Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

parse-community — Vulnerabilities & Security Advisories 126

Browse all 126 CVE security advisories affecting parse-community. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Parse Community provides an open-source backend infrastructure designed to simplify mobile and web application development by offering ready-to-use APIs for data storage, user authentication, and push notifications. This framework allows developers to deploy their own servers, reducing reliance on proprietary third-party services. However, its widespread adoption has made it a frequent target for security researchers, resulting in over 110 recorded Common Vulnerabilities and Exposures (CVEs). Historically, these flaws predominantly involve remote code execution, cross-site scripting, and privilege escalation, often stemming from insufficient input validation or insecure default configurations in older versions. While the project maintains an active security response process, the sheer volume of past incidents highlights the complexity of maintaining secure, self-hosted environments. Users are strongly advised to keep installations updated and adhere to strict configuration guidelines to mitigate risks associated with these known vulnerabilities.

CVE ID Title CVSS Severity Published
CVE-2025-68115 Parse Server vulnerable to Cross-Site Scripting (XSS) via Unescaped Mustache Template Variables — parse-server CWE-79 6.1AI Medium AI 2025-12-16
CVE-2025-67727 Parse Server GitHub CI workflow vulnerable to RCE through Improper Privilege Management — parse-server CWE-94 9.8AI Critical AI 2025-12-12
CVE-2025-64502 Parse Server allows public `explain` queries which may expose sensitive database performance information and schema details — parse-server CWE-201 5.3 - 2025-11-10
CVE-2025-64430 Parse Server Vulnerable to Server-Side Request Forgery (SSRF) in File Upload via URI Format — parse-server CWE-918 7.5 High 2025-11-07
CVE-2025-62374 Parse Javascript SDK vulnerable to prototype pollution in `Parse.Object` and internal APIs — Parse-SDK-JS CWE-1321 6.4 Medium 2025-10-14
CVE-2025-53364 Parse Server exposes the data schema via GraphQL API — parse-server CWE-497 5.3 Medium 2025-07-10
CVE-2025-30168 Parse Server has an OAuth login vulnerability — parse-server CWE-287 6.9 Medium 2025-03-21
CVE-2024-47183 Parse Server's custom object ID allows to acquire role privileges — parse-server CWE-285 8.1 High 2024-10-04
CVE-2024-39309 ZDI-CAN-23894: Parse Server literalizeRegexPart SQL Injection Authentication Bypass Vulnerability — parse-server CWE-288 9.8 Critical 2024-07-01
CVE-2024-29027 Parse Server crash and RCE via invalid Cloud Function or Cloud Job name — parse-server CWE-74 9.1 Critical 2024-03-19
CVE-2024-27298 Parse Server literalizeRegexPart SQL Injection — parse-server CWE-89 10.0 Critical 2024-03-01
CVE-2023-46119 Parse Server may crash when uploading file without extension — parse-server CWE-23 7.5 High 2023-10-25
CVE-2023-41058 Trigger `beforeFind` not invoked in internal query pipeline in parse-server — parse-server CWE-670 7.5 High 2023-09-04
CVE-2023-36475 Parse Server vulnerable to remote code execution via MongoDB BSON parser through prototype pollution — parse-server CWE-1321 9.8 Critical 2023-06-28
CVE-2023-32689 Parse Server vulnerable to phishing attack vulnerability that involves uploading malicious HTML file — parse-server CWE-434 6.3 Medium 2023-05-30
CVE-2023-32688 Invalid push request payload crashes Parse Server — parse-server-push-adapter CWE-20 4.9 Medium 2023-05-27
CVE-2023-22474 Parse Server is vulnerable to authentication bypass via spoofing — parse-server CWE-290 8.7 High 2023-02-03
CVE-2022-39396 Parse Server vulnerable to Remote Code Execution via prototype pollution in MongoDB BSON parser — parse-server CWE-1321 9.8 Critical 2022-11-10
CVE-2022-41878 Parse Server Prototype pollution and Injection via Cloud Code Webhooks or Cloud Code Triggers — parse-server CWE-74 7.2 High 2022-11-10
CVE-2022-41879 Parse Server subject to Prototype pollution via Cloud Code Webhooks — parse-server CWE-1321 7.2 High 2022-11-10
CVE-2022-39313 Parse Server crashes when receiving file download request with invalid byte range — parse-server CWE-1284 7.5 High 2022-10-24
CVE-2022-39231 Parse Server subject to Improper Authentication allowing Auth adapter app ID validation to be circumvented — parse-server CWE-287 3.7 Low 2022-09-23
CVE-2022-39225 Parse Server subject to Incorrect Resource Transfer Between Spheres — parse-server CWE-669 4.3 Medium 2022-09-23
CVE-2022-36079 Parse Server vulnerable to brute force guessing of user sensitive data via search patterns — parse-server CWE-200 8.6 High 2022-09-07
CVE-2022-31112 Protected fields exposed via LiveQuery in parse-server — parse-server CWE-200 8.2 High 2022-06-30
CVE-2022-31089 Invalid file request can crashe parse-server — parse-server CWE-706 7.5 High 2022-06-27
CVE-2022-31083 Authentication bypass in Parse Server Apple Game Center auth adapter — parse-server CWE-287 8.6 High 2022-06-17
CVE-2022-24901 Authentication bypass and denial of service (DoS) vulnerabilities in Apple Game Center auth adapter — parse-server CWE-295 7.5 High 2022-05-04
CVE-2022-24760 Command Injection in Parse server — parse-server CWE-74 10.0 Critical 2022-03-11
CVE-2021-41109 LiveQuery publishes user session tokens — parse-server CWE-200 7.5 High 2021-09-30

This page lists every published CVE security advisory associated with parse-community. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.