Back to all advisories

Tag: Insecure Deserialization

1 advisory tagged with "Insecure Deserialization".

GHSA-7mvq-hwhc-c98g High

PHP Object Injection via Cache Deserialization

A PHP Object Injection vulnerability exists in the file-based cache backend due to insecure usage of PHP’s unserialize() function. Successful exploitation may allow remote code execution under the privileges of the web server user.

icms2

Start securing your codebase today

Connect your repositories and let AI agents handle continuous scanning, research, and triage.

Have questions? Get in touch →