CWE-502

Medium likelihood

Deserialization of Untrusted Data

Parent: CWE-913 - Improper Control of Dynamically-Managed Code Resources

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

2,987 vulnerabilities with CWE-502
CVE-2026-39545 HIGH
WordPress Zermatt theme <= 1.6.1 - PHP Object Injection vulnerability
CVSS 8.1
CVE-2026-39539 HIGH
WordPress Alloggio - Hotel Booking theme <= 2.1.2 - PHP Object Injection vulnerability
CVSS 8.1
CVE-2026-39529 CRITICAL
WordPress Elementra theme <= 1.0.9 - PHP Object Injection vulnerability
CVSS 9.8
CVE-2026-39446 HIGH
WordPress Kapee theme < 1.7.0 - PHP Object Injection vulnerability
CVSS 8.1
CVE-2026-39443 HIGH
WordPress EmallShop theme <= 2.4.21 - PHP Object Injection vulnerability
CVSS 8.1
CVE-2026-27429 CRITICAL
WordPress Nifty theme <= 1.4.1 - PHP Object Injection vulnerability
CVSS 9.8
CVE-2026-27410 MEDIUM
WordPress Slimstat Analytics plugin < 5.4.0 - Deserialization of untrusted data vulnerability
CVSS 6.5
CVE-2026-12256 HIGH
WordPress Avada theme <= 3.15.3 - PHP Object Injection vulnerability
CVSS 8.8
CVE-2026-12115 MEDIUM
Counter Box <= 2.0.13 - Authenticated (Administrator+) PHP Object Injection via Import
CVSS 6.6
CVE-2026-11857 HIGH
Quanos SCHEMA ST4 Client Update Service - Local Privilege Escalation
CVE-2026-35300 CRITICAL
Oracle WebLogic Server 12.2.1.4.0 14.1.1.0.0 14.1.2.0.0 15.1.1.0.0 - Unauthenticated Remote Code Execution
CVSS 9.8
CVE-2026-48775 MEDIUM
LangGraph Checkpoint: Unsafe JSON deserialization in checkpoint loading
CVSS 6.8
CVE-2026-10748 HIGH
Nexus Repository 3 - Remote Code Execution via License Deserialization
CVE-2026-24228 HIGH
Nvidia NeMo Framework - Deserialization of Untrusted Data
CVSS 7.8
CVE-2026-48853 CRITICAL
Remote code execution and denial of service via unsafe Erlang term deserialization in elixir-grpc/grpc
CVE-2026-9691 CRITICAL
WordPress Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms plugin <= 1.1.1 - PHP Object Injection vulnerability
CVSS 9.8
CVE-2026-49781 CRITICAL
WordPress OttoKit plugin <= 1.1.27 - PHP Object Injection vulnerability
CVSS 9.8
CVE-2026-49770 CRITICAL
WordPress WP Travel Engine plugin <= 6.7.12 - PHP Object Injection vulnerability
CVSS 9.8
CVE-2026-49769 CRITICAL
WordPress wpForo Forum plugin <= 3.1.0 - PHP Object Injection vulnerability
CVSS 9.8
CVE-2026-49768 CRITICAL
WordPress Happyforms plugin <= 1.26.13 - PHP Object Injection vulnerability
CVSS 9.8
CVE-2026-49765 CRITICAL
WordPress Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms plugin <= 1.1.8 - PHP Object Injection vulnerability
CVSS 9.8
CVE-2026-49763 CRITICAL
WordPress Integration for Contact Form 7 HubSpot plugin <= 1.3.7 - PHP Object Injection vulnerability
CVSS 9.8
CVE-2026-49109 CRITICAL
WordPress Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms plugin <= 1.4.3 - PHP Object Injection vulnerability
CVSS 9.8
CVE-2026-49106 CRITICAL
WordPress Integration for Contact Form 7 and Constant Contact plugin <= 1.1.6 - PHP Object Injection vulnerability
CVSS 9.8
CVE-2026-49105 CRITICAL
WordPress WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms plugin <= 1.1.4 - PHP Object Injection vulnerability
CVSS 9.8
Details
Vulnerabilities 2,987
Exploit Likelihood Medium