Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

parse-server — Vulnerabilities & Security Advisories 122

All 122 CVE vulnerabilities found in parse-server, with AI-generated Chinese analysis, references, and POCs.

This page documents vulnerability aggregations for the open-source Node.js backend framework known as parse-server, specifically focusing on security weaknesses and related advisories. It collects information regarding various vulnerability types, including injection flaws, broken access control, and security misconfigurations, covering reports published from early 2018 through the present day. The scope includes both critical severity issues and lower-severity defects that impact the stability and confidentiality of applications built on this platform. Here, users can track advisories issued by the maintainers and community contributors to understand the timeline of security patches and hotfixes released for the project. Readers can analyze trends in weakness classes to identify recurring patterns in the codebase that may indicate systemic architectural issues. Additionally, the page provides a comprehensive history of vulnerabilities associated with parse-server, allowing developers to review past incidents and assess the impact of specific versions. This resource serves as a central reference for security auditors and developers seeking to understand the risk landscape of the product. By aggregating data from multiple sources, including GitHub issues, package managers, and security databases, the page offers a holistic view of the product's security posture over time, facilitating better risk management and informed decision-making for users integrating parse-server into their technology stacks.

Vendor: Parse

CVE IDTitleCVSSSeverityPublished
CVE-2026-33539 Parse Server: SQL injection via aggregate and distinct field names in PostgreSQL adapter CWE-89 7.2 -2026-03-24
CVE-2026-33538 Parse Server: Denial of service via unindexed database query for unconfigured auth providers CWE-400 7.5 -2026-03-24
CVE-2026-33527 Parse Server: Session update endpoint allows overwriting server-generated session fields CWE-863 4.3 -2026-03-24
CVE-2026-33508 Parse Server: LiveQuery subscription query depth bypass CWE-674 7.5 -2026-03-24
CVE-2026-33498 Parse Server: Query condition depth bypass via pre-validation transform pipeline CWE-674 7.5 -2026-03-24
CVE-2026-33429 Parse Server: Protected field change detection oracle via LiveQuery watch parameter CWE-203 3.7 -2026-03-24
CVE-2026-33421 Parse Server: LiveQuery bypasses CLP pointer permission enforcement CWE-863 6.5 -2026-03-24
CVE-2026-33409 Parse Server: Auth provider validation bypass on login via partial authData CWE-287 8.1 -2026-03-24
CVE-2026-33323 Parse Server: Email verification resend page leaks user existence CWE-204 5.3 -2026-03-24
CVE-2026-33163 Parse Server leaks protected fields via LiveQuery afterEvent trigger CWE-200 6.5 -2026-03-18
CVE-2026-33042 Parse Server affected by empty authData bypassing credential requirement on signup CWE-287 7.5 -2026-03-18
CVE-2026-32944 Parse Server crash via deeply nested query condition operators CWE-674 7.5 -2026-03-18
CVE-2026-32943 Parse Server has a password reset token single-use bypass via concurrent requests CWE-367 7.4 -2026-03-18
CVE-2026-32886 Parse Server's Cloud function dispatch crashes server via prototype chain traversal CWE-1321 7.5 -2026-03-18
CVE-2026-32878 Parse Server vulnerable to schema poisoning via prototype pollution in deep copy CWE-1321 8.2 -2026-03-18
CVE-2026-32770 Parse Server: LiveQuery subscription with invalid regular expression crashes server CWE-248 5.9 Medium2026-03-18
CVE-2026-32742 Parse Server session creation endpoint allows overwriting server-generated session fields CWE-915 4.3 Medium2026-03-18
CVE-2026-32728 Parse Server has a stored XSS filter bypass via Content-Type MIME parameter and missing XML extension blocklist entries CWE-79 9.8 -2026-03-18
CVE-2026-32594 Parse Server GraphQL WebSocket endpoint bypasses security middleware CWE-306 9.1AICriticalAI2026-03-13
CVE-2026-32269 Parse Server OAuth2 adapter app ID validation sends wrong token to introspection endpoint CWE-683 9.4AICriticalAI2026-03-12
CVE-2026-32248 Parse Server: Account takeover via operator injection in authentication data identifier CWE-943 7.4AIHighAI2026-03-12
CVE-2026-32242 Parse Server OAuth2 adapter shares mutable state across providers via singleton instance CWE-362 8.2AIHighAI2026-03-12
CVE-2026-32234 Parse Server has a SQL injection via query field name when using PostgreSQL CWE-89 8.8AIHighAI2026-03-11
CVE-2026-32098 Parse Server has a protected fields bypass via LiveQuery subscription WHERE clause CWE-200 7.5AIHighAI2026-03-11
CVE-2026-31901 Parse Server has user enumeration via email verification endpoint CWE-204 5.3AIMediumAI2026-03-11
CVE-2026-31875 Parse Server MFA recovery codes not consumed after use CWE-672 8.1AIHighAI2026-03-11
CVE-2026-31872 Parse Server has a protected fields bypass via dot-notation in query and sort CWE-284 5.3AIMediumAI2026-03-11
CVE-2026-31871 Parse Server has a SQL Injection via dot-notation sub-key name in `Increment` operation on PostgreSQL CWE-89 9.8AICriticalAI2026-03-11
CVE-2026-31868 Parse Server has Stored XSS via file upload of HTML-renderable file types CWE-79 7.6AIHighAI2026-03-11
CVE-2026-31856 Parse Server has a SQL injection via `Increment` operation on nested object field in PostgreSQL CWE-89 9.1AICriticalAI2026-03-11

All 122 known CVE vulnerabilities affecting parse-server with full Chinese analysis, references, and POCs where available.