Parseplatform Parse-Server vulnerabilities
102 known vulnerabilities affecting parseplatform/parse-server.
Total CVEs
102
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL19HIGH41MEDIUM36LOW6
Vulnerabilities
Page 6 of 6
CVE-2026-33624P4LOWCVSS 2.7fixed in 8.6.60≥ 9.0.0, < 9.6.0+1 more2026-03-24
CVE-2026-33624 [LOW] CWE-367 CVE-2026-33624: Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.60 and 9.6.0-alpha.54, an attacker who obtains a user's password and a single MFA recovery code can reuse that recovery code an unlimited number of times by sending concurrent login requests. This defeats the single-use design o
nvd
CVE-2022-39225P4LOWCVSS 3.1fixed in 4.10.15≥ 5.0.0, < 5.2.62022-09-23
CVE-2022-39225 [LOW] CWE-669 CVE-2022-39225: Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions prior to 4.10.15, or 5.0.0 and above prior to 5.2.6, a user can write to the session object of another user if the session object ID is known. For example, an attacker can assign the session object to their own user by writing to the `use
nvd
← Previous6 / 6