← Back
CWE-502

2,964 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.

JSON object

Loading...

CVEs (2,964)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Eventum Project
1Eventum
Nov 21, 2024
Sep 5, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Controller/ListController.php in Eventum 3.5.0 is vulnerable to Deserialization of Untrusted Data. Fixed in version 3.5.2.
1Strategy11
1Formidable Form Builder
Jun 17, 2026
Aug 29, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The formidable plugin before 4.02.01 for WordPress has unsafe deserialization.
2Fork Cms
Spoon Library
2Fork Cms
Spoon Library
Jun 17, 2026
Aug 26, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Spoon Library through 2014-02-06, as used in Fork CMS before 1.4.1 and other products, allows PHP object injection via a cookie containing an object.
1Tribulant
1Newsletters
Nov 21, 2024
Aug 22, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The newsletters-lite plugin before 4.6.8.6 for WordPress has PHP object injection.
1Mirasys
1Mirasys Vms
Jun 17, 2026
Aug 22, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Mirasys VMS before V7.6.1 and 8.x before V8.3.2 mishandles the Mirasys.Common.Utils.Security.DataCrypt method in Common.dll in AuditTrailService in SMServer.exe. This method triggers insecure deserialization within the ....Show more
Mirasys VMS before V7.6.1 and 8.x before V8.3.2 mishandles the Mirasys.Common.Utils.Security.DataCrypt method in Common.dll in AuditTrailService in SMServer.exe. This method triggers insecure deserialization within the .NET garbage collector, in which a gadget (contained in a serialized object) may be executed with SYSTEM privileges. The attacker must properly encrypt the object; however, the hardcoded keys are available.Show less
1Optiontree Project
1Optiontree
Jun 17, 2026
Aug 22, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The option-tree plugin before 2.7.3 for WordPress has Object Injection because serialized classes are mishandled.
1Optiontree Project
1Optiontree
Jun 17, 2026
Aug 22, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The option-tree plugin before 2.7.3 for WordPress has Object Injection because the + character is mishandled.
1Optiontree Project
1Optiontree
Jun 17, 2026
Aug 22, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The option-tree plugin before 2.7.0 for WordPress has Object Injection by leveraging a valid nonce.
1Patreon
1Patreon Wordpress
Nov 21, 2024
Aug 22, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The patreon-connect plugin before 1.2.2 for WordPress has Object Injection.
6Apache
DebianFedoraproject+3 more
60Agile Plm
Agile Product Lifecycle Management Integration PackApplication Testing Suite+57 more
Jun 17, 2026
Aug 20, 2019
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, howev...Show more
In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.Show less
1Sap
1Commerce Cloud
Jun 17, 2026
Aug 14, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Due to unsafe deserialization used in SAP Commerce Cloud (virtualjdbc extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, it is possible to execute arbitrary code on a target machine with 'Hybris' user rights, res...Show more
Due to unsafe deserialization used in SAP Commerce Cloud (virtualjdbc extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, it is possible to execute arbitrary code on a target machine with 'Hybris' user rights, resulting in Code Injection.Show less
6Apache
DebianFasterxml+3 more
18Banking Platform
Communications Diameter Signaling RouterCommunications Instant Messaging Server+15 more
Jun 17, 2026
Jul 30, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2. This occurs when Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint...Show more
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2. This occurs when Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the logback jar in the classpath.Show less
1Apache
1Storm
Nov 21, 2024
Jul 26, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In Apache Storm versions 1.1.0 to 1.2.2, when the user is using the storm-kafka-client or storm-kafka modules, it is possible to cause the Storm UI daemon to deserialize user provided bytes into a Java class.
2Oracle
Xstream
10Banking Platform
Business Activity MonitoringCommunications Billing And Revenue Management Elastic Charging Engine+7 more
Jun 17, 2026
Jul 23, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
It was found that xstream API version 1.4.10 before 1.4.11 introduced a regression for a previous deserialization flaw. If the security framework has not been initialized, it may allow a remote attacker to run arbitrary...Show more
It was found that xstream API version 1.4.10 before 1.4.11 introduced a regression for a previous deserialization flaw. If the security framework has not been initialized, it may allow a remote attacker to run arbitrary shell commands when unmarshalling XML or any supported format. e.g. JSON. (regression of CVE-2013-7285)Show less
1Teller
1Slanger
Jun 17, 2026
Jul 15, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Slanger 0.6.0 is affected by: Remote Code Execution (RCE). The impact is: A remote attacker can execute arbitrary commands by sending a crafted request to the server. The component is: Message handler & request validator...Show more
Slanger 0.6.0 is affected by: Remote Code Execution (RCE). The impact is: A remote attacker can execute arbitrary commands by sending a crafted request to the server. The component is: Message handler & request validator. The attack vector is: Remote unauthenticated. The fixed version is: after commit 5267b455caeb2e055cccf0d2b6a22727c111f5c3.Show less
1Osbs Client Project
1Osbs Client
Jun 17, 2026
Jul 11, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A flaw was found in the yaml.load() function in the osbs-client versions since 0.46 before 0.56.1. Insecure use of the yaml.load() function allowed the user to load any suspicious object for code execution via the parsin...Show more
A flaw was found in the yaml.load() function in the osbs-client versions since 0.46 before 0.56.1. Insecure use of the yaml.load() function allowed the user to load any suspicious object for code execution via the parsing of malicious YAML files.Show less
3Fasterxml
OracleRedhat
7Clusterware
Communications Instant Messaging ServerGlobal Lifecycle Management Opatch+4 more
Nov 21, 2024
Jul 9, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.5. Use of Jackson default typing along with a gadget class from iBatis allows exfiltration of content. Fixed in 2.7.9.4, 2.8.11.2, and 2.9.6.
1Typo3
1Typo3
Jun 17, 2026
Jul 9, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
TYPO3 8.x through 8.7.26 and 9.x through 9.5.7 allows Deserialization of Untrusted Data.
3Debian
FasterxmlRedhat
3Debian Linux
Enterprise LinuxJackson Databind
Jun 17, 2026
Jun 24, 2019
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
FasterXML jackson-databind 2.x before 2.9.9.1 might allow attackers to have a variety of impacts by leveraging failure to block the logback-core class from polymorphic deserialization. Depending on the classpath content,...Show more
FasterXML jackson-databind 2.x before 2.9.9.1 might allow attackers to have a variety of impacts by leveraging failure to block the logback-core class from polymorphic deserialization. Depending on the classpath content, remote code execution may be possible.Show less
1Akamai
1Cloudtest
Jun 17, 2026
Jun 21, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Akamai CloudTest before 58.30 allows remote code execution.