 2024
CVE-2024-11145
9.8

CVE-2024-11145 is a critical deserialization vulnerability in Valor Apps Easy Folder Listing Pro for Joomla! that allows unauthenticated remote attack...

Nov 26, 2024
CVE-2024-53911
9.8

This vulnerability allows remote attackers to execute arbitrary code on Veritas Enterprise Vault servers by sending malicious data to a .NET Remoting ...

Nov 24, 2024
CVE-2024-53913
9.8

This vulnerability allows remote attackers to execute arbitrary code on Veritas Enterprise Vault servers by sending malicious data to a .NET Remoting ...

Nov 24, 2024
CVE-2024-53915
9.8

This vulnerability allows remote attackers to execute arbitrary code on Veritas Enterprise Vault servers by sending malicious data to a .NET Remoting ...

Nov 24, 2024
CVE-2024-9511
9.8

The FluentSMTP WordPress plugin is vulnerable to PHP object injection via deserialization of untrusted input, allowing unauthenticated attackers to in...

Nov 23, 2024
CVE-2024-52443
9.8

This CVE describes a PHP object injection vulnerability in the Geolocator WordPress plugin caused by unsafe deserialization of untrusted data. Attacke...

Nov 20, 2024
CVE-2024-52439
9.8

This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the WordPress Team Rosters plugin. All Wo...

Nov 20, 2024
CVE-2024-52433
9.8

This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the My Geo Posts Free WordPress plugin. S...

Nov 18, 2024
CVE-2024-52412
9.8

This vulnerability allows attackers to inject malicious PHP objects through deserialization of untrusted data in the Xin WordPress theme. Successful e...

Nov 16, 2024
CVE-2024-52414
9.8

This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the WDES Responsive Mobile Menu WordPress...

Nov 16, 2024
CVE-2024-52410
9.8

CVE-2024-52410 is a PHP object injection vulnerability in the Phoenixheart Referrer Detector WordPress plugin. Attackers can exploit insecure deserial...

Nov 16, 2024
CVE-2021-3838
9.8

CVE-2021-3838 is a PHAR deserialization vulnerability in DomPDF that allows attackers to achieve remote code execution by uploading malicious files. T...

Nov 15, 2024
CVE-2024-10456
9.8

Delta Electronics InfraSuite Device Master versions before 1.0.12 have a deserialization vulnerability in the Device-Gateway component that allows una...

Oct 30, 2024
CVE-2024-50507
9.8

This CVE describes a PHP object injection vulnerability in the DS.DownloadList WordPress plugin caused by unsafe deserialization of untrusted data. At...

Oct 30, 2024
CVE-2024-48063
9.8

This vulnerability allows remote code execution through deserialization in PyTorch's RemoteModule feature. It affects users running PyTorch distribute...

Oct 29, 2024
CVE-2024-49624
9.8

This CVE describes a PHP object injection vulnerability in the Smartdevth Advanced Advertising System WordPress plugin. Attackers can exploit insecure...

Oct 20, 2024
CVE-2024-49332
9.8

CVE-2024-49332 is a PHP object injection vulnerability in the Giveaway Boost WordPress plugin that allows attackers to execute arbitrary code through ...

Oct 20, 2024
CVE-2024-49318
9.8

This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the My Reading Library WordPress plugin. ...

Oct 17, 2024
CVE-2024-49218
9.8

CVE-2024-49218 is a PHP object injection vulnerability in the Recently WordPress plugin that allows attackers to execute arbitrary code through deseri...

Oct 16, 2024
CVE-2024-48030
9.8

This CVE describes a PHP object injection vulnerability in the Telecash Ricaricaweb WordPress plugin. Attackers can exploit deserialization of untrust...

Oct 16, 2024
CVE-2024-9634
9.8

This vulnerability allows unauthenticated attackers to perform PHP object injection via the give_company_name parameter in the GiveWP WordPress plugin...

Oct 16, 2024
CVE-2024-48033
9.8

This CVE describes a PHP object injection vulnerability in the Talkback WordPress plugin caused by unsafe deserialization of untrusted data. Attackers...

Oct 11, 2024
CVE-2024-47074
9.8

This vulnerability in DataEase allows attackers to execute arbitrary system commands by exploiting PostgreSQL JDBC deserialization through unfiltered ...

Oct 11, 2024

About Deserialization of Untrusted Data (CWE-502)

The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.

Our database tracks 994 CVEs classified as CWE-502, with 480 rated critical and 458 rated high severity. The average CVSS score for Deserialization of Untrusted Data vulnerabilities is 8.8.

External reference: View CWE-502 on MITRE CWE →

Monitor Deserialization of Untrusted Data Vulnerabilities

Get alerted when new Deserialization of Untrusted Data CVEs affect your infrastructure.

Start Monitoring Free