cbcvebase.

Parse-Community Parse-Server vulnerabilities

123 known vulnerabilities affecting parse-community/parse-server.

Total CVEs
123
CISA KEV
0
Public exploits
2
Exploited in wild
1
Severity breakdown
CRITICAL20HIGH45MEDIUM48LOW10

Vulnerabilities

Page 7 of 7
CVE-2026-32943P4LOWCVSS 3.1v>= 9.0.0, < 9.6.0-alpha.28fixed in 8.6.482026-03-18
CVE-2026-32943 [LOW] CWE-367 CVE-2026-32943: Parse Server is an open source backend that can be deployed to any infrastructure that can run Node. Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.28 and 8.6.48, the password reset mechanism does not enforce single-use guarantees for reset tokens. When a user requests a password reset, the generated token can be consumed by multiple concurrent requests within a short time w
ghsanvdosv
CVE-2026-33624P4LOWCVSS 2.7fixed in 8.6.60v>= 9.0.0, < 9.6.0-alpha.542026-03-24
CVE-2026-33624 [LOW] CWE-367 CVE-2026-33624: Parse Server is an open source backend that can be deployed to any infrastructure that can run Node. Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.60 and 9.6.0-alpha.54, an attacker who obtains a user's password and a single MFA recovery code can reuse that recovery code an unlimited number of times by sending concurrent login requests. This defeats the single-use design o
ghsanvdosv
CVE-2022-39225P4LOWCVSS 3.1fixed in 4.10.15v>= 5.0.0, < 5.2.62022-09-23
CVE-2022-39225 [LOW] CWE-669 CVE-2022-39225: Parse Server is an open source backend that can be deployed to any infrastructure that can run Node. Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions prior to 4.10.15, or 5.0.0 and above prior to 5.2.6, a user can write to the session object of another user if the session object ID is known. For example, an attacker can assign the session object to their own user by writing to the `use
ghsanvdosv
Parse-Community Parse-Server vulnerabilities | cvebase