CWE-502— Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.— MITRE CWE catalog
2,874 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-502page 44 of 58
- CVE-2025-60039CRITICALCVSS 9.8EG 9.82025-10-22
Deserialization of Untrusted Data vulnerability in rascals Noisa noisa allows Object Injection.This issue affects Noisa: from n/a through <= 2.6.0.
- CVE-2025-60080HIGHCVSS 7.5EG 7.52025-12-18
Deserialization of Untrusted Data vulnerability in add-ons.org PDF for Gravity Forms + Drag And Drop Template Builder pdf-for-gravity-forms allows Object Injection.This issue affects PDF for Gravity Forms + Drag And Drop Template Builder: …
- CVE-2025-60081HIGHCVSS 8.8EG 8.82025-12-18
Deserialization of Untrusted Data vulnerability in add-ons.org PDF for Contact Form 7 pdf-for-contact-form-7 allows Object Injection.This issue affects PDF for Contact Form 7: from n/a through <= 6.5.0.
- CVE-2025-60082HIGHCVSS 8.8EG 8.82025-12-18
Deserialization of Untrusted Data vulnerability in add-ons.org PDF for WPForms pdf-for-wpforms allows Object Injection.This issue affects PDF for WPForms: from n/a through <= 6.5.0.
- CVE-2025-60083HIGHCVSS 8.8EG 8.82025-12-18
Deserialization of Untrusted Data vulnerability in add-ons.org PDF Invoice Builder for WooCommerce pdf-for-woocommerce allows Object Injection.This issue affects PDF Invoice Builder for WooCommerce: from n/a through <= 6.5.0.
- CVE-2025-60084HIGHCVSS 8.8EG 8.82025-12-18
Deserialization of Untrusted Data vulnerability in add-ons.org PDF for Elementor Forms + Drag And Drop Template Builder pdf-for-elementor-forms allows Object Injection.This issue affects PDF for Elementor Forms + Drag And Drop Template Bui…
- CVE-2025-60089CRITICALCVSS 9.8EG 9.82025-12-18
Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms FreshDesk Plugin gf-freshdesk allows Object Injection.This issue affects WP Gravity Forms FreshDesk Plugin: from n/a through <= 1.3.5.
- CVE-2025-60090CRITICALCVSS 9.8EG 9.82025-12-18
Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Insightly gf-insightly allows Object Injection.This issue affects WP Gravity Forms Insightly: from n/a through <= 1.1.6.
- CVE-2025-60091CRITICALCVSS 9.8EG 9.82025-12-18
Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Zoho CRM and Bigin gf-zoho allows Object Injection.This issue affects WP Gravity Forms Zoho CRM and Bigin: from n/a through <= 1.2.9.
- CVE-2025-60174CRITICALCVSS 9.8EG 9.82025-12-18
Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Constant Contact Plugin gf-constant-contact allows Object Injection.This issue affects WP Gravity Forms Constant Contact Plugin: from n/a through <= 1.1.2.
- CVE-2025-60178CRITICALCVSS 9.8EG 9.82025-12-18
Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms HubSpot gf-hubspot allows Object Injection.This issue affects WP Gravity Forms HubSpot: from n/a through <= 1.2.6.
- CVE-2025-60180CRITICALCVSS 9.8EG 9.82025-12-18
Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Salesforce gf-salesforce-crmperks allows Object Injection.This issue affects WP Gravity Forms Salesforce: from n/a through <= 1.5.1.
- CVE-2025-60205CRITICALCVSS 9.8EG 9.82026-06-17
Unauthenticated PHP Object Injection in ThemeREX Addons <= 2.36.1.1 versions.
- CVE-2025-60209CRITICALCVSS 9.8EG 9.82025-10-22
Deserialization of Untrusted Data vulnerability in CRM Perks Connector for Gravity Forms and Google Sheets wp-gravity-forms-spreadsheets allows Object Injection.This issue affects Connector for Gravity Forms and Google Sheets: from n/a thr…
- CVE-2025-60210CRITICALCVSS 9.8EG 9.82025-10-22
Deserialization of Untrusted Data vulnerability in wpeverest Everest Forms - Frontend Listing everest-forms-frontend-listing allows Object Injection.This issue affects Everest Forms - Frontend Listing: from n/a through <= 1.0.5.
- CVE-2025-60212HIGHCVSS 8.8EG 8.82025-10-22
Deserialization of Untrusted Data vulnerability in designthemes VEDA veda allows Object Injection.This issue affects VEDA: from n/a through <= 4.2.
