Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-502

MITRE ↗

Deserialization of Untrusted Data

1,189
CRITICAL
1,464
HIGH
360
MEDIUM
26
LOW
3,107 CVEs · Page 4/63
9.8
CVE-2026-49765

Unauthenticated PHP Object Injection in Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms <=

9.8
CVE-2026-49768

Unauthenticated PHP Object Injection in Happyforms <= 1.26.13 versions.

9.8
CVE-2026-49769

Unauthenticated PHP Object Injection in wpForo Forum <= 3.1.0 versions.

9.8
CVE-2026-49770

Unauthenticated PHP Object Injection in WP Travel Engine <= 6.7.12 versions.

9.8
CVE-2026-49781

Unauthenticated PHP Object Injection in OttoKit <= 1.1.27 versions.

9.8
CVE-2026-9691

Unauthenticated PHP Object Injection in Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja For

9.8
CVE-2026-35300

Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are

9.8
CVE-2025-60205

Unauthenticated PHP Object Injection in ThemeREX Addons <= 2.36.1.1 versions.

9.8
CVE-2025-69108

Unauthenticated PHP Object Injection in Hot Coffee <= 1.7 versions.

9.8
CVE-2025-69122

Unauthenticated PHP Object Injection in SeaFood Company <= 1.4 versions.

9.8
CVE-2026-27429

Unauthenticated PHP Object Injection in Nifty <= 1.4.1 versions.

9.8
CVE-2026-39529

Unauthenticated PHP Object Injection in Elementra <= 1.0.9 versions.

9.8
CVE-2026-40725

Unauthenticated PHP Object Injection in WooCommerce Product Filters < 2.0.6 versions.

9.8
CVE-2026-42380

Unauthenticated PHP Object Injection in AI Lab < 5.4.2 versions.

9.8
CVE-2026-49075

Contributor PHP Object Injection in JetEngine <= 3.8.9.1 versions.

9.8
CVE-2026-49107

Unauthenticated PHP Object Injection in Thrive Apprentice < 10.8.10.2 versions.

9.8
CVE-2026-52706

Unauthenticated PHP Object Injection in JetEngine <= 3.8.10 versions.

9.8
CVE-2026-54194

Contributor PHP Object Injection in Fusion Builder <= 3.15.4 versions.

9.8
CVE-2026-54806

Unauthenticated PHP Object Injection in WP Activity Log <= 5.6.3.1 versions.

9.8
CVE-2025-60229

Deserialization of Untrusted Data vulnerability in Themeton Lagom allows Object Injection. This issue affects Lagom: fr

9.8
CVE-2025-60230

Deserialization of Untrusted Data vulnerability in Themeton The Barber Shop allows Object Injection. This issue affects

9.8
CVE-2025-60231

Deserialization of Untrusted Data vulnerability in EMV The Hospital nrghospital allows Object Injection. This issue aff

9.8
CVE-2025-60236

Deserialization of Untrusted Data vulnerability in EMV Creatify allows Object Injection. This issue affects Creatify: f

9.8
CVE-2025-69111

Unauthenticated PHP Object Injection in Reisen <= 1.4.1 versions.

9.8
CVE-2025-69127

Unauthenticated PHP Object Injection in Plumbing <= 1.6 versions.

9.8
CVE-2026-49108

Unauthenticated PHP Object Injection in Moderno < 1.43 versions.

9.8
CVE-2025-71321

picklescan before 0.0.33 contains an arbitrary file writing vulnerability that allows attackers to bypass the dangerous

9.8
CVE-2026-53874

picklescan before 1.0.1 contains an unsafe deserialization vulnerability allowing unauthenticated users to execute arbit

9.8
CVE-2026-53805

NVIDIA Spatial Intelligence Lab's (SIL) GEN3C contains an unauthenticated remote code execution vulnerability in the inf

9.8
CVE-2026-12569 KEV

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vul

9.8
CVE-2026-8024

A remote, unauthenticated attacker may exploit a deserialization of untrusted data vulnerability in ibaPDA or ibaDatCoor

9.8
CVE-2026-56121

Feast before 0.63.0 contains an unsafe deserialization vulnerability that allows unauthenticated or unauthorized attacke

9.8
CVE-2026-56032

Subscriber PHP Object Injection in Buddyboss Platform <= 3.0.4 versions.

9.8
CVE-2026-56057

Subscriber PHP Object Injection in Uncanny Automator Pro <= 7.3.0.6 versions.

9.8
CVE-2026-7871

IBM Langflow OSS 1.0.0 through 1.10.0 allows users with Redis access to execute arbitrary code with full application pri

9.8
CVE-2026-56700

Grav CMS before 2.0.0-beta.2 contains multiple code-execution vulnerabilities. Three unsafe unserialize() calls - in Sch

9.8
CVE-2026-58025

Deserialization of untrusted data vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated wi

9.8
CVE-2026-58126

PACSgear PACS Scan 5.2.1 contains an unauthenticated remote code execution vulnerability that allows remote attackers to

9.8
CVE-2026-58127

PACSgear MediaWriter 5.2.1 exposes a .NET Remoting TCP service on port 9000 via PacsgearMediaServerEngine.dll, registere

9.8
CVE-2026-51947

An issue in Pivotal CRM 6.6.4.08 and systems using patch-ghi-15381-cwe-502-20251225.zip (fixed in Pivotal CRM 6.6.5.10 a

9.8
CVE-2026-57621

Unauthenticated PHP Object Injection in Booktics <= 1.0.21 versions.

9.8
CVE-2026-57677

Unauthenticated PHP Object Injection in Novalnet Payment Gateway for WooCommerce <= 12.10.3 versions.

9.8
CVE-2026-12481

A vulnerability in keras-team/keras version 3.14.0 allows for arbitrary code execution due to improper handling of deser

9.8
CVE-2026-43867

Deserialization of Untrusted Data vulnerability in Apache Camel PQC Component. The camel-pqc component persists post-qu

9.8
CVE-2026-33264

A bug in `BaseSerialization.deserialize()` allowed unrestricted `import_string()` of attacker-controlled class paths whe

9.8
CVE-2026-57724

Deserialization of Untrusted Data vulnerability in Themeum Kirki kirki allows Object Injection.This issue affects Kirki:

9.8
CVE-2026-57738

Deserialization of Untrusted Data vulnerability in axiomthemes 777 triple-seven allows Object Injection.This issue affec

9.8
CVE-2026-57744

Deserialization of Untrusted Data vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows Object Injecti

9.8
CVE-2026-57770

Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Photography grandphotography allows Object Injection

9.8
CVE-2026-59518

Deserialization of Untrusted Data vulnerability in wpWax Directorist directorist allows Object Injection.This issue affe

Frequently Asked Questions

What is CWE-502?

CWE-502 (Deserialization of Untrusted Data) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-502?

There are 3,680 CVE records associated with CWE-502 in our database. Of these, 1189 are critical severity, 1464 are high severity, and 360 are medium severity.

How can I protect against CWE-502 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-502 using AI-powered security agents.

Detect CWE-502 Vulnerabilities

CyberStrike's AI agents automatically detect deserialization of untrusted data vulnerabilities across your infrastructure.

Get Started