CWE-502: Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
2,244 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-49113 — Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
- CVE-2025-40551 — SolarWinds Web Help Desk Deserialization of Untrusted Data Remote Code Execution Vulnerability
- CVE-2025-26399 — SolarWinds Web Help Desk Deserialization of Untrusted Data Privilege Escalation Vulnerability
- CVE-2025-10035 — Deserialization Vulnerability in GoAnywhere MFT's License Servlet
- CVE-2025-0994 — Trimble Cityworks versions prior to 15.8.9 and Cityworks with office companion versions prior to 23.10 are vulnerable to
- CVE-2025-25034 — SugarCRM PHP Deserialization RCE
- CVE-2024-52046 — Apache MINA: MINA applications using unbounded deserialization may allow RCE
- CVE-2025-5086 — Deserialization of Untrusted Data vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025
- CVE-2025-27520 — BentoML Allows Remote Code Execution (RCE) via Insecure Deserialization
- CVE-2024-52433 — WordPress My Geo Posts Free plugin <= 1.2 - PHP Object Injection vulnerability
- CVE-2025-49533 — Adobe Experience Manager (MS) | Deserialization of Untrusted Data (CWE-502)
- CVE-2024-1800 — Progress Telerik Report Server Deserialization
- CVE-2026-20131 — Cisco Secure Firewall Management Center Software Remote Code Execution Vulnerability
- CVE-2025-62368 — Taiga Authenticated Remote Code Execution
- CVE-2025-8875 — Insecure Deserialization Vulnerability
- CVE-2024-12029 — Remote Code Execution via Model Deserialization in invoke-ai/invokeai
- CVE-2025-71260 — BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 VIEWSTATE Deserialization RCE
- CVE-2025-3935 — ScreenConnect Exposure to ASP.NET ViewState Code Injection
- CVE-2025-42999 — Insecure Deserialization in SAP NetWeaver (Visual Composer development server)
- CVE-2026-63077 — In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent pollin
Recently published
- CVE-2026-11363 — Ninja Forms <= 3.14.6 - Authenticated (Administrator+) PHP Object Injection via Form Import
- CVE-2026-87083 — tile-ai tilelang Kernel Cache kernel_cache.py KernelCache._load_kernel_from_disk deserialization
- CVE-2026-12648 — A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated
- CVE-2026-12650 — A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated
- CVE-2026-12651 — A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated
- CVE-2026-12745 — A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticat
- CVE-2026-12744 — A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticat
- CVE-2026-16502 — Live Composer <= 2.1.18 - Authenticated (Contributor+) PHP Object Injection via Shortcode
- CVE-2026-71374 — Deserialization of Untrusted Data Vulnerability in Cosminexus Component Container
- CVE-2026-76967 — Insecure Deserialization in SAP NetWeaver Business Client
- CVE-2026-7861 — Code Injection in Next4Biz's CSM (Customer Service Management)
- CVE-2026-86404 — Artemis-server: artemis-jms-client: artemis-core-client: undertow-core: wildfly-messaging-activemq-subsystem: artemis messaging handlers in red hat eap permit deserialization by default
- CVE-2026-10196 — Mail Mint <= 1.31.0 - Unauthenticated PHP Object Injection in Arbitrary Form Fields
- CVE-2026-19887 — Welcart e-Commerce <= 2.12.1 - Unauthenticated Arbitrary File Deletion via PHP Object Injection via 'reserve' Checkout Parameter and 'option' EDY Callback
- CVE-2026-52777 — YesWiki: Authenticated PHP Object Injection in BazarImportAction via unserialize
- CVE-2026-61686 — SolidInvoice: PHP unserialize() called on client-controlled data in DataGrid LiveComponent context prop
- CVE-2026-19795 — Qiskit SDK is vulnerable when deserializing QPY Files and may overflow the available stack space.
- CVE-2026-84834 — WordPress JobSearch plugin <= 3.2.0 - PHP Object Injection vulnerability
- CVE-2026-84753 — WordPress Mail Mint plugin <= 1.31.0 - PHP Object Injection vulnerability
- CVE-2026-84752 — WordPress RTMKit plugin <= 2.1.5 - PHP Object Injection vulnerability