Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

parse-community — Vulnerabilities & Security Advisories 126

Browse all 126 CVE security advisories affecting parse-community. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Parse Community provides an open-source backend infrastructure designed to simplify mobile and web application development by offering ready-to-use APIs for data storage, user authentication, and push notifications. This framework allows developers to deploy their own servers, reducing reliance on proprietary third-party services. However, its widespread adoption has made it a frequent target for security researchers, resulting in over 110 recorded Common Vulnerabilities and Exposures (CVEs). Historically, these flaws predominantly involve remote code execution, cross-site scripting, and privilege escalation, often stemming from insufficient input validation or insecure default configurations in older versions. While the project maintains an active security response process, the sheer volume of past incidents highlights the complexity of maintaining secure, self-hosted environments. Users are strongly advised to keep installations updated and adhere to strict configuration guidelines to mitigate risks associated with these known vulnerabilities.

CVE ID Title CVSS Severity Published
CVE-2026-31840 Parse Server has a SQL injection via dot-notation field name in PostgreSQL — parse-server CWE-89 9.8AI Critical AI 2026-03-11
CVE-2026-31828 Parse Server has an LDAP injection via unsanitized user input in DN and group filter construction — parse-server CWE-90 8.8AI High AI 2026-03-10
CVE-2026-31800 Parse Server: Classes `_GraphQLConfig` and `_Audience` master key bypass via generic class routes — parse-server CWE-862 9.8AI Critical AI 2026-03-10
CVE-2026-30972 Parse Server has a rate limit bypass via batch request endpoint — parse-server CWE-799 5.3AI Medium AI 2026-03-10
CVE-2026-30967 Parse Server OAuth2 authentication adapter account takeover via identity spoofing — parse-server CWE-287 9.8AI Critical AI 2026-03-10
CVE-2026-30966 Parse Server role escalation and CLP bypass via direct `_Join` table write — parse-server CWE-284 10.0 Critical 2026-03-10
CVE-2026-30965 Parse Server session token exfiltration via `redirectClassNameForKey` query parameter — parse-server CWE-863 8.1AI High AI 2026-03-10
CVE-2026-30962 Parse Server has a protected fields bypass via logical query operators — parse-server CWE-284 6.5AI Medium AI 2026-03-10
CVE-2026-30949 Parse Server is missing audience validation in Keycloak authentication adapter — parse-server CWE-287 9.1AI Critical AI 2026-03-10
CVE-2026-30948 Parse Server has stored cross-site scripting (XSS) via SVG file upload — parse-server CWE-79 5.4AI Medium AI 2026-03-10
CVE-2026-30947 Parse Server ha a bypass of class-level permissions in LiveQuery — parse-server CWE-863 7.5AI High AI 2026-03-10
CVE-2026-30946 Parse Server affected by denial-of-service via unbounded query complexity in REST and GraphQL API — parse-server CWE-770 7.5AI High AI 2026-03-10
CVE-2026-30941 Parse Server has a NoSQL injection via token type in password reset and email verification endpoints — parse-server CWE-943 9.8AI Critical AI 2026-03-10
CVE-2026-30939 Parse Server has Denial of Service (DoS) and Cloud Function Dispatch Bypass via Prototype Chain Resolution — parse-server CWE-1321 7.5AI High AI 2026-03-10
CVE-2026-30938 Parse Server has denylist `requestKeywordDenylist` keyword scan bypass through nested object placement — parse-server CWE-693 9.1AI Critical AI 2026-03-10
CVE-2026-30925 Parse Server affected by Regular Expression Denial of Service (ReDoS) via `$regex` query in LiveQuery — parse-server CWE-1333 7.5AI High AI 2026-03-09
CVE-2026-30854 Parse Server: GraphQL `__type` introspection bypass via inline fragments when public introspection is disabled — parse-server CWE-863 5.3 - 2026-03-07
CVE-2026-30850 Parse Server: File metadata endpoint bypasses `beforeFind` / `afterFind` trigger authorization — parse-server CWE-862 5.3 - 2026-03-07
CVE-2026-30848 Parse Server: `PagesRouter` path traversal allows reading files outside configured pages directory — parse-server CWE-22 7.5 - 2026-03-07
CVE-2026-30863 Parse Server: JWT audience validation bypass in Google, Apple, and Facebook authentication adapters — parse-server CWE-287 9.8 - 2026-03-07
CVE-2026-30835 Parse Server: Malformed `$regex` query leaks database error details in API response — parse-server CWE-209 7.5 - 2026-03-06
CVE-2026-30229 Parse Server: Endpoint `/loginAs` allows `readOnlyMasterKey` to gain full read and write access as any user — parse-server CWE-863 9.8 - 2026-03-06
CVE-2026-30228 Parse Server: File creation and deletion bypasses `readOnlyMasterKey` write restriction — parse-server CWE-863 9.1 - 2026-03-06
CVE-2026-29182 Parse Server: Cloud Hooks and Cloud Jobs bypass `readOnlyMasterKey` write restriction — parse-server CWE-863 8.1 - 2026-03-06
CVE-2026-27804 Parse Server: Account takeover via JWT algorithm confusion in Google auth adapter — parse-server CWE-327 9.8AI Critical AI 2026-02-25
CVE-2026-27595 Parse Dashboard has incomplete authentication on AI Agent endpoint — parse-dashboard CWE-306 9.1AI Critical AI 2026-02-25
CVE-2026-27610 Parse Dashboard Has a Cache Key Collision that Leaks Master Key to Read-Only Sessions — parse-dashboard CWE-1289 5.3AI Medium AI 2026-02-25
CVE-2026-27609 Parse Dashboard Missing CSRF Protection on Agent Endpoint — parse-dashboard CWE-352 8.8AI High AI 2026-02-25
CVE-2026-27608 Parse Dashboard Missing Authorization on Agent Endpoint — parse-dashboard CWE-862 8.8AI High AI 2026-02-25
CVE-2025-68150 Parse Server has Server-Side Request Forgery (SSRF) in Instagram OAuth Adapter — parse-server CWE-918 9.1AI Critical AI 2025-12-16

This page lists every published CVE security advisory associated with parse-community. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.