← Back
CWE-502

3,196 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.

JSON object

Loading...

CVEs (3,196)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Pickplugins
2Post Grid
Team Showcase
Jun 17, 2026
Jan 1, 2021
N/A· v4
8.8 HIGH· v3
6.0 MEDIUM· v2
PHP Object injection vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote authenticated attackers to inject arbitrary PHP objects due to insecure unserialization of data supplied in a rem...Show more
PHP Object injection vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote authenticated attackers to inject arbitrary PHP objects due to insecure unserialization of data supplied in a remotely hosted crafted payload in the source parameter via AJAX. The action must be set to team_import_xml_layouts.Show less
1Pickplugins
2Post Grid
Team Showcase
Jun 17, 2026
Jan 1, 2021
N/A· v4
8.8 HIGH· v3
6.0 MEDIUM· v2
PHP Object injection vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authenticated attackers to inject arbitrary PHP objects due to insecure unserialization of data supplied in a remotely...Show more
PHP Object injection vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authenticated attackers to inject arbitrary PHP objects due to insecure unserialization of data supplied in a remotely hosted crafted payload in the source parameter via AJAX. The action must be set to post_grid_import_xml_layouts.Show less
1Tribulant
1Newsletter
Jun 17, 2026
Jan 1, 2021
N/A· v4
8.8 HIGH· v3
6.0 MEDIUM· v2
Insecure Deserialization in the Newsletter plugin before 6.8.2 for WordPress allows authenticated remote attackers with minimal privileges (such as subscribers) to use the tpnc_render AJAX action to inject arbitrary PHP...Show more
Insecure Deserialization in the Newsletter plugin before 6.8.2 for WordPress allows authenticated remote attackers with minimal privileges (such as subscribers) to use the tpnc_render AJAX action to inject arbitrary PHP objects via the options[inline_edits] parameter. NOTE: exploitability depends on PHP objects that might be present with certain other plugins or themes.Show less
1Qdpm
1Qdpm
Jun 17, 2026
Dec 31, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
qdPM through 9.1 allows PHP Object Injection via timeReportActions::executeExport in core/apps/qdPM/modules/timeReport/actions/actions.class.php because unserialize is used.
1Nukeviet
1Nukeviet
Jun 17, 2026
Dec 31, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
includes/core/is_user.php in NukeViet before 4.3.04 deserializes the untrusted nvloginhash cookie (i.e., the code relies on PHP's serialization format when JSON can be used to eliminate the risk).
4Debian
FasterxmlNetapp+1 more
41Agile Plm
Agile Product Lifecycle ManagementApplication Testing Suite+38 more
Aug 25, 2026
Dec 27, 2020
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.oracle.wls.shaded.org.apache.xalan.lib.sql.JNDIConnectionPool (aka embedded Xalan in org....Show more
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.oracle.wls.shaded.org.apache.xalan.lib.sql.JNDIConnectionPool (aka embedded Xalan in org.glassfish.web/javax.servlet.jsp.jstl).Show less
4Debian
FasterxmlNetapp+1 more
27Agile Plm
Agile Product Lifecycle ManagementApplication Testing Suite+24 more
Aug 25, 2026
Dec 17, 2020
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.SharedPoolDataSource.
4Debian
FasterxmlNetapp+1 more
26Agile Plm
Agile Product Lifecycle ManagementApplication Testing Suite+23 more
Aug 25, 2026
Dec 17, 2020
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.PerUserPoolDataSource.
1Jsonpickle Project
1Jsonpickle
Jun 17, 2026
Dec 17, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
jsonpickle through 1.4.1 allows remote code execution during deserialization of a malicious payload through the decode() function. Note: It has been argued that this is expected and clearly documented behaviour. pickle i...Show more
jsonpickle through 1.4.1 allows remote code execution during deserialization of a malicious payload through the decode() function. Note: It has been argued that this is expected and clearly documented behaviour. pickle is known to be capable of causing arbitrary code execution, and must not be used with un-trusted dataShow less
1Quantconnect
1Lean
Jun 17, 2026
Dec 14, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
QuantConnect Lean versions from 2.3.0.0 to 2.4.0.1 are affected by an insecure deserialization vulnerability due to insecure configuration of TypeNameHandling property in Json.NET library.
1Linuxfoundation
1Spinnaker
Jun 17, 2026
Dec 11, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Nolan Ray from Apple Information Security identified a security vulnerability in Spinnaker, all versions prior to version 1.23.4, 1.22.4 or 1.21.5. The vulnerability exists within the handling of SpEL expressions that al...Show more
