CWE-470
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')
The product uses external input with reflection to select which classes or code to use, but it does not sufficiently prevent the input from selecting improper classes or code.
61 vulnerabilities with CWE-470
CVE-2026-48517
HIGH
MessagePack-CSharp: Typeless deserialization type restrictions do not recurse into arrays or generic arguments
CVSS 7.5
CVE-2026-48502
HIGH
MessagePack-CSharp ReadDateTime - Stack Overflow Denial of Service
CVSS 7.5
CVE-2026-49287
HIGH
Statamic CMS vulnerable to unsafe method invocation via collection sorting allows data destruction
CVSS 7.4
CVE-2026-48817
MEDIUM
Starlette: Arbitrary HTTP method dispatched to `HTTPEndpoint` attributes via `getattr`
CVSS 5.3
CVE-2026-46718
MEDIUM
Apache Calcite: A user-controled model can load arbitrary classes, leading to code execution
CVSS 6.5
CVE-2026-34216
MEDIUM
CtrlPanel: Authenticated Remote Code Execution via Dynamic Class Instantiation in SettingsController.php
CVSS 6.6
CVE-2026-8178
HIGH
Remote Code Execution via Unsafe Class Loading in Amazon Redshift JDBC Driver
CVSS 8.1
CVE-2026-44339
HIGH
PraisonAI has unsafe tool resolution in `ToolExecutionMixin.execute_tool`: undeclared `__main__` callables execute
CVSS 8.6
CVE-2026-42027
CRITICAL
Apache OpenNLP: Arbitrary Class Instantiation via Model Manifest in ExtensionLoader
CVSS 9.8
CVE-2026-41175
HIGH
Statamic: Unsafe method invocation via query value resolution allows data destruction
CVSS 8.1
CVE-2026-23923
MEDIUM
Unauthenticated arbitrary PHP class instantiation
CVE-2026-33157
HIGH
Craft CMS: Potential authenticated Remote Code Execution via malicious attached Behavior
CVSS 7.2
CVE-2026-32264
HIGH
Craft CMS vulnerable to behavior injection RCE ElementIndexesController and FieldsController
CVSS 7.2
CVE-2026-32263
HIGH
Craft CMS vulnerable to behavior injection RCE via EntryTypesController
CVSS 7.2
CVE-2026-25498
HIGH
Craft CMS 4.0.0-4.16.17 and 5.0.0-RC1-5.8.21 - Authenticated Remote Code Execution via Behavior Configuration Injection
CVSS 7.2
CVE-2025-68455
HIGH
Craft CMS 4.0.0.1-4.16.16 and 5.0.0-RC1-5.8.20 - Authenticated Remote Code Execution via Malicious Attached Behavior
CVSS 7.2
CVE-2025-34393
CRITICAL
Barracuda RMM < 2025.1.1 - Remote Code Execution via Insecure WSDL Reflection
CVSS 9.8
CVE-2025-12967
HIGH
AWS Wrappers for Amazon Aurora PostgreSQL - Privilege Escalation
CVSS 8.0
CVE-2025-63690
CRITICAL
pig-mesh Pig <= 3.8.2 Quartz - Reflection Remote Command Execution
CVSS 9.1
CVE-2025-61925
MEDIUM
Astro < 5.14.2 - Unsafe Reflection via X-Forwarded-Host Header
CVSS 6.5
CVE-2025-53693
CRITICAL
Sitecore XM/X <10.5 - Cache Poisoning
CVSS 9.8
CVE-2025-3600
HIGH
Progress Telerik UI for ASP.NET AJAX 2011.2.712-2025.1.218 - Denial of Service via Unsafe Reflection
CVSS 7.5
CVE-2025-31119
HIGH
generator-jhipster-entity-audit < 5.9.1 - Unsafe Reflection via Javers Entity Audit Framework
CVSS 7.6
CVE-2025-2794
HIGH
Kentico Xperience <= 13.0.180 - Unauthenticated Denial of Service via Unsafe Reflection
CVE-2024-4990
CRITICAL
yiisoft/yii2 2.0.48 - Code Injection
CVSS 9.1
Details
Vulnerabilities
61