VendorsParse Platformparse-server9.6.0
Vulnerabilities

Parse Platform Parseplatform Parse-server 9.6.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

33CVEs
CVE-2026-32248
Parse Server: Account takeover via operator injection in authentication data identifier
Published 2026-03-12 · Analyzed
9.8EPSS 0.009
CVE-2026-31840
Parse Server has a SQL injection via dot-notation field name in PostgreSQL
Published 2026-03-11 · Analyzed
9.8EPSS 0.007
CVE-2026-31856
Parse Server has a SQL injection via `Increment` operation on nested object field in PostgreSQL
Published 2026-03-11 · Analyzed
9.8EPSS 0.005
CVE-2026-31871
Parse Server has a SQL Injection via dot-notation sub-key name in `Increment` operation on PostgreSQL
Published 2026-03-11 · Analyzed
9.8EPSS 0.005
CVE-2026-33409
Parse Server: Auth provider validation bypass on login via partial authData
Published 2026-03-24 · Analyzed
9.1EPSS 0.006
CVE-2026-32242
Parse Server OAuth2 adapter shares mutable state across providers via singleton instance
Published 2026-03-12 · Analyzed
9.1EPSS 0.004
CVE-2026-33538
Parse Server: Denial of service via unindexed database query for unconfigured auth providers
Published 2026-03-24 · Analyzed
8.7EPSS 0.008
CVE-2026-33498
Parse Server: Query condition depth bypass via pre-validation transform pipeline
Published 2026-03-24 · Analyzed
8.7EPSS 0.006
CVE-2026-32944
Parse Server crash via deeply nested query condition operators
Published 2026-03-18 · Analyzed
8.7EPSS 0.006
CVE-2026-31872
Parse Server has a protected fields bypass via dot-notation in query and sort
Published 2026-03-11 · Analyzed
8.7EPSS 0.005
CVE-2026-33539
Parse Server: SQL injection via aggregate and distinct field names in PostgreSQL adapter
Published 2026-03-24 · Analyzed
8.6EPSS 0.007
CVE-2026-32728
Parse Server has a stored XSS filter bypass via Content-Type MIME parameter and missing XML extension blocklist entries
Published 2026-03-18 · Analyzed
8.3EPSS 0.004
CVE-2026-32886
Parse Server's Cloud function dispatch crashes server via prototype chain traversal
Published 2026-03-18 · Analyzed
8.2EPSS 0.007
CVE-2026-33508
Parse Server: LiveQuery subscription query depth bypass
Published 2026-03-24 · Analyzed
8.2EPSS 0.006
CVE-2026-31875
Parse Server MFA recovery codes not consumed after use
Published 2026-03-11 · Analyzed
8.2EPSS 0.005
CVE-2026-33163
Parse Server leaks protected fields via LiveQuery afterEvent trigger
Published 2026-03-18 · Analyzed
8.2EPSS 0.005
CVE-2026-32770
Parse Server: LiveQuery subscription with invalid regular expression crashes server
Published 2026-03-18 · Analyzed
7.5EPSS 0.007
CVE-2026-32098
Parse Server has a protected fields bypass via LiveQuery subscription WHERE clause
Published 2026-03-11 · Analyzed
7.5EPSS 0.005
CVE-2026-32878
Parse Server vulnerable to schema poisoning via prototype pollution in deep copy
Published 2026-03-18 · Analyzed
7.5EPSS 0.005
CVE-2026-32594
Parse Server GraphQL WebSocket endpoint bypasses security middleware
Published 2026-03-13 · Analyzed
7.3EPSS 0.005
CVE-2026-33627
Parse Server: Auth data exposed via /users/me endpoint
Published 2026-03-24 · Analyzed
7.1EPSS 0.005
CVE-2026-33421
Parse Server: LiveQuery bypasses CLP pointer permission enforcement
Published 2026-03-24 · Analyzed
7.1EPSS 0.004
CVE-2026-33042
Parse Server affected by empty authData bypassing credential requirement on signup
Published 2026-03-18 · Analyzed
6.9EPSS 0.004
CVE-2026-32269
Parse Server OAuth2 adapter app ID validation sends wrong token to introspection endpoint
Published 2026-03-12 · Analyzed
6.5EPSS 0.004
CVE-2026-33323
Parse Server: Email verification resend page leaks user existence
Published 2026-03-24 · Analyzed
6.3EPSS 0.004
CVE-2026-33429
Parse Server: Protected field change detection oracle via LiveQuery watch parameter
Published 2026-03-24 · Analyzed
6.3EPSS 0.004
CVE-2026-31901
Parse Server has user enumeration via email verification endpoint
Published 2026-03-11 · Analyzed
6.3EPSS 0.004
CVE-2026-31868
Parse Server has Stored XSS via file upload of HTML-renderable file types
Published 2026-03-11 · Analyzed
6.3EPSS 0.003
CVE-2026-33527
Parse Server: Session update endpoint allows overwriting server-generated session fields
Published 2026-03-24 · Analyzed
5.3EPSS 0.003
CVE-2026-32234
Parse Server has a SQL injection via query field name when using PostgreSQL
Published 2026-03-11 · Analyzed
5.1EPSS 0.003
CVE-2026-32742
Parse Server session creation endpoint allows overwriting server-generated session fields
Published 2026-03-18 · Analyzed
4.3EPSS 0.004
CVE-2026-32943
Parse Server has a password reset token single-use bypass via concurrent requests
Published 2026-03-18 · Analyzed
3.1EPSS 0.002
CVE-2026-33624
Parse Server: MFA recovery code single-use bypass via concurrent requests
Published 2026-03-24 · Analyzed
2.7EPSS 0.003