cbcvebase.

Parse-Community Parse-Server vulnerabilities

123 known vulnerabilities affecting parse-community/parse-server.

Total CVEs
123
CISA KEV
0
Public exploits
2
Exploited in wild
1
Severity breakdown
CRITICAL20HIGH45MEDIUM48LOW10

Vulnerabilities

Page 5 of 7
CVE-2026-33163P3MEDIUMCVSS 6.5v>= 9.0.0, < 9.6.0-alpha.35fixed in 8.6.502026-03-18
CVE-2026-33163 [MEDIUM] CWE-200 CVE-2026-33163: Parse Server is an open source backend that can be deployed to any infrastructure that can run Node. Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.35 and 8.6.50, when a `Parse.Cloud.afterLiveQueryEvent` trigger is registered for a class, the LiveQuery server leaks protected fields and `authData` to all subscribers of that class. Fields configured as protected via Class-L
ghsanvdosv
CVE-2023-46119P3HIGHCVSS 7.5v>= 1.0.0, < 5.5.6v>= 6.0.0, < 6.3.12023-10-25
CVE-2023-46119 [HIGH] CWE-23 CVE-2023-46119: Parse Server is an open source backend that can be deployed to any infrastructure that can run Node. Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Parse Server crashes when uploading a file without extension. This vulnerability has been patched in versions 5.5.6 and 6.3.1.
ghsanvdosv
CVE-2025-30168P3MEDIUMCVSS 6.9fixed in 7.5.2v>= 8.0.0 ,< 8.0.22025-03-21
CVE-2025-30168 [MEDIUM] CWE-287 CVE-2025-30168: Parse Server is an open source backend that can be deployed to any infrastructure that can run Node. Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 7.5.2 and 8.0.2, the 3rd party authentication handling of Parse Server allows the authentication credentials of some specific authentication providers to be used across multiple Parse Server apps. For example, if a user signed up using th
ghsanvdosv
CVE-2021-39138P3MEDIUMCVSS 6.5fixed in 4.5.12021-08-19
CVE-2021-39138 [MEDIUM] CWE-287 CVE-2021-39138: Parse Server is an open source backend that can be deployed to any infrastructure that can run Node. Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Developers can use the REST API to signup users and also allow users to login anonymously. Prior to version 4.5.1, when an anonymous user is first signed up using REST, the server creates session incorrectly. Particularly, the `authProvider` field
ghsanvdosv
CVE-2023-32689P3MEDIUMCVSS 6.5fixed in 5.4.4v>= 6.0.0, < 6.1.12023-05-30
CVE-2023-32689 [MEDIUM] CWE-434 CVE-2023-32689: Parse Server is an open source backend that can be deployed to any infrastructure that can run Node. Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Versions prior to 5.4.4 and 6.1.1 are vulnerable to a phishing attack vulnerability that involves a user uploading malicious files. A malicious user could upload an HTML file to Parse Server via its public API. That HTML file would then be accessi
ghsanvdosv
CVE-2020-26288P3MEDIUMCVSS 6.5fixed in 4.5.02020-12-30
CVE-2020-26288 [MEDIUM] CWE-312 CVE-2020-26288: Parse Server is an open source backend that can be deployed to any infrastructure that can run Node. Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. It is an npm package "parse-server". In Parse Server before version 4.5.0, user passwords involved in LDAP authentication are stored in cleartext. This is fixed in version 4.5.0 by stripping password after authentication to prevent cleartext passw
ghsanvdosv
CVE-2026-31875P3MEDIUMCVSS 5.9v>= 9.0.0 < 9.6.0-alpha.7fixed in 8.6.332026-03-11
CVE-2026-31875 [MEDIUM] CWE-672 CVE-2026-31875: Parse Server is an open source backend that can be deployed to any infrastructure that can run Node. Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.7 and 8.6.33, when multi-factor authentication (MFA) via TOTP is enabled for a user account, Parse Server generates two single-use recovery codes. These codes are intended as a fallback when the user cannot provide a TOTP toke
ghsanvdosv
CVE-2026-30850P3MEDIUMCVSS 5.9fixed in 8.6.9fixed in 9.5.0-alpha.92026-03-07
CVE-2026-30850 [MEDIUM] CWE-862 CVE-2026-30850: Parse Server is an open source backend that can be deployed to any infrastructure that can run Node. Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.9 and 9.5.0-alpha.9, the file metadata endpoint (GET /files/:appId/metadata/:filename) does not enforce beforeFind / afterFind file triggers. When these triggers are used as access-control gates, the metadata endpoint bypasse
ghsanvdosv
CVE-2026-53725P3MEDIUMCVSS 5.9v>= 9.8.0, < 9.9.1-alpha.52026-06-12
CVE-2026-53725 [MEDIUM] CWE-200 CVE-2026-53725: Parse Server is an open source backend that can be deployed to any infrastructure that can run Node. Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. From version 9.8.0 to before version 9.9.1-alpha.5, apps that enable MFA and deny get on the _User class via Class-Level Permissions could expose sensitive user data through the /login and /verifyPassword endpoints. These endpoints re-fetch the us
ghsanvd
CVE-2026-43930P3MEDIUMCVSS 5.9v>= 9.0.0, < 9.9.0-alpha.2fixed in 8.6.762026-05-12
CVE-2026-43930 [MEDIUM] CWE-362 CVE-2026-43930: Parse Server is an open source backend that can be deployed to any infrastructure that can run Node. Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.76 and 9.9.0-alpha.2, a race condition in the MFA SMS one-time password (OTP) login path allows two concurrent /login requests carrying the same OTP to both succeed and both receive valid session tokens, breaking the single-use proper