- CVE-2025-60213CRITICALCVSS 9.8EG 9.82025-10-22
Deserialization of Untrusted Data vulnerability in Whitebox-Studio Scape scape allows Object Injection.This issue affects Scape: from n/a through <= 1.5.13.
- CVE-2025-60214CRITICALCVSS 9.8EG 9.82025-10-22
Deserialization of Untrusted Data vulnerability in BoldThemes Goldenblatt goldenblatt allows Object Injection.This issue affects Goldenblatt: from n/a through < 1.3.0.
- CVE-2025-60215HIGHCVSS 8.8EG 8.82025-10-22
Deserialization of Untrusted Data vulnerability in designthemes Kriya kriya allows Object Injection.This issue affects Kriya: from n/a through <= 3.4.
- CVE-2025-60216CRITICALCVSS 9.8EG 9.82025-10-22
Deserialization of Untrusted Data vulnerability in BoldThemes Addison addison allows Object Injection.This issue affects Addison: from n/a through < 1.4.8.
- CVE-2025-60221CRITICALCVSS 9.8EG 9.82025-10-22
Deserialization of Untrusted Data vulnerability in captivateaudio Captivate Sync captivatesync-trade allows Object Injection.This issue affects Captivate Sync: from n/a through <= 3.0.3.
- CVE-2025-60224CRITICALCVSS 9.8EG 9.82025-10-22
Deserialization of Untrusted Data vulnerability in wpshuffle Subscribe to Download subscribe-to-download allows Object Injection.This issue affects Subscribe to Download: from n/a through <= 2.0.9.
- CVE-2025-60225CRITICALCVSS 9.8EG 9.82025-10-22
Deserialization of Untrusted Data vulnerability in AncoraThemes BugsPatrol bugspatrol allows Object Injection.This issue affects BugsPatrol: from n/a through <= 1.5.0.
- CVE-2025-60226CRITICALCVSS 9.8EG 9.82025-10-22
Deserialization of Untrusted Data vulnerability in axiomthemes White Rabbit whiterabbit allows Object Injection.This issue affects White Rabbit: from n/a through <= 1.5.2.
- CVE-2025-60228HIGHCVSS 8.8EG 8.82025-10-22
Deserialization of Untrusted Data vulnerability in designthemes Knowledge Base kbase allows Object Injection.This issue affects Knowledge Base: from n/a through <= 2.9.
- CVE-2025-60229CRITICALCVSS 9.8EG 9.82026-06-17
Deserialization of Untrusted Data vulnerability in Themeton Lagom allows Object Injection. This issue affects Lagom: from n/a through 2.0.
- CVE-2025-60230CRITICALCVSS 9.8EG 9.82026-06-17
Deserialization of Untrusted Data vulnerability in Themeton The Barber Shop allows Object Injection. This issue affects The Barber Shop: from n/a through 1.9.
- CVE-2025-60231CRITICALCVSS 9.8EG 9.82026-06-17
Deserialization of Untrusted Data vulnerability in EMV The Hospital nrghospital allows Object Injection. This issue affects The Hospital: from n/a through 1.8.1.
- CVE-2025-60232CRITICALCVSS 9.8EG 9.82025-10-22
Deserialization of Untrusted Data vulnerability in quantumcloud KBx Pro Ultimate knowledgebase-helpdesk-pro allows Object Injection.This issue affects KBx Pro Ultimate: from n/a through <= 8.0.5.
- CVE-2025-60233CRITICALCVSS 9.8EG 9.82026-03-19
Deserialization of Untrusted Data vulnerability in Themeton Zuut allows Object Injection.This issue affects Zuut: from n/a through 1.4.2.
- CVE-2025-60234HIGHCVSS 8.8EG 8.82025-10-22
Deserialization of Untrusted Data vulnerability in designthemes Single Property single-property allows Object Injection.This issue affects Single Property: from n/a through <= 2.8.
- CVE-2025-60236CRITICALCVSS 9.8EG 9.82026-06-17
Deserialization of Untrusted Data vulnerability in EMV Creatify allows Object Injection. This issue affects Creatify: from n/a through 1.5.
- CVE-2025-60237CRITICALCVSS 9.8EG 9.82026-03-19
Deserialization of Untrusted Data vulnerability in Themeton Finag allows Object Injection.This issue affects Finag: from n/a through 1.5.0.
