Parse-Server
Parse-Community · 124 CVEs
Parse Server 9.0.0 Authentication Bypass via Unverified Provider Identity
Sep 27, 2026
Parse Server 9.0.0 before 9.10.1 Protected Fields Disclosure via LiveQuery
Sep 26, 2026
Parse Server 9.0.0 Unauthenticated Installation Deletion via Operator Injection
Sep 26, 2026
Parse Server 9.0.0 Authentication Bypass via LDAP Empty Password
Sep 9, 2026
Parse Server 9.0.0 Information Disclosure via GraphQL Error Messages
Jul 24, 2026
Parse Server 9.0.0 Information Disclosure via GraphQL Error Messages
Jul 24, 2026
Parse Server 9.0.0 Schema Disclosure via GraphQL Variable Coercion
Jul 21, 2026
Parse Server 9.0.0 Stored XSS via malformed Content-Type
Jul 11, 2026
Parse Server: LiveQuery discloses object data to a subscriber across an ACL read-access change
Jul 8, 2026
Parse Server: Denial of service via exponential-time processing of deeply nested query operators
Jul 8, 2026
Parse Server: Stored XSS via non-standard file extension bypassing file upload extension blocklist
Jul 8, 2026
Parse Server - Arbitrary Code Execution via Malicious Version Tags
Jun 25, 2026
Parse Server - Unreviewed Code Execution via Malicious Version Tags
Jun 25, 2026
Parse Server: Relation `$relatedTo` query bypasses `protectedFields` and owning-object ACL
Jun 12, 2026
Parse Server: Endpoints `/login` and `/verifyPassword` disclose MFA secrets and protected fields when `_User` get is de…
Jun 12, 2026
Parse Server: Stored XSS via trailing-dot filename bypassing file upload extension blocklist
Jun 12, 2026
Parse Server: Server option routeAllowList is bypassable through batch sub-requests
Jun 12, 2026
Parse Server: Pre-authentication denial of service via client version header regex backtracking
Jun 12, 2026
Parse Server: GraphQL "Did you mean" validation suggestions disclose schema to unauthenticated callers
Jun 12, 2026
Parse Server: MFA SMS one-time password accepted twice under concurrent login
May 12, 2026
Parse Server's Endpoint `/sessions/me` bypasses `_Session` `protectedFields`
Apr 7, 2026
Parse Server has a login timing side-channel reveals user existence
Apr 7, 2026
Parse Server has a file upload Content-Type override via extension mismatch
Apr 6, 2026
Parse Server: Streaming file download bypasses afterFind file trigger authorization
Mar 31, 2026
Parse Server: Auth data exposed via verify password endpoint
Mar 31, 2026
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-101042 | Parse Server 9.0.0 Authentication Bypass via Unverified Provider Identity | HIGH | 0.21% | Sep 27, 2026 |
| CVE-2026-100632 | Parse Server 9.0.0 before 9.10.1 Protected Fields Disclosure via LiveQuery | HIGH | 0.29% | Sep 26, 2026 |
| CVE-2026-100631 | Parse Server 9.0.0 Unauthenticated Installation Deletion via Operator Injection | HIGH | 0.36% | Sep 26, 2026 |
| CVE-2026-87806 | Parse Server 9.0.0 Authentication Bypass via LDAP Empty Password | CRITICAL | 0.51% | Sep 9, 2026 |
| CVE-2026-66009 | Parse Server 9.0.0 Information Disclosure via GraphQL Error Messages | MEDIUM | 0.45% | Jul 24, 2026 |
| CVE-2026-66008 | Parse Server 9.0.0 Information Disclosure via GraphQL Error Messages | MEDIUM | 0.56% | Jul 24, 2026 |
| CVE-2026-64627 | Parse Server 9.0.0 Schema Disclosure via GraphQL Variable Coercion | MEDIUM | 0.47% | Jul 21, 2026 |
| CVE-2026-61448 | Parse Server 9.0.0 Stored XSS via malformed Content-Type | LOW | 0.41% | Jul 11, 2026 |
| CVE-2026-57481 | Parse Server: LiveQuery discloses object data to a subscriber across an ACL read-access change | LOW | 0.53% | Jul 8, 2026 |
| CVE-2026-57480 | Parse Server: Denial of service via exponential-time processing of deeply nested query operators | HIGH | 0.59% | Jul 8, 2026 |
| CVE-2026-55778 | Parse Server: Stored XSS via non-standard file extension bypassing file upload extension blocklist | LOW | 0.55% | Jul 8, 2026 |
| CVE-2021-47987 | Parse Server - Arbitrary Code Execution via Malicious Version Tags | HIGH | 0.18% | Jun 25, 2026 |
| CVE-2021-47986 | Parse Server - Unreviewed Code Execution via Malicious Version Tags | HIGH | 0.18% | Jun 25, 2026 |
| CVE-2026-53726 | Parse Server: Relation `$relatedTo` query bypasses `protectedFields` and owning-object ACL | MEDIUM | 0.48% | Jun 12, 2026 |
| CVE-2026-53725 | Parse Server: Endpoints `/login` and `/verifyPassword` disclose MFA secrets and protected fields when `_User` get is denied | MEDIUM | 0.43% | Jun 12, 2026 |
| CVE-2026-53724 | Parse Server: Stored XSS via trailing-dot filename bypassing file upload extension blocklist | LOW | 0.49% | Jun 12, 2026 |
| CVE-2026-50008 | Parse Server: Server option routeAllowList is bypassable through batch sub-requests | MEDIUM | 0.60% | Jun 12, 2026 |
| CVE-2026-47138 | Parse Server: Pre-authentication denial of service via client version header regex backtracking | HIGH | 0.91% | Jun 12, 2026 |
| CVE-2026-47248 | Parse Server: GraphQL "Did you mean" validation suggestions disclose schema to unauthenticated callers | MEDIUM | 0.51% | Jun 12, 2026 |
| CVE-2026-43930 | Parse Server: MFA SMS one-time password accepted twice under concurrent login | LOW | 0.30% | May 12, 2026 |
| CVE-2026-39381 | Parse Server's Endpoint `/sessions/me` bypasses `_Session` `protectedFields` | MEDIUM | 0.32% | Apr 7, 2026 |
| CVE-2026-39321 | Parse Server has a login timing side-channel reveals user existence | MEDIUM | 0.37% | Apr 7, 2026 |
| CVE-2026-35200 | Parse Server has a file upload Content-Type override via extension mismatch | LOW | 0.28% | Apr 6, 2026 |
| CVE-2026-34784 | Parse Server: Streaming file download bypasses afterFind file trigger authorization | HIGH | 0.47% | Mar 31, 2026 |
| CVE-2026-34215 | Parse Server: Auth data exposed via verify password endpoint | HIGH | 0.53% | Mar 31, 2026 |
Showing 1 to 25 of 124 CVEs