CVE-2025-68115Medium· 6.1▾ SunlitParse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions prior to 8.6.1 and 9.1.0-alpha.3, a Reflected Cross-Site Scripting (XSS) vulnerability exists in Parse Server's password …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 33.6 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions prior to 8.6.1 and 9.1.0-alpha.3, a Reflected Cross-Site Scripting (XSS) vulnerability exists in Parse Server's password reset and email verification HTML pages. The patch, available in versions 8.6.1 and 9.1.0-alpha.3, escapes user controlled values that are inserted into the HTML pages. No known workarounds are available.
parse-server < 8.6.1parse-server = 9.0.0parse-server = 9.1.0Upgrade past the affected range:
parse-server 8.6.1Connected by shared product, vendor, weakness, or advisory.
CVE-2026-53724Lowparse-server: Stored XSS via trailing-dot filename bypassing file upload extension blocklist
CVE-2025-67727Critical· 9.8Parse Server is an open source backend that can be deployed to any infrastructure that runs Node.js
CVE-2026-101042Medium· 6.4Parse Server is an open-source backend server
CVE-2026-100632Medium· 6.5Parse Server is an open-source backend server
CVE-2026-100631High· 7.5Parse Server is an open source backend server
CVE-2026-32594MediumParse Server's GraphQL WebSocket endpoint bypasses security middleware