Parse-Server
Parseplatform · 102 CVEs
Parse Server leaks protected fields via LiveQuery afterEvent trigger
Mar 18, 2026
Parse Server affected by empty authData bypassing credential requirement on signup
Mar 18, 2026
Parse Server crash via deeply nested query condition operators
Mar 18, 2026
Parse Server has a password reset token single-use bypass via concurrent requests
Mar 18, 2026
Parse Server's Cloud function dispatch crashes server via prototype chain traversal
Mar 18, 2026
Parse Server vulnerable to schema poisoning via prototype pollution in deep copy
Mar 18, 2026
Parse Server: LiveQuery subscription with invalid regular expression crashes server
Mar 18, 2026
Parse Server session creation endpoint allows overwriting server-generated session fields
Mar 18, 2026
Parse Server has a stored XSS filter bypass via Content-Type MIME parameter and missing XML extension blocklist entries
Mar 18, 2026
Parse Server GraphQL WebSocket endpoint bypasses security middleware
Mar 13, 2026
Parse Server OAuth2 adapter app ID validation sends wrong token to introspection endpoint
Mar 12, 2026
Parse Server: Account takeover via operator injection in authentication data identifier
Mar 12, 2026
Parse Server OAuth2 adapter shares mutable state across providers via singleton instance
Mar 12, 2026
Parse Server has a SQL injection via query field name when using PostgreSQL
Mar 11, 2026
Parse Server has a protected fields bypass via LiveQuery subscription WHERE clause
Mar 11, 2026
Parse Server has user enumeration via email verification endpoint
Mar 11, 2026
Parse Server MFA recovery codes not consumed after use
Mar 11, 2026
Parse Server has a protected fields bypass via dot-notation in query and sort
Mar 11, 2026
Parse Server has a SQL Injection via dot-notation sub-key name in `Increment` operation on PostgreSQL
Mar 11, 2026
Parse Server has Stored XSS via file upload of HTML-renderable file types
Mar 11, 2026
Parse Server has a SQL injection via `Increment` operation on nested object field in PostgreSQL
Mar 11, 2026
Parse Server has a SQL injection via dot-notation field name in PostgreSQL
Mar 11, 2026
Parse Server has an LDAP injection via unsanitized user input in DN and group filter construction
Mar 10, 2026
Parse Server: Classes `_GraphQLConfig` and `_Audience` master key bypass via generic class routes
Mar 10, 2026
Parse Server has a rate limit bypass via batch request endpoint
Mar 10, 2026
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-33163 | Parse Server leaks protected fields via LiveQuery afterEvent trigger | HIGH | 0.50% | Mar 18, 2026 |
| CVE-2026-33042 | Parse Server affected by empty authData bypassing credential requirement on signup | MEDIUM | 0.37% | Mar 18, 2026 |
| CVE-2026-32944 | Parse Server crash via deeply nested query condition operators | HIGH | 0.61% | Mar 18, 2026 |
| CVE-2026-32943 | Parse Server has a password reset token single-use bypass via concurrent requests | LOW | 0.24% | Mar 18, 2026 |
| CVE-2026-32886 | Parse Server's Cloud function dispatch crashes server via prototype chain traversal | HIGH | 0.67% | Mar 18, 2026 |
| CVE-2026-32878 | Parse Server vulnerable to schema poisoning via prototype pollution in deep copy | MEDIUM | 0.47% | Mar 18, 2026 |
| CVE-2026-32770 | Parse Server: LiveQuery subscription with invalid regular expression crashes server | HIGH | 0.71% | Mar 18, 2026 |
| CVE-2026-32742 | Parse Server session creation endpoint allows overwriting server-generated session fields | MEDIUM | 0.39% | Mar 18, 2026 |
| CVE-2026-32728 | Parse Server has a stored XSS filter bypass via Content-Type MIME parameter and missing XML extension blocklist entries | HIGH | 0.36% | Mar 18, 2026 |
| CVE-2026-32594 | Parse Server GraphQL WebSocket endpoint bypasses security middleware | MEDIUM | 0.47% | Mar 13, 2026 |
| CVE-2026-32269 | Parse Server OAuth2 adapter app ID validation sends wrong token to introspection endpoint | MEDIUM | 0.40% | Mar 12, 2026 |
| CVE-2026-32248 | Parse Server: Account takeover via operator injection in authentication data identifier | CRITICAL | 0.92% | Mar 12, 2026 |
| CVE-2026-32242 | Parse Server OAuth2 adapter shares mutable state across providers via singleton instance | CRITICAL | 0.38% | Mar 12, 2026 |
| CVE-2026-32234 | Parse Server has a SQL injection via query field name when using PostgreSQL | MEDIUM | 0.33% | Mar 11, 2026 |
| CVE-2026-32098 | Parse Server has a protected fields bypass via LiveQuery subscription WHERE clause | MEDIUM | 0.49% | Mar 11, 2026 |
| CVE-2026-31901 | Parse Server has user enumeration via email verification endpoint | MEDIUM | 0.40% | Mar 11, 2026 |
| CVE-2026-31875 | Parse Server MFA recovery codes not consumed after use | HIGH | 0.52% | Mar 11, 2026 |
| CVE-2026-31872 | Parse Server has a protected fields bypass via dot-notation in query and sort | HIGH | 0.47% | Mar 11, 2026 |
| CVE-2026-31871 | Parse Server has a SQL Injection via dot-notation sub-key name in `Increment` operation on PostgreSQL | CRITICAL | 0.54% | Mar 11, 2026 |
| CVE-2026-31868 | Parse Server has Stored XSS via file upload of HTML-renderable file types | MEDIUM | 0.33% | Mar 11, 2026 |
| CVE-2026-31856 | Parse Server has a SQL injection via `Increment` operation on nested object field in PostgreSQL | CRITICAL | 0.54% | Mar 11, 2026 |
| CVE-2026-31840 | Parse Server has a SQL injection via dot-notation field name in PostgreSQL | CRITICAL | 0.70% | Mar 11, 2026 |
| CVE-2026-31828 | Parse Server has an LDAP injection via unsanitized user input in DN and group filter construction | MEDIUM | 0.76% | Mar 10, 2026 |
| CVE-2026-31800 | Parse Server: Classes `_GraphQLConfig` and `_Audience` master key bypass via generic class routes | HIGH | 0.59% | Mar 10, 2026 |
| CVE-2026-30972 | Parse Server has a rate limit bypass via batch request endpoint | MEDIUM | 0.61% | Mar 10, 2026 |
Showing 26 to 50 of 102 CVEs