Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

parse-community — Vulnerabilities & Security Advisories 126

Browse all 126 CVE security advisories affecting parse-community. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Parse Community provides an open-source backend infrastructure designed to simplify mobile and web application development by offering ready-to-use APIs for data storage, user authentication, and push notifications. This framework allows developers to deploy their own servers, reducing reliance on proprietary third-party services. However, its widespread adoption has made it a frequent target for security researchers, resulting in over 110 recorded Common Vulnerabilities and Exposures (CVEs). Historically, these flaws predominantly involve remote code execution, cross-site scripting, and privilege escalation, often stemming from insufficient input validation or insecure default configurations in older versions. While the project maintains an active security response process, the sheer volume of past incidents highlights the complexity of maintaining secure, self-hosted environments. Users are strongly advised to keep installations updated and adhere to strict configuration guidelines to mitigate risks associated with these known vulnerabilities.

CVE ID Title CVSS Severity Published
CVE-2026-33539 Parse Server: SQL injection via aggregate and distinct field names in PostgreSQL adapter — parse-server CWE-89 7.2 - 2026-03-24
CVE-2026-33538 Parse Server: Denial of service via unindexed database query for unconfigured auth providers — parse-server CWE-400 7.5 - 2026-03-24
CVE-2026-33527 Parse Server: Session update endpoint allows overwriting server-generated session fields — parse-server CWE-863 4.3 - 2026-03-24
CVE-2026-33508 Parse Server: LiveQuery subscription query depth bypass — parse-server CWE-674 7.5 - 2026-03-24
CVE-2026-33498 Parse Server: Query condition depth bypass via pre-validation transform pipeline — parse-server CWE-674 7.5 - 2026-03-24
CVE-2026-33429 Parse Server: Protected field change detection oracle via LiveQuery watch parameter — parse-server CWE-203 3.7 - 2026-03-24
CVE-2026-33421 Parse Server: LiveQuery bypasses CLP pointer permission enforcement — parse-server CWE-863 6.5 - 2026-03-24
CVE-2026-33409 Parse Server: Auth provider validation bypass on login via partial authData — parse-server CWE-287 8.1 - 2026-03-24
CVE-2026-33323 Parse Server: Email verification resend page leaks user existence — parse-server CWE-204 5.3 - 2026-03-24
CVE-2026-33163 Parse Server leaks protected fields via LiveQuery afterEvent trigger — parse-server CWE-200 6.5 - 2026-03-18
CVE-2026-33042 Parse Server affected by empty authData bypassing credential requirement on signup — parse-server CWE-287 7.5 - 2026-03-18
CVE-2026-32944 Parse Server crash via deeply nested query condition operators — parse-server CWE-674 7.5 - 2026-03-18
CVE-2026-32943 Parse Server has a password reset token single-use bypass via concurrent requests — parse-server CWE-367 7.4 - 2026-03-18
CVE-2026-32886 Parse Server's Cloud function dispatch crashes server via prototype chain traversal — parse-server CWE-1321 7.5 - 2026-03-18
CVE-2026-32878 Parse Server vulnerable to schema poisoning via prototype pollution in deep copy — parse-server CWE-1321 8.2 - 2026-03-18
CVE-2026-32770 Parse Server: LiveQuery subscription with invalid regular expression crashes server — parse-server CWE-248 5.9 Medium 2026-03-18
CVE-2026-32742 Parse Server session creation endpoint allows overwriting server-generated session fields — parse-server CWE-915 4.3 Medium 2026-03-18
CVE-2026-32728 Parse Server has a stored XSS filter bypass via Content-Type MIME parameter and missing XML extension blocklist entries — parse-server CWE-79 9.8 - 2026-03-18
CVE-2026-32594 Parse Server GraphQL WebSocket endpoint bypasses security middleware — parse-server CWE-306 9.1AI Critical AI 2026-03-13
CVE-2026-32269 Parse Server OAuth2 adapter app ID validation sends wrong token to introspection endpoint — parse-server CWE-683 9.4AI Critical AI 2026-03-12
CVE-2026-32248 Parse Server: Account takeover via operator injection in authentication data identifier — parse-server CWE-943 7.4AI High AI 2026-03-12
CVE-2026-32242 Parse Server OAuth2 adapter shares mutable state across providers via singleton instance — parse-server CWE-362 8.2AI High AI 2026-03-12
CVE-2026-32234 Parse Server has a SQL injection via query field name when using PostgreSQL — parse-server CWE-89 8.8AI High AI 2026-03-11
CVE-2026-32098 Parse Server has a protected fields bypass via LiveQuery subscription WHERE clause — parse-server CWE-200 7.5AI High AI 2026-03-11
CVE-2026-31901 Parse Server has user enumeration via email verification endpoint — parse-server CWE-204 5.3AI Medium AI 2026-03-11
CVE-2026-31875 Parse Server MFA recovery codes not consumed after use — parse-server CWE-672 8.1AI High AI 2026-03-11
CVE-2026-31872 Parse Server has a protected fields bypass via dot-notation in query and sort — parse-server CWE-284 5.3AI Medium AI 2026-03-11
CVE-2026-31871 Parse Server has a SQL Injection via dot-notation sub-key name in `Increment` operation on PostgreSQL — parse-server CWE-89 9.8AI Critical AI 2026-03-11
CVE-2026-31868 Parse Server has Stored XSS via file upload of HTML-renderable file types — parse-server CWE-79 7.6AI High AI 2026-03-11
CVE-2026-31856 Parse Server has a SQL injection via `Increment` operation on nested object field in PostgreSQL — parse-server CWE-89 9.1AI Critical AI 2026-03-11

This page lists every published CVE security advisory associated with parse-community. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.