VendorsParse Platformparse-serverall versions
Vulnerabilities

Parse Platform Parseplatform Parse-server

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

102CVEs
CVE-2026-33429
Parse Server: Protected field change detection oracle via LiveQuery watch parameter
Published 2026-03-24 · Analyzed
6.3EPSS 0.003
CVE-2026-30848
Parse Server: `PagesRouter` path traversal allows reading files outside configured pages directory
Published 2026-03-07 · Analyzed
6.3EPSS 0.003
CVE-2026-30850
Parse Server: File metadata endpoint bypasses `beforeFind` / `afterFind` trigger authorization
Published 2026-03-07 · Analyzed
6.3EPSS 0.003
CVE-2026-31868
Parse Server has Stored XSS via file upload of HTML-renderable file types
Published 2026-03-11 · Analyzed
6.3EPSS 0.002
CVE-2026-31901
Parse Server has user enumeration via email verification endpoint
Published 2026-03-11 · Analyzed
6.3EPSS 0.002
CVE-2026-39321
Parse Server has a login timing side-channel reveals user existence
Published 2026-04-07 · Analyzed
6.3EPSS 0.002
CVE-2025-68115
Parse Server vulnerable to Cross-Site Scripting (XSS) via Unescaped Mustache Template Variables
Published 2025-12-16 · Analyzed
6.1EPSS 0.002
CVE-2026-43930
Parse Server: MFA SMS one-time password accepted twice under concurrent login
Published 2026-05-12 · Analyzed
5.9EPSS 0.002
CVE-2026-34574
Parse Server: Session field immutability bypass via falsy-value guard
Published 2026-03-31 · Analyzed
5.4EPSS 0.002
CVE-2026-35200
Parse Server has a file upload Content-Type override via extension mismatch
Published 2026-04-06 · Analyzed
5.4EPSS 0.002
CVE-2019-1020013
parse-server before 3.6.0 allows account enumeration.
Published 2019-07-29 · Modified
5.3EPSS 0.012
CVE-2026-33527
Parse Server: Session update endpoint allows overwriting server-generated session fields
Published 2026-03-24 · Analyzed
5.3EPSS 0.003
CVE-2026-34595
Parse Server: LiveQuery protected-field guard bypass via array-like logical operator value
Published 2026-03-31 · Analyzed
5.3EPSS 0.003
CVE-2026-39381
Parse Server's Endpoint `/sessions/me` bypasses `_Session` `protectedFields`
Published 2026-04-07 · Analyzed
5.3EPSS 0.002
CVE-2026-32234
Parse Server has a SQL injection via query field name when using PostgreSQL
Published 2026-03-11 · Analyzed
5.1EPSS 0.002
CVE-2026-34224
Parse Server: MFA single-use token bypass via concurrent authData login requests
Published 2026-03-31 · Modified
4.4EPSS 0.003
CVE-2020-15270
Improper session expiration in Parse Server
Published 2020-10-22 · Modified
4.3EPSS 0.012
CVE-2022-39225
Parse Server subject to Incorrect Resource Transfer Between Spheres
Published 2022-09-23 · Modified
4.3EPSS 0.005
CVE-2026-32742
Parse Server session creation endpoint allows overwriting server-generated session fields
Published 2026-03-18 · Analyzed
4.3EPSS 0.003
CVE-2022-39231
Parse Server subject to Improper Authentication allowing Auth adapter app ID validation to be circumvented
Published 2022-09-23 · Modified
3.7EPSS 0.005
CVE-2026-32943
Parse Server has a password reset token single-use bypass via concurrent requests
Published 2026-03-18 · Analyzed
3.1EPSS 0.002
CVE-2026-33624
Parse Server: MFA recovery code single-use bypass via concurrent requests
Published 2026-03-24 · Analyzed
2.7EPSS 0.002
← Prev3 / 3