VendorsParse Platformparse-server9.5.2
Vulnerabilities

Parse Platform Parseplatform Parse-server 9.5.2

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

11CVEs
CVE-2026-30966
Parse Server role escalation and CLP bypass via direct `_Join` table write
Published 2026-03-10 · Analyzed
10.0EPSS 0.005
CVE-2026-30965
Parse Server session token exfiltration via `redirectClassNameForKey` query parameter
Published 2026-03-10 · Analyzed
9.9EPSS 0.016
CVE-2026-31800
Parse Server: Classes `_GraphQLConfig` and `_Audience` master key bypass via generic class routes
Published 2026-03-10 · Analyzed
9.1EPSS 0.006
CVE-2026-31828
Parse Server has an LDAP injection via unsanitized user input in DN and group filter construction
Published 2026-03-10 · Analyzed
8.8EPSS 0.008
CVE-2026-30949
Parse Server is missing audience validation in Keycloak authentication adapter
Published 2026-03-10 · Analyzed
8.8EPSS 0.006
CVE-2026-30967
Parse Server OAuth2 authentication adapter account takeover via identity spoofing
Published 2026-03-10 · Analyzed
8.8EPSS 0.006
CVE-2026-30946
Parse Server affected by denial-of-service via unbounded query complexity in REST and GraphQL API
Published 2026-03-10 · Analyzed
8.7EPSS 0.006
CVE-2026-30947
Parse Server ha a bypass of class-level permissions in LiveQuery
Published 2026-03-10 · Analyzed
8.7EPSS 0.005
CVE-2026-30948
Parse Server has stored cross-site scripting (XSS) via SVG file upload
Published 2026-03-10 · Analyzed
8.3EPSS 0.003
CVE-2026-30972
Parse Server has a rate limit bypass via batch request endpoint
Published 2026-03-10 · Analyzed
7.5EPSS 0.006
CVE-2026-30962
Parse Server has a protected fields bypass via logical query operators
Published 2026-03-10 · Analyzed
7.1EPSS 0.004