Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

parse-server — Vulnerabilities & Security Advisories 122

All 122 CVE vulnerabilities found in parse-server, with AI-generated Chinese analysis, references, and POCs.

This page catalogs known security vulnerabilities associated with the parse-server product, focusing on the general category of software weaknesses. It aggregates a comprehensive list of security issues affecting this specific server implementation, covering vulnerability data from initial releases through to recent updates. The collection includes diverse weakness types such as authentication flaws, access control misconfigurations, and input validation errors that have been identified and reported within the ecosystem. Readers can use this resource to track a vendor's advisories by monitoring how the maintainers respond to disclosed issues over time. The page also allows users to understand a weakness class by examining how specific technical flaws manifest within the parse-server architecture and its dependencies. Additionally, you can look up a product's vulnerability history to assess the overall security posture and remediation speed of the software over its lifecycle. This structured overview helps developers and security professionals evaluate the risk profile of parse-server deployments by providing context on the nature and frequency of reported incidents. By reviewing these aggregated details, stakeholders can make informed decisions about upgrade priorities, configuration hardening, and third-party risk management without needing to navigate through scattered individual reports. The content is organized to facilitate efficient research and comparative analysis across different versions and vulnerability categories.

Vendor: Parse

CVE IDTitleCVSSSeverityPublished
CVE-2026-31840 Parse Server has a SQL injection via dot-notation field name in PostgreSQL CWE-89 9.8AICriticalAI2026-03-11
CVE-2026-31828 Parse Server has an LDAP injection via unsanitized user input in DN and group filter construction CWE-90 8.8AIHighAI2026-03-10
CVE-2026-31800 Parse Server: Classes `_GraphQLConfig` and `_Audience` master key bypass via generic class routes CWE-862 9.8AICriticalAI2026-03-10
CVE-2026-30972 Parse Server has a rate limit bypass via batch request endpoint CWE-799 5.3AIMediumAI2026-03-10
CVE-2026-30967 Parse Server OAuth2 authentication adapter account takeover via identity spoofing CWE-287 9.8AICriticalAI2026-03-10
CVE-2026-30966 Parse Server role escalation and CLP bypass via direct `_Join` table write CWE-284 10.0 Critical2026-03-10
CVE-2026-30965 Parse Server session token exfiltration via `redirectClassNameForKey` query parameter CWE-863 8.1AIHighAI2026-03-10
CVE-2026-30962 Parse Server has a protected fields bypass via logical query operators CWE-284 6.5AIMediumAI2026-03-10
CVE-2026-30949 Parse Server is missing audience validation in Keycloak authentication adapter CWE-287 9.1AICriticalAI2026-03-10
CVE-2026-30948 Parse Server has stored cross-site scripting (XSS) via SVG file upload CWE-79 5.4AIMediumAI2026-03-10
CVE-2026-30947 Parse Server ha a bypass of class-level permissions in LiveQuery CWE-863 7.5AIHighAI2026-03-10
CVE-2026-30946 Parse Server affected by denial-of-service via unbounded query complexity in REST and GraphQL API CWE-770 7.5AIHighAI2026-03-10
CVE-2026-30941 Parse Server has a NoSQL injection via token type in password reset and email verification endpoints CWE-943 9.8AICriticalAI2026-03-10
CVE-2026-30939 Parse Server has Denial of Service (DoS) and Cloud Function Dispatch Bypass via Prototype Chain Resolution CWE-1321 7.5AIHighAI2026-03-10
CVE-2026-30938 Parse Server has denylist `requestKeywordDenylist` keyword scan bypass through nested object placement CWE-693 9.1AICriticalAI2026-03-10
CVE-2026-30925 Parse Server affected by Regular Expression Denial of Service (ReDoS) via `$regex` query in LiveQuery CWE-1333 7.5AIHighAI2026-03-09
CVE-2026-30854 Parse Server: GraphQL `__type` introspection bypass via inline fragments when public introspection is disabled CWE-863 5.3 -2026-03-07
CVE-2026-30850 Parse Server: File metadata endpoint bypasses `beforeFind` / `afterFind` trigger authorization CWE-862 5.3 -2026-03-07
CVE-2026-30848 Parse Server: `PagesRouter` path traversal allows reading files outside configured pages directory CWE-22 7.5 -2026-03-07
CVE-2026-30863 Parse Server: JWT audience validation bypass in Google, Apple, and Facebook authentication adapters CWE-287 9.8 -2026-03-07
CVE-2026-30835 Parse Server: Malformed `$regex` query leaks database error details in API response CWE-209 7.5 -2026-03-06
CVE-2026-30229 Parse Server: Endpoint `/loginAs` allows `readOnlyMasterKey` to gain full read and write access as any user CWE-863 9.8 -2026-03-06
CVE-2026-30228 Parse Server: File creation and deletion bypasses `readOnlyMasterKey` write restriction CWE-863 9.1 -2026-03-06
CVE-2026-29182 Parse Server: Cloud Hooks and Cloud Jobs bypass `readOnlyMasterKey` write restriction CWE-863 8.1 -2026-03-06
CVE-2026-27804 Parse Server: Account takeover via JWT algorithm confusion in Google auth adapter CWE-327 9.8AICriticalAI2026-02-25
CVE-2025-68150 Parse Server has Server-Side Request Forgery (SSRF) in Instagram OAuth Adapter CWE-918 9.1AICriticalAI2025-12-16
CVE-2025-68115 Parse Server vulnerable to Cross-Site Scripting (XSS) via Unescaped Mustache Template Variables CWE-79 6.1AIMediumAI2025-12-16
CVE-2025-67727 Parse Server GitHub CI workflow vulnerable to RCE through Improper Privilege Management CWE-94 9.8AICriticalAI2025-12-12
CVE-2025-64502 Parse Server allows public `explain` queries which may expose sensitive database performance information and schema details CWE-201 5.3 -2025-11-10
CVE-2025-64430 Parse Server Vulnerable to Server-Side Request Forgery (SSRF) in File Upload via URI Format CWE-918 7.5 High2025-11-07

All 122 known CVE vulnerabilities affecting parse-server with full Chinese analysis, references, and POCs where available.