- CVE-2025-60238CRITICALCVSS 9.8EG 9.82025-10-22
Deserialization of Untrusted Data vulnerability in universam UNIVERSAM universam-demo allows Object Injection.This issue affects UNIVERSAM: from n/a through <= 9.04.02.
- CVE-2025-60245CRITICALCVSS 9.8EG 9.82025-11-06
Deserialization of Untrusted Data vulnerability in WP User Manager WP User Manager wp-user-manager allows Object Injection.This issue affects WP User Manager: from n/a through <= 2.9.12.
- CVE-2025-60455HIGHCVSS 8.4EG 8.42025-11-18
Unsafe Deserialization vulnerability in Modular Max Serve before 25.6, specifically when the "--experimental-enable-kvcache-agent" feature is used allowing attackers to execute arbitrary code.
- CVE-2025-60828MEDIUMCVSS 6.5EG 6.52025-10-08
WukongCRM-9.0-JAVA was discovered to contain a fastjson deserialization vulnerability via the /OaExamine/setOaExamine interface.
- CVE-2025-60830MEDIUMCVSS 6.5EG 6.52025-10-08
redragon-erp v1.0 was discovered to contain a Shiro deserialization vulnerability caused by the default Shiro key.
- CVE-2025-60834MEDIUMCVSS 6.5EG 6.52025-10-08
A fastjson deserialization vulnerability in uzy-ssm-mall v1.1.0 allows attackers to execute arbitrary code via supplying a crafted input.
- CVE-2025-60887MEDIUMCVSS 5.3EG 5.32026-04-28
An issue was discovered in Cista v0.15 and below. Insecure deserialization of untrusted input under certain conditions may lead to leaking of stack/heap addresses which may be used to bypass ASLR. Classes with pointer-like mechanics under …
- CVE-2025-60889CRITICALCVSS 9.8EG 9.82026-04-28
Insecure deserialization of untrusted input in StellarGroup HPX 1.11.0 under certain conditions may allow attackers to execute arbitrary code or other unspecified impacts.
- CVE-2025-61140CRITICALCVSS 9.8EG 9.82026-01-28
The value function in jsonpath 1.1.1 lib/index.js is vulnerable to Prototype Pollution.
- CVE-2025-61168CRITICALCVSS 9.8EG 9.82025-11-25
An issue in the cms_rest.php component of SIGB PMB v8.0.1.14 allows attackers to execute arbitrary code via unserializing an arbitrary file.
- CVE-2025-61505MEDIUMCVSS 6.5EG 6.52025-10-10
e107 CMS thru 2.3.3 are vulnerable to insecure deserialization in the `install.php` script. The script processes user-controlled input in the `previous_steps` POST parameter using `unserialize(base64_decode())` without validation, allowing…
- CVE-2025-61622CRITICALCVSS 9.8EG 9.82025-10-01
Deserialization of untrusted data in python in pyfory versions 0.12.0 through 0.12.2, or the legacy pyfury versions from 0.1.0 through 0.10.3: allows arbitrary code execution. An application is vulnerable if it reads pyfory serialized…
- CVE-2025-61677LOWCVSS 2.5EG 2.52025-10-03
DataChain is a Python-based AI-data warehouse for transforming and analyzing unstructured data. Versions 0.34.1 and below allow for deseriaization of untrusted data because of the way the DataChain library reads serialized objects from env…
- CVE-2025-61765MEDIUMCVSS 6.4EG 6.42025-10-06
python-socketio is a Python implementation of the Socket.IO realtime client and server. A remote code execution vulnerability in python-socketio versions prior to 5.14.0 allows attackers to execute arbitrary Python code through malicious p…
- CVE-2025-61810HIGHCVSS 8.4EG 8.42025-12-10
ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. A high privileged attacker could e…
- CVE-2025-61880HIGHCVSS 8.8EG 8.82026-02-12
In Infoblox NIOS through 9.0.7, insecure deserialization can result in remote code execution.
- CVE-2025-62008HIGHCVSS 8.8EG 8.82025-10-22
Deserialization of Untrusted Data vulnerability in acowebs Product Table For WooCommerce product-table-for-woocommerce.This issue affects Product Table For WooCommerce: from n/a through <= 1.2.4.
Map vulnerabilities like CWE-502 to your infrastructure
EchelonGraph correlates every CVE — across CWE-502 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →