CWE-502

Medium likelihood

Deserialization of Untrusted Data

Parent: CWE-913 - Improper Control of Dynamically-Managed Code Resources

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

2,594 vulnerabilities with CWE-502
CVE-2025-11739 HIGH
Product Version - Deserialization
CVE-2025-54001 CRITICAL
ThemeREX Classter <=2.5 - Deserialization
CVSS 9.8
CVE-2025-57622 CRITICAL
Step-Video-T2V - Deserialization
CVSS 9.8
CVE-2025-52998 CRITICAL
Chamilo <1.11.30 - Deserialization
CVSS 9.8
CVE-2025-50198 MEDIUM
Chamilo <1.11.30 - Deserialization
CVSS 4.9
CVE-2025-69405 CRITICAL
Lorem Ipsum | Books & Media Store <=1.2.6 - Deserialization
CVSS 9.8
CVE-2025-69404 CRITICAL
ThemeREX Extreme Store <=1.5.7 - Deserialization
CVSS 9.8
CVE-2025-69382 CRITICAL
Themesflat Elementor <=1.0.1 - Deserialization
CVSS 9.8
CVE-2025-69372 CRITICAL
AncoraThemes SevenHills <=1.6.2 - Deserialization
CVSS 9.8
CVE-2025-69371 CRITICAL
AncoraThemes KindlyCare <=1.6.1 - Deserialization
CVSS 9.8
CVE-2025-69370 CRITICAL
ThemeGoods Capella <=2.5.5 - Deserialization
CVSS 9.8
CVE-2025-69329 CRITICAL
Jthemes Prestige <1.4.1 - Deserialization
CVSS 9.8
CVE-2025-69328 HIGH
Booking and Rental Manager <=2.5.9 - Deserialization
CVSS 8.8
CVE-2025-69301 CRITICAL
ThemeGoods PhotoMe <=5.6.11 - Deserialization
CVSS 9.8
CVE-2025-69294 HIGH
PeakShops <=1.5.9 - Deserialization
CVSS 8.8
CVE-2025-68853 HIGH
Kleor Contact Manager <=9.1.1 - Deserialization
CVSS 8.8
CVE-2025-68541 CRITICAL
BoldThemes Ippsum <=1.2.0 - Deserialization
CVSS 9.8
CVE-2025-68531 HIGH
ModelTheme Addons <1.5.6 - Deserialization
CVSS 8.8
CVE-2025-68526 HIGH
Modal Popup Box <=1.6.1 - Deserialization
CVSS 8.8
CVE-2025-67997 CRITICAL
BoldThemes Travelicious <1.6.7 - Deserialization
CVSS 9.8
CVE-2025-67996 CRITICAL
BoldThemes Nestin <1.2.6 - Deserialization
CVSS 9.8
CVE-2025-67995 CRITICAL
LoftOcean PatioTime <2.1 - Deserialization
CVSS 9.8
CVE-2025-15579 CRITICAL
OpenText Directory Services 10.5-26.1 - Deserialization
CVE-2025-60038 HIGH
Rexroth IndraWorks - Deserialization RCE
CVSS 7.8
CVE-2025-60037 HIGH
Rexroth IndraWorks - Deserialization RCE
CVSS 7.8
Details
Vulnerabilities 2,594
Exploit Likelihood Medium