nvd
CVE-2026-30228P4MEDIUMCVSS 4.9fixed in 8.6.5fixed in 9.5.0-alpha.32026-03-06
CVE-2026-30228 [MEDIUM] CWE-863 CVE-2026-30228: Parse Server is an open source backend that can be deployed to any infrastructure that can run Node. Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.5 and 9.5.0-alpha.3, the readOnlyMasterKey can be used to create and delete files via the Files API (POST /files/:filename, DELETE /files/:filename). This bypasses the read-only restriction which violates the access scope of
ghsanvdosv
CVE-2026-34574P4MEDIUMCVSS 5.4fixed in 8.6.69v>= 9.0.0, < 9.7.0-alpha.142026-03-31
CVE-2026-34574 [MEDIUM] CWE-697 CVE-2026-34574: Parse Server is an open source backend that can be deployed to any infrastructure that can run Node. Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.69 and 9.7.0-alpha.14, an authenticated user can bypass the immutability guard on session fields (expiresAt, createdWith) by sending a null value in a PUT request to the session update endpoint. This allows nullifying the ses
ghsanvdosv
CVE-2026-33323P4MEDIUMCVSS 5.3fixed in 8.6.51v>= 9.0.0, < 9.6.0-alpha.402026-03-24
CVE-2026-33323 [MEDIUM] CWE-204 CVE-2026-33323: Parse Server is an open source backend that can be deployed to any infrastructure that can run Node. Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.51 and 9.6.0-alpha.40, the Pages route and legacy PublicAPI route for resending email verification links return distinguishable responses depending on whether the provided username exists and has an unverified email. This all
ghsanvdosv
CVE-2026-30938P4MEDIUMCVSS 5.3fixed in 8.6.12v>= 9.0.0 < 9.5.1-alpha.12026-03-10
CVE-2026-30938 [MEDIUM] CWE-693 CVE-2026-30938: Parse Server is an open source backend that can be deployed to any infrastructure that can run Node. Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.12 and 9.5.1-alpha.1, the requestKeywordDenylist security control can be bypassed by placing any nested object or array before a prohibited keyword in the request payload. This is caused by a logic bug that stops scanning sibling keys
ghsanvdosv
CVE-2026-34363P4MEDIUMCVSS 5.3fixed in 8.6.65v>= 9.0.0, < 9.7.0-alpha.92026-03-31
CVE-2026-34363 [MEDIUM] CWE-362 CVE-2026-34363: Parse Server is an open source backend that can be deployed to any infrastructure that can run Node. Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.65 and 9.7.0-alpha.9, when multiple clients subscribe to the same class via LiveQuery, the event handlers process each subscriber concurrently using shared mutable objects. The sensitive data filter modifies these shared obje
ghsanvdosv
CVE-2020-15126P4MEDIUMCVSS 6.5v>= 3.5.0, < 4.3.02020-07-22
CVE-2020-15126 [MEDIUM] CWE-863 CVE-2020-15126: In parser-server from version 3.5.0 and before 4.3.0, an authenticated user using the viewer GraphQL In parser-server from version 3.5.0 and before 4.3.0, an authenticated user using the viewer GraphQL query can by pass all read security on his User object and can also by pass all objects linked via relation or Pointer on his User object.
ghsanvdosv
CVE-2026-30854P4MEDIUMCVSS 5.3v>= 9.3.1-alpha.3, < 9.5.0-alpha.102026-03-07
CVE-2026-30854 [MEDIUM] CWE-863 CVE-2026-30854: Parse Server is an open source backend that can be deployed to any infrastructure that can run Node. Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. From version 9.3.1-alpha.3 to before version 9.5.0-alpha.10, when graphQLPublicIntrospection is disabled, __type queries nested inside inline fragments (e.g. ... on Query { __type(name:"User") { name } }) bypass the introspection control, allowing
ghsanvdosv
CVE-2026-33042P4MEDIUMCVSS 5.3v>= 9.0.0, < 9.6.0-alpha.29fixed in 8.6.492026-03-18
CVE-2026-33042 [MEDIUM] CWE-287 CVE-2026-33042: Parse Server is an open source backend that can be deployed to any infrastructure that can run Node. Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.29 and 8.6.49, a user can sign up without providing credentials by sending an empty `authData` object, bypassing the username and password requirement. This allows the creation of authenticated sessions without proper credenti
ghsanvdosv
CVE-2026-32234P4MEDIUMCVSS 4.7v>= 9.0.0 < 9.6.0-alpha.10fixed in 8.6.362026-03-11
CVE-2026-32234 [MEDIUM] CWE-89 CVE-2026-32234: Parse Server is an open source backend that can be deployed to any infrastructure that can run Node. Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.10 and 8.6.36, an attacker with access to the master key can inject malicious SQL via crafted field names used in query constraints when Parse Server is configured with PostgreSQL as the database. The field name in a $regex que
ghsanvdosv
CVE-2026-31868P4MEDIUMCVSS 6.1v>= 9.0.0 < 9.6.0-alpha.4fixed in 8.6.302026-03-11
CVE-2026-31868 [MEDIUM] CWE-79 CVE-2026-31868: Parse Server is an open source backend that can be deployed to any infrastructure that can run Node. Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.4 and 8.6.30, an attacker can upload a file with a file extension or content type that is not blocked by the default configuration of the Parse Server fileUpload.fileExtensions option. The file can contain malicious code, for e
ghsanvdosv
Parse-Community Parse-Server vulnerabilities | cvebase