Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

parse-community — Vulnerabilities & Security Advisories 126

Browse all 126 CVE security advisories affecting parse-community. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Parse Community provides an open-source backend infrastructure designed to simplify mobile and web application development by offering ready-to-use APIs for data storage, user authentication, and push notifications. This framework allows developers to deploy their own servers, reducing reliance on proprietary third-party services. However, its widespread adoption has made it a frequent target for security researchers, resulting in over 110 recorded Common Vulnerabilities and Exposures (CVEs). Historically, these flaws predominantly involve remote code execution, cross-site scripting, and privilege escalation, often stemming from insufficient input validation or insecure default configurations in older versions. While the project maintains an active security response process, the sheer volume of past incidents highlights the complexity of maintaining secure, self-hosted environments. Users are strongly advised to keep installations updated and adhere to strict configuration guidelines to mitigate risks associated with these known vulnerabilities.

Found 120 results / 126 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2026-66009 Parse Server 9.0.0 Information Disclosure via GraphQL Error Messages — parse-server CWE-209 6.3 Medium 2026-07-24
CVE-2026-66008 Parse Server 9.0.0 Information Disclosure via GraphQL Error Messages — parse-server CWE-209 6.3 Medium 2026-07-24
CVE-2026-64627 Parse Server 9.0.0 Schema Disclosure via GraphQL Variable Coercion — parse-server CWE-209 6.9 Medium 2026-07-21
CVE-2026-61448 Parse Server 9.0.0 Stored XSS via malformed Content-Type — parse-server CWE-434 - - 2026-07-11
CVE-2026-57481 Parse Server: LiveQuery discloses object data to a subscriber across an ACL read-access change — parse-server CWE-200 - - 2026-07-08
CVE-2026-57480 Parse Server: Denial of service via exponential-time processing of deeply nested query operators — parse-server CWE-407 - - 2026-07-08
CVE-2026-55778 Parse Server: Stored XSS via non-standard file extension bypassing file upload extension blocklist — parse-server CWE-434 - - 2026-07-08
CVE-2021-47987 Parse Server - Arbitrary Code Execution via Malicious Version Tags — parse-server CWE-494 7.5 High 2026-06-25
CVE-2021-47986 Parse Server - Unreviewed Code Execution via Malicious Version Tags — parse-server CWE-494 7.5 High 2026-06-25
CVE-2026-53726 Parse Server: Relation `$relatedTo` query bypasses `protectedFields` and owning-object ACL — parse-server CWE-639 - - 2026-06-12
CVE-2026-53725 Parse Server: Endpoints `/login` and `/verifyPassword` disclose MFA secrets and protected fields when `_User` get is denied — parse-server CWE-200 - - 2026-06-12
CVE-2026-53724 Parse Server: Stored XSS via trailing-dot filename bypassing file upload extension blocklist — parse-server CWE-434 - - 2026-06-12
CVE-2026-50008 Parse Server: Server option routeAllowList is bypassable through batch sub-requests — parse-server CWE-863 - - 2026-06-12
CVE-2026-47138 Parse Server: Pre-authentication denial of service via client version header regex backtracking — parse-server CWE-1333 - - 2026-06-12
CVE-2026-47248 Parse Server: GraphQL "Did you mean" validation suggestions disclose schema to unauthenticated callers — parse-server CWE-209 - - 2026-06-12
CVE-2026-43930 Parse Server: MFA SMS one-time password accepted twice under concurrent login — parse-server CWE-362 - - 2026-05-12
CVE-2026-39381 Parse Server's Endpoint `/sessions/me` bypasses `_Session` `protectedFields` — parse-server CWE-863 6.5AI Medium AI 2026-04-07
CVE-2026-39321 Parse Server has a login timing side-channel reveals user existence — parse-server CWE-208 4.8AI Medium AI 2026-04-07
CVE-2026-35200 Parse Server has a file upload Content-Type override via extension mismatch — parse-server CWE-436 8.2AI High AI 2026-04-06
CVE-2026-34784 Parse Server: Streaming file download bypasses afterFind file trigger authorization — parse-server CWE-285 7.5 - 2026-03-31
CVE-2026-34215 Parse Server: Auth data exposed via verify password endpoint — parse-server CWE-200 6.5 - 2026-03-31
CVE-2026-34595 Parse Server: LiveQuery protected-field guard bypass via array-like logical operator value — parse-server CWE-843 8.8AI High AI 2026-03-31
CVE-2026-34574 Parse Server: Session field immutability bypass via falsy-value guard — parse-server CWE-697 7.1AI High AI 2026-03-31
CVE-2026-34573 Parse Server: GraphQL complexity validator exponential fragment traversal DoS — parse-server CWE-407 7.5AI High AI 2026-03-31
CVE-2026-34532 Parse Server: Cloud function validator bypass via prototype chain traversal — parse-server CWE-863 9.1AI Critical AI 2026-03-31
CVE-2026-34373 Parse Server: GraphQL API endpoint ignores CORS origin restriction — parse-server CWE-346 8.2AI High AI 2026-03-31
CVE-2026-34363 Parse Server: LiveQuery protected field leak via shared mutable state across concurrent subscribers — parse-server CWE-362 7.5AI High AI 2026-03-31
CVE-2026-34224 Parse Server: MFA single-use token bypass via concurrent authData login requests — parse-server CWE-367 8.2AI High AI 2026-03-31
CVE-2026-33627 Parse Server: Auth data exposed via /users/me endpoint — parse-server CWE-200 8.1 - 2026-03-24
CVE-2026-33624 Parse Server: MFA recovery code single-use bypass via concurrent requests — parse-server CWE-367 9.1 - 2026-03-24

This page lists every published CVE security advisory associated with parse-community. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.