Parse-Server
Parseplatform · 102 CVEs
Parse Server OAuth2 authentication adapter account takeover via identity spoofing
Mar 10, 2026
Parse Server role escalation and CLP bypass via direct `_Join` table write
Mar 10, 2026
Parse Server session token exfiltration via `redirectClassNameForKey` query parameter
Mar 10, 2026
Parse Server has a protected fields bypass via logical query operators
Mar 10, 2026
Parse Server is missing audience validation in Keycloak authentication adapter
Mar 10, 2026
Parse Server has stored cross-site scripting (XSS) via SVG file upload
Mar 10, 2026
Parse Server ha a bypass of class-level permissions in LiveQuery
Mar 10, 2026
Parse Server affected by denial-of-service via unbounded query complexity in REST and GraphQL API
Mar 10, 2026
Parse Server has a NoSQL injection via token type in password reset and email verification endpoints
Mar 10, 2026
Parse Server has Denial of Service (DoS) and Cloud Function Dispatch Bypass via Prototype Chain Resolution
Mar 10, 2026
Parse Server has denylist `requestKeywordDenylist` keyword scan bypass through nested object placement
Mar 10, 2026
Parse Server affected by Regular Expression Denial of Service (ReDoS) via `$regex` query in LiveQuery
Mar 9, 2026
Parse Server: GraphQL `__type` introspection bypass via inline fragments when public introspection is disabled
Mar 7, 2026
Parse Server: File metadata endpoint bypasses `beforeFind` / `afterFind` trigger authorization
Mar 7, 2026
Parse Server: `PagesRouter` path traversal allows reading files outside configured pages directory
Mar 7, 2026
Parse Server: JWT audience validation bypass in Google, Apple, and Facebook authentication adapters
Mar 7, 2026
Parse Server: Malformed `$regex` query leaks database error details in API response
Mar 6, 2026
Parse Server: Endpoint `/loginAs` allows `readOnlyMasterKey` to gain full read and write access as any user
Mar 6, 2026
Parse Server: File creation and deletion bypasses `readOnlyMasterKey` write restriction
Mar 6, 2026
Parse Server: Cloud Hooks and Cloud Jobs bypass `readOnlyMasterKey` write restriction
Mar 6, 2026
Parse Server: Account takeover via JWT algorithm confusion in Google auth adapter
Feb 25, 2026
Parse Server has Server-Side Request Forgery (SSRF) in Instagram OAuth Adapter
Dec 16, 2025
Parse Server vulnerable to Cross-Site Scripting (XSS) via Unescaped Mustache Template Variables
Dec 16, 2025
Parse Server GitHub CI workflow vulnerable to RCE through Improper Privilege Management
Dec 12, 2025
Parse Server's custom object ID allows to acquire role privileges
Oct 4, 2024
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-30967 | Parse Server OAuth2 authentication adapter account takeover via identity spoofing | HIGH | 0.64% | Mar 10, 2026 |
| CVE-2026-30966 | Parse Server role escalation and CLP bypass via direct `_Join` table write | CRITICAL | 0.52% | Mar 10, 2026 |
| CVE-2026-30965 | Parse Server session token exfiltration via `redirectClassNameForKey` query parameter | CRITICAL | 1.55% | Mar 10, 2026 |
| CVE-2026-30962 | Parse Server has a protected fields bypass via logical query operators | HIGH | 0.40% | Mar 10, 2026 |
| CVE-2026-30949 | Parse Server is missing audience validation in Keycloak authentication adapter | HIGH | 0.64% | Mar 10, 2026 |
| CVE-2026-30948 | Parse Server has stored cross-site scripting (XSS) via SVG file upload | HIGH | 0.29% | Mar 10, 2026 |
| CVE-2026-30947 | Parse Server ha a bypass of class-level permissions in LiveQuery | HIGH | 0.47% | Mar 10, 2026 |
| CVE-2026-30946 | Parse Server affected by denial-of-service via unbounded query complexity in REST and GraphQL API | HIGH | 0.64% | Mar 10, 2026 |
| CVE-2026-30941 | Parse Server has a NoSQL injection via token type in password reset and email verification endpoints | HIGH | 0.47% | Mar 10, 2026 |
| CVE-2026-30939 | Parse Server has Denial of Service (DoS) and Cloud Function Dispatch Bypass via Prototype Chain Resolution | HIGH | 0.68% | Mar 10, 2026 |
| CVE-2026-30938 | Parse Server has denylist `requestKeywordDenylist` keyword scan bypass through nested object placement | MEDIUM | 0.41% | Mar 10, 2026 |
| CVE-2026-30925 | Parse Server affected by Regular Expression Denial of Service (ReDoS) via `$regex` query in LiveQuery | HIGH | 0.61% | Mar 9, 2026 |
| CVE-2026-30854 | Parse Server: GraphQL `__type` introspection bypass via inline fragments when public introspection is disabled | MEDIUM | 0.35% | Mar 7, 2026 |
| CVE-2026-30850 | Parse Server: File metadata endpoint bypasses `beforeFind` / `afterFind` trigger authorization | MEDIUM | 0.35% | Mar 7, 2026 |
| CVE-2026-30848 | Parse Server: `PagesRouter` path traversal allows reading files outside configured pages directory | MEDIUM | 0.35% | Mar 7, 2026 |
| CVE-2026-30863 | Parse Server: JWT audience validation bypass in Google, Apple, and Facebook authentication adapters | CRITICAL | 0.71% | Mar 7, 2026 |
| CVE-2026-30835 | Parse Server: Malformed `$regex` query leaks database error details in API response | MEDIUM | 0.42% | Mar 6, 2026 |
| CVE-2026-30229 | Parse Server: Endpoint `/loginAs` allows `readOnlyMasterKey` to gain full read and write access as any user | HIGH | 0.58% | Mar 6, 2026 |
| CVE-2026-30228 | Parse Server: File creation and deletion bypasses `readOnlyMasterKey` write restriction | MEDIUM | 0.45% | Mar 6, 2026 |
| CVE-2026-29182 | Parse Server: Cloud Hooks and Cloud Jobs bypass `readOnlyMasterKey` write restriction | HIGH | 0.58% | Mar 6, 2026 |
| CVE-2026-27804 | Parse Server: Account takeover via JWT algorithm confusion in Google auth adapter | CRITICAL | 0.23% | Feb 25, 2026 |
| CVE-2025-68150 | Parse Server has Server-Side Request Forgery (SSRF) in Instagram OAuth Adapter | HIGH | 0.33% | Dec 16, 2025 |
| CVE-2025-68115 | Parse Server vulnerable to Cross-Site Scripting (XSS) via Unescaped Mustache Template Variables | MEDIUM | 0.22% | Dec 16, 2025 |
| CVE-2025-67727 | Parse Server GitHub CI workflow vulnerable to RCE through Improper Privilege Management | MEDIUM | 0.42% | Dec 12, 2025 |
| CVE-2024-47183 | Parse Server's custom object ID allows to acquire role privileges | HIGH | 0.42% | Oct 4, 2024 |
Showing 51 to 75 of 102 CVEs