VendorsParse Platformparse-serverall versions
Vulnerabilities

Parse Platform Parseplatform Parse-server

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

102CVEs
CVE-2026-30948
Parse Server has stored cross-site scripting (XSS) via SVG file upload
Published 2026-03-10 · Analyzed
8.3EPSS 0.002
CVE-2022-31112
Protected fields exposed via LiveQuery in parse-server
Published 2022-06-30 · Modified
8.2EPSS 0.013
CVE-2026-34573
Parse Server: GraphQL complexity validator exponential fragment traversal DoS
Published 2026-03-31 · Analyzed
8.2EPSS 0.006
CVE-2026-32886
Parse Server's Cloud function dispatch crashes server via prototype chain traversal
Published 2026-03-18 · Analyzed
8.2EPSS 0.005
CVE-2026-30925
Parse Server affected by Regular Expression Denial of Service (ReDoS) via `$regex` query in LiveQuery
Published 2026-03-09 · Analyzed
8.2EPSS 0.004
CVE-2026-31875
Parse Server MFA recovery codes not consumed after use
Published 2026-03-11 · Analyzed
8.2EPSS 0.004
CVE-2026-33163
Parse Server leaks protected fields via LiveQuery afterEvent trigger
Published 2026-03-18 · Analyzed
8.2EPSS 0.004
CVE-2026-34784
Parse Server: Streaming file download bypasses afterFind file trigger authorization
Published 2026-03-31 · Analyzed
8.2EPSS 0.004
CVE-2026-34363
Parse Server: LiveQuery protected field leak via shared mutable state across concurrent subscribers
Published 2026-03-31 · Analyzed
8.2EPSS 0.004
CVE-2026-33508
Parse Server: LiveQuery subscription query depth bypass
Published 2026-03-24 · Analyzed
8.2EPSS 0.003
CVE-2026-34215
Parse Server: Auth data exposed via verify password endpoint
Published 2026-03-31 · Modified
8.2EPSS 0.003
CVE-2024-47183
Parse Server's custom object ID allows to acquire role privileges
Published 2024-10-04 · Analyzed
8.1EPSS 0.004
CVE-2020-5251
Information disclosure in parse-server
Published 2020-03-04 · Modified
7.7EPSS 0.008
CVE-2020-26288
Parse Server stores password in plain text
Published 2020-12-30 · Modified
7.7EPSS 0.008
CVE-2021-47986
Parse Server - Unreviewed Code Execution via Malicious Version Tags
Published 2026-06-25 · Analyzed
7.7EPSS 0.002
CVE-2021-39187
Crash server with query parameter
Published 2021-09-02 · Modified
7.5EPSS 0.018
CVE-2019-1020012
parse-server before 3.4.1 allows DoS after any POST to a volatile class.
Published 2019-07-29 · Modified
7.5EPSS 0.014
CVE-2021-41109
LiveQuery publishes user session tokens
Published 2021-09-30 · Modified
7.5EPSS 0.012
CVE-2022-31089
Invalid file request can crashe parse-server
Published 2022-06-27 · Modified
7.5EPSS 0.011
CVE-2023-46119
Parse Server may crash when uploading file without extension
Published 2023-10-25 · Modified
7.5EPSS 0.011
CVE-2023-41058
Trigger `beforeFind` not invoked in internal query pipeline in parse-server
Published 2023-09-04 · Modified
7.5EPSS 0.008
CVE-2022-39313
Parse Server crashes when receiving file download request with invalid byte range
Published 2022-10-24 · Modified
7.5EPSS 0.007
CVE-2022-24901
Authentication bypass and denial of service (DoS) vulnerabilities in Apple Game Center auth adapter
Published 2022-05-04 · Modified
7.5EPSS 0.007
CVE-2026-32770
Parse Server: LiveQuery subscription with invalid regular expression crashes server
Published 2026-03-18 · Analyzed
7.5EPSS 0.006
CVE-2026-32878
Parse Server vulnerable to schema poisoning via prototype pollution in deep copy
Published 2026-03-18 · Analyzed
7.5EPSS 0.003
CVE-2026-30972
Parse Server has a rate limit bypass via batch request endpoint
Published 2026-03-10 · Analyzed
7.5EPSS 0.003
CVE-2026-32098
Parse Server has a protected fields bypass via LiveQuery subscription WHERE clause
Published 2026-03-11 · Analyzed
7.5EPSS 0.003
CVE-2026-32594
Parse Server GraphQL WebSocket endpoint bypasses security middleware
Published 2026-03-13 · Analyzed
7.3EPSS 0.003
CVE-2026-33421
Parse Server: LiveQuery bypasses CLP pointer permission enforcement
Published 2026-03-24 · Analyzed
7.1EPSS 0.004
CVE-2026-33627
Parse Server: Auth data exposed via /users/me endpoint
Published 2026-03-24 · Analyzed
7.1EPSS 0.004
CVE-2026-30962
Parse Server has a protected fields bypass via logical query operators
Published 2026-03-10 · Analyzed
7.1EPSS 0.003
CVE-2026-30938
Parse Server has denylist `requestKeywordDenylist` keyword scan bypass through nested object placement
Published 2026-03-10 · Analyzed
6.9EPSS 0.004
CVE-2026-30835
Parse Server: Malformed `$regex` query leaks database error details in API response
Published 2026-03-06 · Analyzed
6.9EPSS 0.003
CVE-2026-30228
Parse Server: File creation and deletion bypasses `readOnlyMasterKey` write restriction
Published 2026-03-06 · Analyzed
6.9EPSS 0.003
CVE-2026-33042
Parse Server affected by empty authData bypassing credential requirement on signup
Published 2026-03-18 · Analyzed
6.9EPSS 0.003
CVE-2026-30854
Parse Server: GraphQL `__type` introspection bypass via inline fragments when public introspection is disabled
Published 2026-03-07 · Analyzed
6.9EPSS 0.003
CVE-2021-39138
New anonymous user session acts as if it's created with password
Published 2021-08-18 · Modified
6.5EPSS 0.010
CVE-2023-32689
Parse Server vulnerable to phishing attack vulnerability that involves uploading malicious HTML file
Published 2023-05-30 · Modified
6.5EPSS 0.006
CVE-2026-32269
Parse Server OAuth2 adapter app ID validation sends wrong token to introspection endpoint
Published 2026-03-12 · Analyzed
6.5EPSS 0.003
CVE-2026-33323
Parse Server: Email verification resend page leaks user existence
Published 2026-03-24 · Analyzed
6.3EPSS 0.003
← Prev2 / 3Next →