Search Results (3409 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-97283 2026-10-05 9.8 Critical
Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP Advanced Post Manager advanced-post-manager allows Object Injection.This issue affects Advanced Post Manager: from n/a through 4.5.5.
CVE-2019-25777 2026-10-05 8.1 High
YAML versions before 1.27_001 for Perl allow a loaded perl/glob document to replace any package variable, which can lead to arbitrary code execution. A perl/glob document names a package and a symbol, and supplies the value assigned to it. Nothing restricts the name, so the target can be @INC or YAML's own load options. A perl/glob document that sets $YAML::LoadCode or $YAML::UseCode turns on code loading, which is off by default, for every later Load() in the process. A perl/code document is then passed to a string eval, so an attacker who supplies two documents to separate Load() calls in one process can execute arbitrary Perl code.
CVE-2017-20285 2026-10-05 7.4 High
YAML versions before 1.30 for Perl allow a loaded document to trigger the DESTROY method of arbitrary classes. A perl/hash:Class tag blesses a hash into the class it names. The document supplies the object's fields, and Perl calls DESTROY when it goes out of scope. What DESTROY does depends on the classes the process has loaded. With File::Temp::Dir from core Perl, it can delete a directory tree the document names.
CVE-2026-100506 2026-10-05 7.2 High
Deserialization of Untrusted Data vulnerability in WP Spell Check WP Spell Check wp-spell-check allows Object Injection.This issue affects WP Spell Check: from n/a through 12.1.
CVE-2026-100511 2026-10-05 8.8 High
Deserialization of Untrusted Data vulnerability in Vektor Inc. VK Google Job Posting Manager vk-google-job-posting-manager allows Object Injection.This issue affects VK Google Job Posting Manager: from n/a through 1.3.1.
CVE-2026-97257 2026-10-05 8.8 High
Deserialization of Untrusted Data vulnerability in PressTigers Simple Event Planner simple-event-planner allows Object Injection.This issue affects Simple Event Planner: from n/a through 1.5.7.
CVE-2026-93617 2026-10-05 7.2 High
Deserialization of Untrusted Data vulnerability in WP Sunshine Sunshine Photo Cart sunshine-photo-cart allows Object Injection.This issue affects Sunshine Photo Cart: from n/a through 3.7.1.
CVE-2026-103348 2026-10-05 7.2 High
Deserialization of Untrusted Data vulnerability in Smackcoders Inc. WP Ultimate Exporter wp-ultimate-exporter allows Object Injection.This issue affects WP Ultimate Exporter: from n/a through 3.0.
CVE-2026-104905 1 Neorazorx 1 Facturascripts 2026-10-05 8.1 High
FacturaScripts before version 2026.7 contains a PHP object injection vulnerability in WidgetSelect::processFormData() that allows authenticated attackers to trigger unserialize() on raw POST data without an allowed_classes filter for multiple-select fields. Attackers can submit a serialized XLSXWriter object as the field value to invoke its __destruct() method, deleting arbitrary attacker-specified files such as config.php or backup data, resulting in denial of service and potential application reinstall hijack.
CVE-2026-103349 2026-10-05 7.2 High
Deserialization of Untrusted Data vulnerability in Rymera Web Co Product Feed PRO for WooCommerce woo-product-feed-pro allows Object Injection.This issue affects Product Feed PRO for WooCommerce: from n/a through 13.5.7.
CVE-2026-76595 1 Advisor-backend 1 Advisor-backend 2026-10-04 N/A
A flaw was found in advisor-backend. Multiple code paths within the application deserialize YAML (YAML Ain't Markup Language) with an unsafe full Loader, which can instantiate arbitrary Python objects via YAML tags. An unauthenticated remote attacker can exploit this by submitting specially crafted YAML input, leading to remote code execution (RCE) within the `advisor-backend` pod. This compromise could allow access to shared database credentials and impact all tenants.
CVE-2026-103877 1 Apache 1 Directory Ldap Api 2026-10-02 8.1 High
Deserialization of Untrusted Data vulnerability in Apache Directory LDAP API. A rogue/compromised LDAP server (or pre-TLS MITM) can answer a client's loadSchema() subschema search with a schema object that contains a serialized Java class, allowing some potential RCE.  This issue affects Apache Directory LDAP API: from 2.1.0 before 2.1.9. Users are recommended to upgrade to version 2.1.9, which fixes the issue.
CVE-2026-12544 2 Redhat, Theforeman 4 Satellite, Satellite Capsule, Satellite Utils and 1 more 2026-10-02 7.7 High
A flaw was found in Foreman. The foreman-rake initialization logic in /usr/share/foreman/config/settings.rb contains a vulnerable code pattern where configuration data is processed through two distinct executable layers. This creates a multi-stage execution chain that allows for both Server-Side Template Injection (SSTI) and insecure deserialization. This vulnerability can lead to remote code execution, total infrastructure compromise and supply chain risk.
CVE-2026-94390 2 Dotstore, Wordpress-extensions 2 Hide Shipping Method For Woocommerce, Hide Shipping Method For Woocommerce 2026-10-01 7.2 High
Editor PHP Object Injection in Hide Shipping Method For WooCommerce <= 1.5.4 versions.
CVE-2026-97256 2 Greg–siteorigin, Wordpress-extensions 2 Page Builder By Siteorigin, Page Builder By Siteorigin 2026-10-01 7.2 High
Editor PHP Object Injection in Page Builder by SiteOrigin <= 2.36.0 versions.
CVE-2026-97291 2 Magazine3, Wordpress-extensions 2 Schema & Structured Data For Wp & Amp, Schema & Structured Data For Wp & Amp 2026-10-01 8.8 High
Contributor PHP Object Injection in Schema & Structured Data for WP & AMP <= 1.66 versions.
CVE-2026-100512 2 Hook & Filter, Wordpress-extensions 2 Nested Pages, Nested Pages 2026-10-01 9.8 Critical
Contributor PHP Object Injection in Nested Pages <= 3.3.2 versions.
CVE-2026-102377 2 10web, Wordpress-extensions 2 Photo Gallery, Photo Gallery By 10web 2026-10-01 8.8 High
Contributor PHP Object Injection in Photo Gallery by 10Web <= 1.8.46 versions.
CVE-2026-102392 2 Themehigh, Wordpress-extensions 2 Extra Product Options For Woocommerce, Extra Product Options For Woocommerce 2026-10-01 7.2 High
Shop manager PHP Object Injection in Extra Product Options For WooCommerce | Custom Product Addons and Fields <= 3.3.8 versions.
CVE-2026-103441 1 Wikimedia 1 Mediawiki-wikibase Extension 2026-10-01 N/A
Deserialization of untrusted data vulnerability in The Wikimedia Foundation MediaWiki Wikibase extension allows Leverage Executable Code in Non-Executable Files. This issue affects MediaWiki Wikibase extension: 1.46, 1.45, and 1.43.