VulnSea

parseplatform has 7 CVEs on record. Disclosures have slowed: 0 in the last 90 days after 7 in the 90 before. The busiest recent month was March 2026 with 7. The median CVSS is 5.4 (medium), with 1 rated critical. None have a confirmed exploitation report.

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
5.4
Publish → KEV
Last 90 days
0 prev 7

Products

  • parse-server 7
7
Total CVEs
1
Critical
0
CISA KEV
0
Exploited

parseplatform vulnerabilities

CVEs affecting parseplatform, newest first. Open any entry for full detail, references, and exploit status.

7 CVEsRSS

CVE-2026-34373High· 8.8
5mo ago

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.66 and 9.7.0-alpha.10, the GraphQL API endpoint does not respect the allowOrigin server option and unconditiona…

Twilightparseplatform · parse-serverEPSS 0.20%via NVD
CVE-2026-34363Medium· 5.3
5mo ago

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.65 and 9.7.0-alpha.9, when multiple clients subscribe to the same class via LiveQuery, the event handlers proce…

Sunlitparseplatform · parse-serverEPSS 0.37%via NVD
CVE-2026-34224Medium· 4.4
5mo ago

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.64 and 9.7.0-alpha.8, an attacker who possesses a valid authentication provider token and a single MFA recovery…

Sunlitparseplatform · parse-serverEPSS 0.31%via NVD
CVE-2026-34595Medium· 4.3
5mo ago

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.70 and 9.7.0-alpha.18, an authenticated user with find class-level permission can bypass the protectedFields cl…

Sunlitparseplatform · parse-serverEPSS 0.25%via NVD
CVE-2026-34574Medium· 5.4
5mo ago

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.69 and 9.7.0-alpha.14, an authenticated user can bypass the immutability guard on session fields (expiresAt, cr…

Sunlitparseplatform · parse-serverEPSS 0.21%via NVD
CVE-2026-34573High· 7.5
5mo ago

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.68 and 9.7.0-alpha.12, the GraphQL query complexity validator can be exploited to cause a denial-of-service by …

Twilightparseplatform · parse-serverEPSS 0.64%via NVD
CVE-2026-34532Critical· 9.1
5mo ago

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.67 and 9.7.0-alpha.11, an attacker can bypass Cloud Function validator access controls by appending "prototype.…

Midnightparseplatform · parse-serverEPSS 0.28%via NVD
parseplatform vulnerabilities (CVEs) · VulnSea