Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

parse-server — Vulnerabilities & Security Advisories 122

All 122 CVE vulnerabilities found in parse-server, with AI-generated Chinese analysis, references, and POCs.

This page documents vulnerability aggregations for the open-source Node.js backend framework known as parse-server, specifically focusing on security weaknesses and related advisories. It collects information regarding various vulnerability types, including injection flaws, broken access control, and security misconfigurations, covering reports published from early 2018 through the present day. The scope includes both critical severity issues and lower-severity defects that impact the stability and confidentiality of applications built on this platform. Here, users can track advisories issued by the maintainers and community contributors to understand the timeline of security patches and hotfixes released for the project. Readers can analyze trends in weakness classes to identify recurring patterns in the codebase that may indicate systemic architectural issues. Additionally, the page provides a comprehensive history of vulnerabilities associated with parse-server, allowing developers to review past incidents and assess the impact of specific versions. This resource serves as a central reference for security auditors and developers seeking to understand the risk landscape of the product. By aggregating data from multiple sources, including GitHub issues, package managers, and security databases, the page offers a holistic view of the product's security posture over time, facilitating better risk management and informed decision-making for users integrating parse-server into their technology stacks.

Vendor: Parse

CVE IDTitleCVSSSeverityPublished
CVE-2026-31840 Parse Server has a SQL injection via dot-notation field name in PostgreSQL CWE-89 9.8AICriticalAI2026-03-11
CVE-2026-31828 Parse Server has an LDAP injection via unsanitized user input in DN and group filter construction CWE-90 8.8AIHighAI2026-03-10
CVE-2026-31800 Parse Server: Classes `_GraphQLConfig` and `_Audience` master key bypass via generic class routes CWE-862 9.8AICriticalAI2026-03-10
CVE-2026-30972 Parse Server has a rate limit bypass via batch request endpoint CWE-799 5.3AIMediumAI2026-03-10
CVE-2026-30967 Parse Server OAuth2 authentication adapter account takeover via identity spoofing CWE-287 9.8AICriticalAI2026-03-10
CVE-2026-30966 Parse Server role escalation and CLP bypass via direct `_Join` table write CWE-284 10.0 Critical2026-03-10
CVE-2026-30965 Parse Server session token exfiltration via `redirectClassNameForKey` query parameter CWE-863 8.1AIHighAI2026-03-10
CVE-2026-30962 Parse Server has a protected fields bypass via logical query operators CWE-284 6.5AIMediumAI2026-03-10
CVE-2026-30949 Parse Server is missing audience validation in Keycloak authentication adapter CWE-287 9.1AICriticalAI2026-03-10
CVE-2026-30948 Parse Server has stored cross-site scripting (XSS) via SVG file upload CWE-79 5.4AIMediumAI2026-03-10
CVE-2026-30947 Parse Server ha a bypass of class-level permissions in LiveQuery CWE-863 7.5AIHighAI2026-03-10
CVE-2026-30946 Parse Server affected by denial-of-service via unbounded query complexity in REST and GraphQL API CWE-770 7.5AIHighAI2026-03-10
CVE-2026-30941 Parse Server has a NoSQL injection via token type in password reset and email verification endpoints CWE-943 9.8AICriticalAI2026-03-10
CVE-2026-30939 Parse Server has Denial of Service (DoS) and Cloud Function Dispatch Bypass via Prototype Chain Resolution CWE-1321 7.5AIHighAI2026-03-10
CVE-2026-30938 Parse Server has denylist `requestKeywordDenylist` keyword scan bypass through nested object placement CWE-693 9.1AICriticalAI2026-03-10
CVE-2026-30925 Parse Server affected by Regular Expression Denial of Service (ReDoS) via `$regex` query in LiveQuery CWE-1333 7.5AIHighAI2026-03-09
CVE-2026-30854 Parse Server: GraphQL `__type` introspection bypass via inline fragments when public introspection is disabled CWE-863 5.3 -2026-03-07
CVE-2026-30850 Parse Server: File metadata endpoint bypasses `beforeFind` / `afterFind` trigger authorization CWE-862 5.3 -2026-03-07
CVE-2026-30848 Parse Server: `PagesRouter` path traversal allows reading files outside configured pages directory CWE-22 7.5 -2026-03-07
CVE-2026-30863 Parse Server: JWT audience validation bypass in Google, Apple, and Facebook authentication adapters CWE-287 9.8 -2026-03-07
CVE-2026-30835 Parse Server: Malformed `$regex` query leaks database error details in API response CWE-209 7.5 -2026-03-06
CVE-2026-30229 Parse Server: Endpoint `/loginAs` allows `readOnlyMasterKey` to gain full read and write access as any user CWE-863 9.8 -2026-03-06
CVE-2026-30228 Parse Server: File creation and deletion bypasses `readOnlyMasterKey` write restriction CWE-863 9.1 -2026-03-06
CVE-2026-29182 Parse Server: Cloud Hooks and Cloud Jobs bypass `readOnlyMasterKey` write restriction CWE-863 8.1 -2026-03-06
CVE-2026-27804 Parse Server: Account takeover via JWT algorithm confusion in Google auth adapter CWE-327 9.8AICriticalAI2026-02-25
CVE-2025-68150 Parse Server has Server-Side Request Forgery (SSRF) in Instagram OAuth Adapter CWE-918 9.1AICriticalAI2025-12-16
CVE-2025-68115 Parse Server vulnerable to Cross-Site Scripting (XSS) via Unescaped Mustache Template Variables CWE-79 6.1AIMediumAI2025-12-16
CVE-2025-67727 Parse Server GitHub CI workflow vulnerable to RCE through Improper Privilege Management CWE-94 9.8AICriticalAI2025-12-12
CVE-2025-64502 Parse Server allows public `explain` queries which may expose sensitive database performance information and schema details CWE-201 5.3 -2025-11-10
CVE-2025-64430 Parse Server Vulnerable to Server-Side Request Forgery (SSRF) in File Upload via URI Format CWE-918 7.5 High2025-11-07

All 122 known CVE vulnerabilities affecting parse-server with full Chinese analysis, references, and POCs where available.