VendorsParse Platformparse-serverany version
Vulnerabilities

Parse Platform Parseplatform Parse-server any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

101CVEs
CVE-2022-24760
Command Injection in Parse server
Published 2022-03-11 · Modified
10.0EPSS 0.491
CVE-2024-27298
Parse Server literalizeRegexPart SQL Injection
Published 2024-03-01 · Analyzed
10.0EPSS 0.010
CVE-2026-30966
Parse Server role escalation and CLP bypass via direct `_Join` table write
Published 2026-03-10 · Analyzed
10.0EPSS 0.005
CVE-2026-30965
Parse Server session token exfiltration via `redirectClassNameForKey` query parameter
Published 2026-03-10 · Analyzed
9.9EPSS 0.016
CVE-2022-39396
Parse Server vulnerable to Remote Code Execution via prototype pollution in MongoDB BSON parser
Published 2022-11-10 · Modified
9.8EPSS 0.387
CVE-2023-36475
Parse Server vulnerable to remote code execution via MongoDB BSON parser through prototype pollution
Published 2023-06-28 · Modified
9.8EPSS 0.032
CVE-2022-41878
Parse Server Prototype pollution and Injection via Cloud Code Webhooks or Cloud Code Triggers
Published 2022-11-10 · Modified
9.8EPSS 0.009
CVE-2026-32248
Parse Server: Account takeover via operator injection in authentication data identifier
Published 2026-03-12 · Analyzed
9.8EPSS 0.009
CVE-2022-41879
Parse Server subject to Prototype pollution via Cloud Code Webhooks
Published 2022-11-10 · Modified
9.8EPSS 0.009
CVE-2026-31840
Parse Server has a SQL injection via dot-notation field name in PostgreSQL
Published 2026-03-11 · Analyzed
9.8EPSS 0.007
CVE-2026-30863
Parse Server: JWT audience validation bypass in Google, Apple, and Facebook authentication adapters
Published 2026-03-07 · Analyzed
9.8EPSS 0.007
CVE-2026-31856
Parse Server has a SQL injection via `Increment` operation on nested object field in PostgreSQL
Published 2026-03-11 · Analyzed
9.8EPSS 0.005
CVE-2026-31871
Parse Server has a SQL Injection via dot-notation sub-key name in `Increment` operation on PostgreSQL
Published 2026-03-11 · Analyzed
9.8EPSS 0.005
CVE-2025-67727
Parse Server GitHub CI workflow vulnerable to RCE through Improper Privilege Management
Published 2025-12-12 · Analyzed
9.8EPSS 0.004
CVE-2026-27804
Parse Server: Account takeover via JWT algorithm confusion in Google auth adapter
Published 2026-02-25 · Analyzed
9.3EPSS 0.002
CVE-2026-31800
Parse Server: Classes `_GraphQLConfig` and `_Audience` master key bypass via generic class routes
Published 2026-03-10 · Analyzed
9.1EPSS 0.006
CVE-2026-33409
Parse Server: Auth provider validation bypass on login via partial authData
Published 2026-03-24 · Analyzed
9.1EPSS 0.006
CVE-2026-34532
Parse Server: Cloud function validator bypass via prototype chain traversal
Published 2026-03-31 · Analyzed
9.1EPSS 0.005
CVE-2026-32242
Parse Server OAuth2 adapter shares mutable state across providers via singleton instance
Published 2026-03-12 · Analyzed
9.1EPSS 0.004
CVE-2024-29027
Parse Server crash and RCE via invalid Cloud Function or Cloud Job name
Published 2024-03-19 · Analyzed
9.0EPSS 0.012
CVE-2026-31828
Parse Server has an LDAP injection via unsanitized user input in DN and group filter construction
Published 2026-03-10 · Analyzed
8.8EPSS 0.008
CVE-2026-30939
Parse Server has Denial of Service (DoS) and Cloud Function Dispatch Bypass via Prototype Chain Resolution
Published 2026-03-10 · Analyzed
8.8EPSS 0.007
CVE-2026-30949
Parse Server is missing audience validation in Keycloak authentication adapter
Published 2026-03-10 · Analyzed
8.8EPSS 0.006
CVE-2026-30967
Parse Server OAuth2 authentication adapter account takeover via identity spoofing
Published 2026-03-10 · Analyzed
8.8EPSS 0.006
CVE-2026-34373
Parse Server: GraphQL API endpoint ignores CORS origin restriction
Published 2026-03-31 · Analyzed
8.8EPSS 0.002
CVE-2026-33538
Parse Server: Denial of service via unindexed database query for unconfigured auth providers
Published 2026-03-24 · Analyzed
8.7EPSS 0.008
CVE-2023-22474
Parse Server is vulnerable to authentication bypass via spoofing
Published 2023-02-03 · Modified
8.7EPSS 0.007
CVE-2026-30946
Parse Server affected by denial-of-service via unbounded query complexity in REST and GraphQL API
Published 2026-03-10 · Analyzed
8.7EPSS 0.006
CVE-2026-33498
Parse Server: Query condition depth bypass via pre-validation transform pipeline
Published 2026-03-24 · Analyzed
8.7EPSS 0.006
CVE-2026-32944
Parse Server crash via deeply nested query condition operators
Published 2026-03-18 · Analyzed
8.7EPSS 0.006
CVE-2026-31872
Parse Server has a protected fields bypass via dot-notation in query and sort
Published 2026-03-11 · Analyzed
8.7EPSS 0.005
CVE-2026-30941
Parse Server has a NoSQL injection via token type in password reset and email verification endpoints
Published 2026-03-10 · Analyzed
8.7EPSS 0.005
CVE-2026-30947
Parse Server ha a bypass of class-level permissions in LiveQuery
Published 2026-03-10 · Analyzed
8.7EPSS 0.005
CVE-2022-36079
Parse Server vulnerable to brute force guessing of user sensitive data via search patterns
Published 2022-09-07 · Modified
8.6EPSS 0.013
CVE-2022-31083
Authentication bypass in Parse Server Apple Game Center auth adapter
Published 2022-06-17 · Modified
8.6EPSS 0.009
CVE-2026-33539
Parse Server: SQL injection via aggregate and distinct field names in PostgreSQL adapter
Published 2026-03-24 · Analyzed
8.6EPSS 0.007
CVE-2026-29182
Parse Server: Cloud Hooks and Cloud Jobs bypass `readOnlyMasterKey` write restriction
Published 2026-03-06 · Analyzed
8.6EPSS 0.006
CVE-2026-30229
Parse Server: Endpoint `/loginAs` allows `readOnlyMasterKey` to gain full read and write access as any user
Published 2026-03-06 · Analyzed
8.5EPSS 0.006
CVE-2026-32728
Parse Server has a stored XSS filter bypass via Content-Type MIME parameter and missing XML extension blocklist entries
Published 2026-03-18 · Analyzed
8.3EPSS 0.004
CVE-2025-68150
Parse Server has Server-Side Request Forgery (SSRF) in Instagram OAuth Adapter
Published 2025-12-16 · Analyzed
8.3EPSS 0.003
1 / 3Next →