Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

parse-server — Vulnerabilities & Security Advisories 122

All 122 CVE vulnerabilities found in parse-server, with AI-generated Chinese analysis, references, and POCs.

This page catalogs known security vulnerabilities associated with the parse-server product, focusing on the general category of software weaknesses. It aggregates a comprehensive list of security issues affecting this specific server implementation, covering vulnerability data from initial releases through to recent updates. The collection includes diverse weakness types such as authentication flaws, access control misconfigurations, and input validation errors that have been identified and reported within the ecosystem. Readers can use this resource to track a vendor's advisories by monitoring how the maintainers respond to disclosed issues over time. The page also allows users to understand a weakness class by examining how specific technical flaws manifest within the parse-server architecture and its dependencies. Additionally, you can look up a product's vulnerability history to assess the overall security posture and remediation speed of the software over its lifecycle. This structured overview helps developers and security professionals evaluate the risk profile of parse-server deployments by providing context on the nature and frequency of reported incidents. By reviewing these aggregated details, stakeholders can make informed decisions about upgrade priorities, configuration hardening, and third-party risk management without needing to navigate through scattered individual reports. The content is organized to facilitate efficient research and comparative analysis across different versions and vulnerability categories.

Vendor: Parse

CVE ID Title CVSS Severity Published
CVE-2026-66009 Parse Server 9.0.0 Information Disclosure via GraphQL Error Messages CWE-209 6.3 Medium 2026-07-24
CVE-2026-66008 Parse Server 9.0.0 Information Disclosure via GraphQL Error Messages CWE-209 6.3 Medium 2026-07-24
CVE-2026-64627 Parse Server 9.0.0 Schema Disclosure via GraphQL Variable Coercion CWE-209 6.9 Medium 2026-07-21
CVE-2026-61448 Parse Server 9.0.0 Stored XSS via malformed Content-Type CWE-434 - - 2026-07-11
CVE-2026-57481 Parse Server: LiveQuery discloses object data to a subscriber across an ACL read-access change CWE-200 - - 2026-07-08
CVE-2026-57480 Parse Server: Denial of service via exponential-time processing of deeply nested query operators CWE-407 - - 2026-07-08
CVE-2026-55778 Parse Server: Stored XSS via non-standard file extension bypassing file upload extension blocklist CWE-434 - - 2026-07-08
CVE-2021-47987 Parse Server - Arbitrary Code Execution via Malicious Version Tags CWE-494 7.5 High 2026-06-25
CVE-2021-47986 Parse Server - Unreviewed Code Execution via Malicious Version Tags CWE-494 7.5 High 2026-06-25
CVE-2026-53726 Parse Server: Relation `$relatedTo` query bypasses `protectedFields` and owning-object ACL CWE-639 - - 2026-06-12
CVE-2026-53725 Parse Server: Endpoints `/login` and `/verifyPassword` disclose MFA secrets and protected fields when `_User` get is denied CWE-200 - - 2026-06-12
CVE-2026-53724 Parse Server: Stored XSS via trailing-dot filename bypassing file upload extension blocklist CWE-434 - - 2026-06-12
CVE-2026-50008 Parse Server: Server option routeAllowList is bypassable through batch sub-requests CWE-863 - - 2026-06-12
CVE-2026-47138 Parse Server: Pre-authentication denial of service via client version header regex backtracking CWE-1333 - - 2026-06-12
CVE-2026-47248 Parse Server: GraphQL "Did you mean" validation suggestions disclose schema to unauthenticated callers CWE-209 - - 2026-06-12
CVE-2026-43930 Parse Server: MFA SMS one-time password accepted twice under concurrent login CWE-362 - - 2026-05-12
CVE-2026-39381 Parse Server's Endpoint `/sessions/me` bypasses `_Session` `protectedFields` CWE-863 6.5AI Medium AI 2026-04-07
CVE-2026-39321 Parse Server has a login timing side-channel reveals user existence CWE-208 4.8AI Medium AI 2026-04-07
CVE-2026-35200 Parse Server has a file upload Content-Type override via extension mismatch CWE-436 8.2AI High AI 2026-04-06
CVE-2026-34784 Parse Server: Streaming file download bypasses afterFind file trigger authorization CWE-285 7.5 - 2026-03-31
CVE-2026-34215 Parse Server: Auth data exposed via verify password endpoint CWE-200 6.5 - 2026-03-31
CVE-2026-34595 Parse Server: LiveQuery protected-field guard bypass via array-like logical operator value CWE-843 8.8AI High AI 2026-03-31
CVE-2026-34574 Parse Server: Session field immutability bypass via falsy-value guard CWE-697 7.1AI High AI 2026-03-31
CVE-2026-34573 Parse Server: GraphQL complexity validator exponential fragment traversal DoS CWE-407 7.5AI High AI 2026-03-31
CVE-2026-34532 Parse Server: Cloud function validator bypass via prototype chain traversal CWE-863 9.1AI Critical AI 2026-03-31
CVE-2026-34373 Parse Server: GraphQL API endpoint ignores CORS origin restriction CWE-346 8.2AI High AI 2026-03-31
CVE-2026-34363 Parse Server: LiveQuery protected field leak via shared mutable state across concurrent subscribers CWE-362 7.5AI High AI 2026-03-31
CVE-2026-34224 Parse Server: MFA single-use token bypass via concurrent authData login requests CWE-367 8.2AI High AI 2026-03-31
CVE-2026-33627 Parse Server: Auth data exposed via /users/me endpoint CWE-200 8.1 - 2026-03-24
CVE-2026-33624 Parse Server: MFA recovery code single-use bypass via concurrent requests CWE-367 9.1 - 2026-03-24

All 122 known CVE vulnerabilities affecting parse-server with full Chinese analysis, references, and POCs where available.