We have discovered 472,216 live websites that are affected by CWE-502.
| 154,265 websites | |
| 42,292 websites | |
| 22,943 websites | |
| 21,879 websites | |
| 17,924 websites | |
| 15,905 websites | |
| 14,165 websites | |
| 12,255 websites | |
| 10,427 websites | |
| 10,310 websites |
| .com | 201,088 websites |
| .de | 24,825 websites |
| .org | 22,828 websites |
| .co.uk | 15,216 websites |
| .it | 12,772 websites |
| .nl | 12,751 websites |
| .net | 12,309 websites |
| .fr | 9,697 websites |
| .com.au | 8,976 websites |
| .com.br | 8,897 websites |
| Discovered | CVE | Description | Websites |
|---|---|---|---|
| Apr, 2026 | CVE-2026-35537 | An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsafe deserialization in the... | 15,595 |
| Apr, 2026 | CVE-2026-29782 | OpenSTAManager: Remote Code Execution via Insecure Deserialization in OAuth2 | 8 |
| Mar, 2026 | CVE-2026-3328 | Frontend Admin by DynamiApps <= 3.28.31 - Authenticated (Editor+) PHP Object Injection via 'post_content' of Admin Form Posts | 1,406 |
| Mar, 2026 | CVE-2026-25445 | WordPress WishList Member X plugin <= 3.29.0 - PHP Object Injection vulnerability | 396 |
| Mar, 2026 | CVE-2026-26114 | Microsoft SharePoint Server Remote Code Execution Vulnerability | 3,346 |
| Mar, 2026 | CVE-2026-2020 | JS Archive List <= 6.1.7 - Authenticated (Contributor+) PHP Object Injection via 'included' Shortcode Attribute | 740 |
| Mar, 2026 | CVE-2026-3452 | Concrete CMS below 9.4.8 is vulnerable to stored deserialization leading to RCE in the Express Entry List block. | 11,688 |
| Mar, 2026 | CVE-2026-27971 | Qwik affected by unauthenticated RCE via server$ Deserialization | 12,899 |
| Mar, 2026 | CVE-2025-50198 | Chamilo: Deserialization of untrusted data in /plugin/vchamilo/views/import.php via POST configuration_file; POST course_path; POST home_path parameters | 8 |
| Mar, 2026 | CVE-2025-52998 | Chamilo: PHAR deserialization bypass | 8 |
| Discovered | CVE | Description | Websites |
|---|---|---|---|
| Dec, 2023 | CVE-2023-28782 | WordPress Gravity Forms Plugin <= 2.7.3 is vulnerable to PHP Object Injection | 75,656 |
| Dec, 2023 | CVE-2023-40555 | WordPress Flatsome Theme <= 3.17.5 is vulnerable to PHP Object Injection | 55,978 |
| Aug, 2024 | CVE-2024-2694 | Betheme <= 27.5.6 - Authenticated (Contributor+) PHP Object Injection | 51,621 |
| Sep, 2025 | CVE-2025-9083 | Ninja-forms < 3.11.1 - Unauthenticated PHP Objection | 51,401 |
| Oct, 2023 | CVE-2023-3154 | NextGEN Gallery < 3.39 - Admin+ PHAR Deserialization | 29,815 |
| Jul, 2025 | CVE-2025-6464 | Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.44.2 - Unauthenticated PHP Object Injection (PHAR) Triggered via Administrator Form Submission Deletion | 18,179 |
| Apr, 2024 | CVE-2024-32600 | WordPress Master Slider plugin <= 3.9.5 - PHP Object Injection vulnerability | 15,889 |
| Apr, 2026 | CVE-2026-35537 | An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsafe deserialization in the... | 15,595 |
| Sep, 2025 | CVE-2025-9260 | Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder 5.1.16 - 6.1.1 - Authenticated (Subscriber+) PHP Object Injection To Arbitrary File Read | 13,964 |
| Mar, 2026 | CVE-2026-27971 | Qwik affected by unauthenticated RCE via server$ Deserialization | 12,899 |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ********.****.com | *** | ||
| *******.com | *,*** | ||
| ***************.eu | *,*** | ||
| ****.******.jp | *,*** | ||
| ***.int | *,*** | ||
| *.******.net | *,*** | ||
| **********.dk | *,*** | ||
| ***.****.******.jp | *,*** | ||
| ******.gov | *,*** | ||
| *********.nl | *,*** |