Nolan Ray from Apple Information Security identified a security vulnerability in Spinnaker, all versions prior to version 1.23.4, 1.22.4 or 1.21.5. The vulnerability exists within the handling of SpEL expressions that allows an attacker to read and write arbitrary files within the orca container via authenticated HTTP POST requests.Show less
1Microsoft
1Exchange Server
Jun 17, 2026
Dec 10, 2020
N/A· v4
8.8 HIGH· v3
6.0 MEDIUM· v2
Microsoft Exchange Remote Code Execution Vulnerability
1Apache
1Tapestry
Jun 17, 2026
Dec 8, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A Java Serialization vulnerability was found in Apache Tapestry 4. Apache Tapestry 4 will attempt to deserialize the "sp" parameter even before invoking the page's validate method, leading to deserialization without auth...Show more
A Java Serialization vulnerability was found in Apache Tapestry 4. Apache Tapestry 4 will attempt to deserialize the "sp" parameter even before invoking the page's validate method, leading to deserialization without authentication. Apache Tapestry 4 reached end of life in 2008 and no update to address this issue will be released. Apache Tapestry 5 versions are not vulnerable to this issue. Users of Apache Tapestry 4 should upgrade to the latest Apache Tapestry 5 version.Show less
4Debian
DrupalFedoraproject+1 more
4Archive Tar
Debian LinuxDrupal+1 more
Jun 17, 2026
Nov 19, 2020
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Archive_Tar through 1.4.10 allows an unserialization attack because phar: is blocked but PHAR: is not blocked.
1Cisco
1Security Manager
Jun 17, 2026
Nov 17, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Multiple vulnerabilities in the Java deserialization function that is used by Cisco Security Manager could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. These vulnerabilit...Show more
Multiple vulnerabilities in the Java deserialization function that is used by Cisco Security Manager could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. These vulnerabilities are due to insecure deserialization of user-supplied content by the affected software. An attacker could exploit these vulnerabilities by sending a malicious serialized Java object to a specific listener on an affected system. A successful exploit could allow the attacker to execute arbitrary commands on the device with the privileges of NT AUTHORITY\SYSTEM on the Windows target host. Cisco has not released software updates that address these vulnerabilities.Show less
1Riken
1Xoonips
Jun 17, 2026
Nov 16, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Deserialization of untrusted data vulnerability in XooNIps 3.49 and earlier allows remote attackers to execute arbitrary code via unspecified vectors.
1Welcart
1Welcart E Commerce
Jun 17, 2026
Nov 7, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The usc-e-shop (aka Collne Welcart e-Commerce) plugin before 1.9.36 for WordPress allows Object Injection because of usces_unserialize. There is not a complete POP chain.
1Databaseschemareader Project
1Dbschemareader
Jun 17, 2026
Nov 4, 2020
N/A· v4
8.0 HIGH· v3
6.8 MEDIUM· v2
DatabaseSchemaViewer before version 2.7.4.3 is vulnerable to arbitrary code execution if a user is tricked into opening a specially crafted `.dbschema` file. The patch was released in v2.7.4.3. As a workaround, ensure `....Show more
DatabaseSchemaViewer before version 2.7.4.3 is vulnerable to arbitrary code execution if a user is tricked into opening a specially crafted `.dbschema` file. The patch was released in v2.7.4.3. As a workaround, ensure `.dbschema` files from untrusted sources are not opened.Show less
3Debian
FedoraprojectWordpress
3Debian Linux
FedoraWordpress
Jun 17, 2026
Nov 2, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
WordPress before 5.5.2 mishandles deserialization requests in wp-includes/Requests/Utility/FilteredIterator.php.
1Redhat
1Fabric8 Maven
Jun 17, 2026
Oct 22, 2020
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
A flaw was found in the fabric8-maven-plugin 4.0.0 and later. When using a wildfly-swarm or thorntail custom configuration, a malicious YAML configuration file on the local machine executing the maven plug-in could allow...Show more
A flaw was found in the fabric8-maven-plugin 4.0.0 and later. When using a wildfly-swarm or thorntail custom configuration, a malicious YAML configuration file on the local machine executing the maven plug-in could allow for deserialization of untrusted data resulting in arbitrary code execution. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.Show less