Parseplatform
Parseplatform Parse-server: vulnerabilidades y CVE
Parseplatform Parse-server tiene 102 vulnerabilidades publicadas, 74 de ellas en los últimos 12 meses. 17 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE102
Últimos 12 meses74
Críticas17
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2021-47986 | Alta (7.7) | 0.18% | — | 25 jun 2026 | Parse Server before 4.10.0 contains a supply chain vulnerability where incorrect version tags were pushed to the repository linking to unreviewed code in a personal fork. Attackers could exploit this by specifying… |
| CVE-2026-43930 | Baja (2.1) | 0.30% | — | 12 may 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.76 and 9.9.0-alpha.2, a race condition in the MFA SMS one-time password (OTP) login path allows two… |
| CVE-2026-39381 | Media (5.3) | 0.32% | — | 7 abr 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.8.0-alpha.7 and 8.6.75, the GET /sessions/me endpoint returns _Session fields that the server operator… |
| CVE-2026-39321 | Media (6.3) | 0.37% | — | 7 abr 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.8.0-alpha.6 and 8.6.74, he login endpoint response time differs measurably depending on whether the… |
| CVE-2026-35200 | Baja (2.1) | 0.28% | — | 6 abr 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.73 and 9.7.1-alpha.4, a file can be uploaded with a filename extension that passes the file extension… |
| CVE-2026-34784 | Alta (8.2) | 0.47% | — | 31 mar 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.71 and 9.7.1-alpha.1, file downloads via HTTP Range requests bypass the afterFind(Parse.File)… |
| CVE-2026-34215 | Alta (8.2) | 0.53% | — | 31 mar 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.63 and 9.7.0-alpha.7, the verify password endpoint returns unsanitized authentication data,… |
| CVE-2026-34595 | Media (5.3) | 0.43% | — | 31 mar 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.70 and 9.7.0-alpha.18, an authenticated user with find class-level permission can bypass the… |
| CVE-2026-34574 | Media (5.3) | 0.34% | — | 31 mar 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.69 and 9.7.0-alpha.14, an authenticated user can bypass the immutability guard on session… |
| CVE-2026-34573 | Alta (8.2) | 0.86% | — | 31 mar 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.68 and 9.7.0-alpha.12, the GraphQL query complexity validator can be exploited to cause a… |
| CVE-2026-34532 | Crítica (9.1) | 0.49% | — | 31 mar 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.67 and 9.7.0-alpha.11, an attacker can bypass Cloud Function validator access controls by… |
| CVE-2026-34373 | Media (5.3) | 0.24% | — | 31 mar 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.66 and 9.7.0-alpha.10, the GraphQL API endpoint does not respect the allowOrigin server… |
| CVE-2026-34363 | Alta (8.2) | 0.40% | — | 31 mar 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.65 and 9.7.0-alpha.9, when multiple clients subscribe to the same class via LiveQuery, the… |
| CVE-2026-34224 | Baja (2.1) | 0.34% | — | 31 mar 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.64 and 9.7.0-alpha.8, an attacker who possesses a valid authentication provider token and a… |
| CVE-2026-33627 | Alta (7.1) | 0.53% | — | 24 mar 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.61 and 9.6.0-alpha.55, an authenticated user calling GET /users/me receives unsanitized auth… |
| CVE-2026-33624 | Baja (2.1) | 0.29% | — | 24 mar 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.60 and 9.6.0-alpha.54, an attacker who obtains a user's password and a single MFA recovery… |
| CVE-2026-33539 | Alta (8.6) | 0.67% | — | 24 mar 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.59 and 9.6.0-alpha.53, an attacker with master key access can execute arbitrary SQL… |
| CVE-2026-33538 | Alta (8.7) | 0.75% | — | 24 mar 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.58 and 9.6.0-alpha.52, an unauthenticated attacker can cause denial of service by sending… |
| CVE-2026-33527 | Media (5.3) | 0.34% | — | 24 mar 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.57 and 9.6.0-alpha.48, an authenticated user can overwrite server-generated session fields… |
| CVE-2026-33508 | Alta (8.2) | 0.62% | — | 24 mar 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.56 and 9.6.0-alpha.45, Parse Server's LiveQuery component does not enforce the… |
| CVE-2026-33498 | Alta (8.7) | 0.62% | — | 24 mar 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.55 and 9.6.0-alpha.44, an attacker can send an unauthenticated HTTP request with a deeply… |
| CVE-2026-33429 | Media (6.3) | 0.41% | — | 24 mar 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.54 and 9.6.0-alpha.43, an attacker can subscribe to LiveQuery with a watch parameter… |
| CVE-2026-33421 | Alta (7.1) | 0.44% | — | 24 mar 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.53 and 9.6.0-alpha.42, Parse Server's LiveQuery WebSocket interface does not enforce… |
| CVE-2026-33409 | Alta (7) | 0.56% | — | 24 mar 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.52 and 9.6.0-alpha.41, an authentication bypass vulnerability allows an attacker to log in as… |
| CVE-2026-33323 | Media (6.3) | 0.43% | — | 24 mar 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.51 and 9.6.0-alpha.40, the Pages route and legacy PublicAPI route for resending email… |
| CVE-2026-33163 | Alta (8.2) | 0.50% | — | 18 mar 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.35 and 8.6.50, when a `Parse.Cloud.afterLiveQueryEvent` trigger is registered for a class, the… |
| CVE-2026-33042 | Media (6.9) | 0.37% | — | 18 mar 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.29 and 8.6.49, a user can sign up without providing credentials by sending an empty `authData`… |
| CVE-2026-32944 | Alta (8.7) | 0.61% | — | 18 mar 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.21 and 8.6.45, an unauthenticated attacker can crash the Parse Server process by sending a… |
| CVE-2026-32943 | Baja (2.3) | 0.24% | — | 18 mar 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.28 and 8.6.48, the password reset mechanism does not enforce single-use guarantees for reset… |
| CVE-2026-32886 | Alta (8.2) | 0.67% | — | 18 mar 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.24 and 8.6.47, remote clients can crash the Parse Server process by calling a cloud function… |