CWE-502

Medium likelihood

Deserialization of Untrusted Data

Parent: CWE-913 - Improper Control of Dynamically-Managed Code Resources

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

2,421 vulnerabilities with CWE-502
CVE-2026-2020 HIGH
WordPress JS Archive List <=6.1.7 - Deserialization
CVSS 7.5
CVE-2026-28277 MEDIUM
LangGraph SQLite Checkpoint <=1.0.9 - Deserialization
CVSS 6.8
CVE-2026-27749 HIGH
Avira Internet Security - Deserialization
CVSS 7.8
CVE-2026-2599 CRITICAL
Database for Contact Form 7 <1.4.7 - Deserialization
CVSS 9.8
CVE-2026-28105 CRITICAL
ThemeREX Good Energy <=1.7.7 - Deserialization
CVSS 9.8
CVE-2026-28074 CRITICAL
ThemeREX Pizza House <=1.4.0 - Deserialization
CVSS 9.8
CVE-2026-27439 CRITICAL
ThemeREX Dentario <=1.5 - Deserialization
CVSS 9.8
CVE-2026-27438 CRITICAL
ThemeREX Kingler <=1.7 - Deserialization
CVSS 9.8
CVE-2026-27437 CRITICAL
ThemeREX Tennis Club <=1.2.3 - Deserialization
CVSS 9.8
CVE-2026-27417 CRITICAL
SeventhQueen Sweet Date <4.0.1 - Deserialization
CVSS 9.8
CVE-2026-27379 HIGH
NextScripts social-networks-auto-poster <=4.4.7 - Deserialization
CVSS 8.8
CVE-2026-27369
BoldThemes Celeste <=1.3.6 - Deserialization
CVE-2026-27338
AivahThemes Car Zone <=3.7 - Deserialization
CVE-2026-27098 HIGH
axiomthemes Au Pair Agency <=1.2.2 - Deserialization
CVSS 8.1
CVE-2026-24385 HIGH
Podlove Web Player <=5.9.1 - Deserialization
CVSS 7.5
CVE-2026-23798 HIGH
blubrry PowerPress Podcasting <=11.15.10 - Deserialization
CVSS 8.8
CVE-2026-22501 CRITICAL
Mounthood <=1.3.2 - Deserialization
CVSS 9.8
CVE-2026-22497
AncoraThemes Jardi <=1.7.2 - Deserialization
CVE-2026-22475 CRITICAL
axiomthemes Estate <=1.3.4 - Deserialization
CVSS 9.8
CVE-2026-22474
ThemeREX Equestrian Centre <=1.5 - Deserialization
CVE-2026-22473 HIGH
Dental Clinic <=3.7 - Deserialization
CVSS 8.8
CVE-2026-22471
Secudeal Payments for Ecommerce <=1.1 - Deserialization
CVE-2026-22454
ThemeREX Solaris <=2.5 - Deserialization
CVE-2026-22453
ThemeREX Pets Club <=2.3 - Deserialization
CVE-2026-22451
AncoraThemes Handyman <=1.4 - Deserialization
Details
Vulnerabilities 2,421
Exploit Likelihood Medium