VulnSea

parse-server vulnerabilities

CVEs whose affected-version data names the parse-server package (npm). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

15 CVEsRSS

CVE-2026-87806High· 7.4
1w ago

Parse Server versions <= 8.6.87 and >= 9.0.0 < 9.10.1-alpha.7 contain an authentication bypass in the built-in LDAP authentication adapter

Parse Server versions <= 8.6.87 and >= 9.0.0 < 9.10.1-alpha.7 contain an authentication bypass in the built-in LDAP authentication adapter. The adapter forwarded the client-supplied password to the directory without verifying that a pass…

Twilightparse-community · parse-serverEPSS 0.29%via NVD
GHSA-cgxm-vr2f-6fj8High
3mo ago

parse-server: Denial of service via exponential-time processing of deeply nested query operators

parse-server: Denial of service via exponential-time processing of deeply nested query operators

Twilightparse-server · parse-servervia GHSA
CVE-2026-50008Medium
3mo ago

parse-server: Server option routeAllowList is bypassable through batch sub-requests

parse-server: Server option routeAllowList is bypassable through batch sub-requests

Sunlitparse-server · parse-serverEPSS 0.34%via GHSA
CVE-2026-53724Low
3mo ago

parse-server: Stored XSS via trailing-dot filename bypassing file upload extension blocklist

parse-server: Stored XSS via trailing-dot filename bypassing file upload extension blocklist

Sunlitparse-server · parse-serverEPSS 0.28%via GHSA
CVE-2026-53725Medium
3mo ago

parse-server: Endpoints `/login` and `/verifyPassword` disclose MFA secrets and protected fields when `_User` get is denied

parse-server: Endpoints `/login` and `/verifyPassword` disclose MFA secrets and protected fields when `_User` get is denied

Sunlitparse-server · parse-serverEPSS 0.25%via GHSA
CVE-2026-53726Medium
3mo ago

parse-server: Relation `$relatedTo` query bypasses `protectedFields` and owning-object ACL

parse-server: Relation `$relatedTo` query bypasses `protectedFields` and owning-object ACL

Sunlitparse-server · parse-serverEPSS 0.28%via GHSA
CVE-2026-55778Low
3mo ago

parse-server: Stored XSS via non-standard file extension bypassing file upload extension blocklist

parse-server: Stored XSS via non-standard file extension bypassing file upload extension blocklist

Sunlitparse-server · parse-serverEPSS 0.55%via GHSA
GHSA-97pr-9hgg-3p8rLow
3mo ago

parse-server: LiveQuery discloses object data to a subscriber across an ACL read-access change

parse-server: LiveQuery discloses object data to a subscriber across an ACL read-access change

Sunlitparse-server · parse-servervia GHSA
CVE-2026-34373High· 8.8
5mo ago

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.66 and 9.7.0-alpha.10, the GraphQL API endpoint does not respect the allowOrigin server option and unconditiona…

Twilightparseplatform · parse-serverEPSS 0.20%via NVD
CVE-2026-34363Medium· 5.3
5mo ago

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.65 and 9.7.0-alpha.9, when multiple clients subscribe to the same class via LiveQuery, the event handlers proce…

Sunlitparseplatform · parse-serverEPSS 0.37%via NVD
CVE-2026-34224Medium· 4.4
5mo ago

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.64 and 9.7.0-alpha.8, an attacker who possesses a valid authentication provider token and a single MFA recovery…

Sunlitparseplatform · parse-serverEPSS 0.31%via NVD
CVE-2026-34595Medium· 4.3
5mo ago

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.70 and 9.7.0-alpha.18, an authenticated user with find class-level permission can bypass the protectedFields cl…

Sunlitparseplatform · parse-serverEPSS 0.25%via NVD
CVE-2026-34574Medium· 5.4
5mo ago

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.69 and 9.7.0-alpha.14, an authenticated user can bypass the immutability guard on session fields (expiresAt, cr…

Sunlitparseplatform · parse-serverEPSS 0.21%via NVD
CVE-2026-34573High· 7.5
5mo ago

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.68 and 9.7.0-alpha.12, the GraphQL query complexity validator can be exploited to cause a denial-of-service by …

Twilightparseplatform · parse-serverEPSS 0.64%via NVD
CVE-2026-34532Critical· 9.1
5mo ago

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.67 and 9.7.0-alpha.11, an attacker can bypass Cloud Function validator access controls by appending "prototype.…

Midnightparseplatform · parse-serverEPSS 0.28%via NVD
parse-server vulnerabilities (CVEs) · VulnSea