VendorsParse Platformparse-server9.5.0
Vulnerabilities

Parse Platform Parseplatform Parse-server 9.5.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2026-30863
Parse Server: JWT audience validation bypass in Google, Apple, and Facebook authentication adapters
Published 2026-03-07 · Analyzed
9.8EPSS 0.005
CVE-2026-30229
Parse Server: Endpoint `/loginAs` allows `readOnlyMasterKey` to gain full read and write access as any user
Published 2026-03-06 · Analyzed
8.5EPSS 0.004
CVE-2026-30925
Parse Server affected by Regular Expression Denial of Service (ReDoS) via `$regex` query in LiveQuery
Published 2026-03-09 · Analyzed
8.2EPSS 0.004
CVE-2026-30835
Parse Server: Malformed `$regex` query leaks database error details in API response
Published 2026-03-06 · Analyzed
6.9EPSS 0.003
CVE-2026-30228
Parse Server: File creation and deletion bypasses `readOnlyMasterKey` write restriction
Published 2026-03-06 · Analyzed
6.9EPSS 0.003
CVE-2026-30854
Parse Server: GraphQL `__type` introspection bypass via inline fragments when public introspection is disabled
Published 2026-03-07 · Analyzed
6.9EPSS 0.003
CVE-2026-30848
Parse Server: `PagesRouter` path traversal allows reading files outside configured pages directory
Published 2026-03-07 · Analyzed
6.3EPSS 0.003
CVE-2026-30850
Parse Server: File metadata endpoint bypasses `beforeFind` / `afterFind` trigger authorization
Published 2026-03-07 · Analyzed
6.3EPSS 0.003