Weaknesses of type CWE-502

2,668 results

Desserialização de dados não confiáveis

A aplicação reconstrói objetos a partir de dados serializados (JSON, XML, binário) recebidos de fontes externas sem validar adequadamente se o conteúdo é legítimo. Um atacante pode injetar código malicioso ou objetos especialmente crafted que são executados durante a desserialização, comprometendo toda a aplicação.

Example

Um servidor Java desserializa objetos recebidos em requisições HTTP usando ObjectInputStream, sem verificar a classe ou origem dos dados. Um atacante envia um objeto serializado contendo uma cadeia de gadgets (RCE via biblioteca como Apache Commons Collections) que é executada assim que o objeto é reconstruído em memória.

How to mitigate

Valide e liste explicitamente as classes que podem ser desserializadas (whitelist). Para JSON/XML, use parsers que não executem código (como JSON simples, evite eval). Considere alternativas seguras como Protocol Buffers ou MessagePack, e mantenha bibliotecas críticas atualizadas.

CVE-2025-69382CRITICALWordPress Themesflat Elementor plugin <= 1.0.1 - PHP Object Injection vulnerabilityEPSS 0.4%CVE-2024-39780HIGHUse of unsafe yaml load in dynparamEPSS 0.4%CVE-2026-22474CRITICALWordPress Equestrian Centre theme <= 1.5 - PHP Object Injection vulnerabilityEPSS 0.4%CVE-2025-69329CRITICALWordPress Prestige theme < 1.4.1 - PHP Object Injection vulnerabilityEPSS 0.4%CVE-2025-67996CRITICALWordPress Nestin theme < 1.2.6 - PHP Object Injection vulnerabilityEPSS 0.4%CVE-2025-69405CRITICALWordPress Lorem Ipsum | Books & Media Store theme <= 1.2.11 - PHP Object Injection vulnerabilityEPSS 0.4%CVE-2025-69370CRITICALWordPress Capella theme <= 2.5.5 - PHP Object Injection vulnerabilityEPSS 0.4%CVE-2025-69301CRITICALWordPress PhotoMe theme <= 5.6.11 - PHP Object Injection vulnerabilityEPSS 0.4%CVE-2025-69404CRITICALWordPress Extreme Store theme <= 1.5.10 - PHP Object Injection vulnerabilityEPSS 0.4%CVE-2023-47507HIGHWordPress Master Slider Pro Plugin <= 3.6.5 is vulnerable to PHP Object InjectionEPSS 0.4%CVE-2026-47058HIGHVulnerability in Oracle Java SE (component: Scripting). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf and 11.EPSS 0.4%CVE-2025-60233CRITICALWordPress Zuut theme <= 1.4.2 - PHP Object Injection vulnerabilityEPSS 0.4%CVE-2025-69111CRITICALWordPress Reisen theme <= 1.4.1 - PHP Object Injection vulnerabilityEPSS 0.4%CVE-2025-69127CRITICALWordPress Plumbing theme <= 1.6 - PHP Object Injection vulnerabilityEPSS 0.4%CVE-2026-96775HIGHMLflow dspy bypasses pickle deserialization controlEPSS 0.4%CVE-2026-12728HIGHIBM MQ Java messaging is vulnerable to remote code executionEPSS 0.4%CVE-2025-0769MEDIUMPixelYourSite 10.1.1.1 - Insecure deserializationEPSS 0.4%CVE-2026-7888HIGHConcrete CMS below 9.5.3 is vulnerable to PHP Object Injection via unserialize() calls in the Workflow, Form block, and File/Set components that lack the allowed_classes restriction.EPSS 0.4%CVE-2026-42521MEDIUMJenkins Matrix Authorization Strategy Plugin 2.0-beta-1 through 3.2.9 (both inclusive) invokes parameterless constructors of classes specifiEPSS 0.4%CVE-2025-52828HIGHWordPress Red Art theme <= 3.8 - PHP Object Injection VulnerabilityEPSS 0.4%