« Back to list

Parseplatform

Parseplatform Parse Server: vulnerabilities and CVEs

Parseplatform Parse Server has 22 published vulnerabilities, 18 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.

CVEs22
Last 12 months18
Critical1
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-101042High (7.4)0.21%—Sep 27, 2026
Parse Server is an open-source backend server. In versions >= 9.0.0 < 9.10.1-alpha.10 and >= 8.0.2 < 8.6.91, the code-based authentication adapters (GitHub, Google Play Games, Instagram, LINE, LinkedIn, Microsoft, QQ,…
CVE-2026-100632High (7.1)0.29%—Sep 26, 2026
Parse Server is an open-source backend server. In versions >= 9.0.0 and < 9.10.1-alpha.8, and in versions < 8.6.89, LiveQuery evaluates the protectedFields class-level permission against an incompletely resolved caller…
CVE-2026-100631High (8.7)0.36%—Sep 26, 2026
Parse Server is an open source backend server. In versions prior to 8.6.90 and in versions from 9.0.0 prior to 9.10.1-alpha.9, the device token deduplication logic for installation records does not validate the type of…
CVE-2026-66009Medium (6.3)0.45%—Jul 24, 2026
Parse Server versions >= 9.0.0 before 9.10.0-alpha.5 and >= 8.2.2 before 8.6.86 return GraphQL validation error messages that name required custom input fields even when public introspection is disabled…
CVE-2026-66008Medium (6.3)0.56%—Jul 24, 2026
Parse Server versions >= 9.0.0 before 9.10.0-alpha.6 and >= 8.2.2 before 8.6.87 disclose Pointer and Relation target class names through GraphQL validation and input-coercion error messages when public schema…
CVE-2026-64627Medium (6.9)0.47%—Jul 21, 2026
Parse Server versions >= 9.0.0 before 9.10.0-alpha.4 and versions before 8.6.85 contain a schema disclosure vulnerability. When the GraphQL API is mounted with public introspection disabled (graphQLPublicIntrospection:…
CVE-2026-61448Low (2.1)0.41%—Jul 11, 2026
Parse Server is affected by a stored cross-site scripting (XSS) vulnerability in versions >= 9.0.0, < 9.10.0-alpha.2 and <= 8.6.83. When an uploaded file's extension is not recognized by the mime package, Parse Server…
CVE-2026-57481Low (2.3)0.53%—Jul 8, 2026
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.9.1-alpha.13 and 8.6.83, a LiveQuery subscriber could receive object field values they were not…
CVE-2026-57480High (8.7)0.59%—Jul 8, 2026
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.9.1-alpha.12 and 8.6.82, deeply nested $or, $and, and $nor query condition operators in the REST API or…
CVE-2021-47987High (7.7)0.18%—Jun 25, 2026
Parse Server before 4.10.0 was affected by a supply chain incident in which incorrect version tags were pushed to the official repository pointing to an unreviewed personal fork of a contributor with write access. No…
CVE-2026-53726Medium (6.9)0.48%—Jun 12, 2026
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.80 and 9.9.1-alpha.6, a relation query using the $relatedTo operator could read the…
CVE-2026-53725Medium (5.9)0.43%—Jun 12, 2026
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. From version 9.8.0 to before version 9.9.1-alpha.5, apps that enable MFA and deny get on the _User class via…
CVE-2026-53724Low (2.1)0.49%—Jun 12, 2026
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.79 and 9.9.1-alpha.4, the default file upload extension blocklist can be bypassed by…
CVE-2026-50008Medium (6.9)0.60%—Jun 12, 2026
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. From version 9.8.0 to before version 9.9.1-alpha.3, the routeAllowList server option restricts external client…
CVE-2026-47248Medium (6.9)0.51%—Jun 12, 2026
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.78 and 9.9.1-alpha.2, Parse Server's GraphQL endpoint discloses schema metadata to…
CVE-2026-47138High (8.7)0.91%—Jun 12, 2026
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.77 and 9.9.1-alpha.1, an unauthenticated attacker who knows a publicly-known Parse…
CVE-2025-64502Medium (6.9)0.42%—Nov 10, 2025
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. The MongoDB `explain()` method provides detailed information about query execution plans, including index usage,…
CVE-2025-64430High (7.5)0.60%—Nov 7, 2025
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions 4.2.0 through 7.5.3, and 8.0.0 through 8.3.1-alpha.1, there is a Server-Side Request Forgery (SSRF)…
CVE-2025-53364Medium (5.3)0.94%—Jul 10, 2025
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Starting in 5.3.0 and before 7.5.3 and 8.2.2, the Parse Server GraphQL API previously allowed public access to the…
CVE-2025-30168Medium (6.9)0.40%—Mar 21, 2025
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 7.5.2 and 8.0.2, the 3rd party authentication handling of Parse Server allows the authentication…
CVE-2024-39309Critical (9.8)20%—Jul 1, 2024
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. A vulnerability in versions prior to 6.5.7 and 7.1.0 allows SQL injection when Parse Server is configured to use…
CVE-2020-15126Medium (6.5)1.1%—Jul 22, 2020
In parser-server from version 3.5.0 and before 4.3.0, an authenticated user using the viewer GraphQL query can by pass all read security on his User object and can also by pass all objects linked via relation or Pointer…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1190 Exploit Public-Facing Application4
  2. T1499.004 Application or System Exploitation2
  3. T1005 Data from Local System1
  4. T1078.001 Default Accounts1
  5. T1090 Proxy1
  6. T1195 Supply Chain Compromise1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Parseplatform