Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

parse-server — Vulnerabilities & Security Advisories 122

All 122 CVE vulnerabilities found in parse-server, with AI-generated Chinese analysis, references, and POCs.

This page catalogs known security vulnerabilities associated with the parse-server product, focusing on the general category of software weaknesses. It aggregates a comprehensive list of security issues affecting this specific server implementation, covering vulnerability data from initial releases through to recent updates. The collection includes diverse weakness types such as authentication flaws, access control misconfigurations, and input validation errors that have been identified and reported within the ecosystem. Readers can use this resource to track a vendor's advisories by monitoring how the maintainers respond to disclosed issues over time. The page also allows users to understand a weakness class by examining how specific technical flaws manifest within the parse-server architecture and its dependencies. Additionally, you can look up a product's vulnerability history to assess the overall security posture and remediation speed of the software over its lifecycle. This structured overview helps developers and security professionals evaluate the risk profile of parse-server deployments by providing context on the nature and frequency of reported incidents. By reviewing these aggregated details, stakeholders can make informed decisions about upgrade priorities, configuration hardening, and third-party risk management without needing to navigate through scattered individual reports. The content is organized to facilitate efficient research and comparative analysis across different versions and vulnerability categories.

Vendor: Parse

CVE IDTitleCVSSSeverityPublished
CVE-2025-53364 Parse Server exposes the data schema via GraphQL API CWE-497 5.3 Medium2025-07-10
CVE-2025-30168 Parse Server has an OAuth login vulnerability CWE-287 6.9 Medium2025-03-21
CVE-2024-47183 Parse Server's custom object ID allows to acquire role privileges CWE-285 8.1 High2024-10-04
CVE-2024-39309 ZDI-CAN-23894: Parse Server literalizeRegexPart SQL Injection Authentication Bypass Vulnerability CWE-288 9.8 Critical2024-07-01
CVE-2024-29027 Parse Server crash and RCE via invalid Cloud Function or Cloud Job name CWE-74 9.1 Critical2024-03-19
CVE-2024-27298 Parse Server literalizeRegexPart SQL Injection CWE-89 10.0 Critical2024-03-01
CVE-2023-46119 Parse Server may crash when uploading file without extension CWE-23 7.5 High2023-10-25
CVE-2023-41058 Trigger `beforeFind` not invoked in internal query pipeline in parse-server CWE-670 7.5 High2023-09-04
CVE-2023-36475 Parse Server vulnerable to remote code execution via MongoDB BSON parser through prototype pollution CWE-1321 9.8 Critical2023-06-28
CVE-2023-32689 Parse Server vulnerable to phishing attack vulnerability that involves uploading malicious HTML file CWE-434 6.3 Medium2023-05-30
CVE-2023-22474 Parse Server is vulnerable to authentication bypass via spoofing CWE-290 8.7 High2023-02-03
CVE-2022-39396 Parse Server vulnerable to Remote Code Execution via prototype pollution in MongoDB BSON parser CWE-1321 9.8 Critical2022-11-10
CVE-2022-41878 Parse Server Prototype pollution and Injection via Cloud Code Webhooks or Cloud Code Triggers CWE-74 7.2 High2022-11-10
CVE-2022-41879 Parse Server subject to Prototype pollution via Cloud Code Webhooks CWE-1321 7.2 High2022-11-10
CVE-2022-39313 Parse Server crashes when receiving file download request with invalid byte range CWE-1284 7.5 High2022-10-24
CVE-2022-39231 Parse Server subject to Improper Authentication allowing Auth adapter app ID validation to be circumvented CWE-287 3.7 Low2022-09-23
CVE-2022-39225 Parse Server subject to Incorrect Resource Transfer Between Spheres CWE-669 4.3 Medium2022-09-23
CVE-2022-36079 Parse Server vulnerable to brute force guessing of user sensitive data via search patterns CWE-200 8.6 High2022-09-07
CVE-2022-31112 Protected fields exposed via LiveQuery in parse-server CWE-200 8.2 High2022-06-30
CVE-2022-31089 Invalid file request can crashe parse-server CWE-706 7.5 High2022-06-27
CVE-2022-31083 Authentication bypass in Parse Server Apple Game Center auth adapter CWE-287 8.6 High2022-06-17
CVE-2022-24901 Authentication bypass and denial of service (DoS) vulnerabilities in Apple Game Center auth adapter CWE-295 7.5 High2022-05-04
CVE-2022-24760 Command Injection in Parse server CWE-74 10.0 Critical2022-03-11
CVE-2021-41109 LiveQuery publishes user session tokens CWE-200 7.5 High2021-09-30
CVE-2021-39187 Crash server with query parameter CWE-74 7.5 High2021-09-02
CVE-2021-39138 New anonymous user session acts as if it's created with password CWE-287 4.8 Medium2021-08-18
CVE-2020-26288 Parse Server stores password in plain text CWE-312 7.7 High2020-12-30
CVE-2020-15270 Improper session expiration in Parse Server CWE-672 4.3 Medium2020-10-22
CVE-2020-15126 Information disclosure through Viewer query in parse-server CWE-863 6.5 Medium2020-07-22
CVE-2020-5251 Information disclosure in parse-server CWE-285 7.7 High2020-03-04

All 122 known CVE vulnerabilities affecting parse-server with full Chinese analysis, references, and POCs where available.