Parseplatform
Parseplatform Parse Server: vulnerabilities and CVEs
Parseplatform Parse Server has 22 published vulnerabilities, 18 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.
CVEs22
Last 12 months18
Critical1
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-101042 | High (7.4) | 0.21% | — | Sep 27, 2026 | Parse Server is an open-source backend server. In versions >= 9.0.0 < 9.10.1-alpha.10 and >= 8.0.2 < 8.6.91, the code-based authentication adapters (GitHub, Google Play Games, Instagram, LINE, LinkedIn, Microsoft, QQ,… |
| CVE-2026-100632 | High (7.1) | 0.29% | — | Sep 26, 2026 | Parse Server is an open-source backend server. In versions >= 9.0.0 and < 9.10.1-alpha.8, and in versions < 8.6.89, LiveQuery evaluates the protectedFields class-level permission against an incompletely resolved caller… |
| CVE-2026-100631 | High (8.7) | 0.36% | — | Sep 26, 2026 | Parse Server is an open source backend server. In versions prior to 8.6.90 and in versions from 9.0.0 prior to 9.10.1-alpha.9, the device token deduplication logic for installation records does not validate the type of… |
| CVE-2026-66009 | Medium (6.3) | 0.45% | — | Jul 24, 2026 | Parse Server versions >= 9.0.0 before 9.10.0-alpha.5 and >= 8.2.2 before 8.6.86 return GraphQL validation error messages that name required custom input fields even when public introspection is disabled… |
| CVE-2026-66008 | Medium (6.3) | 0.56% | — | Jul 24, 2026 | Parse Server versions >= 9.0.0 before 9.10.0-alpha.6 and >= 8.2.2 before 8.6.87 disclose Pointer and Relation target class names through GraphQL validation and input-coercion error messages when public schema… |
| CVE-2026-64627 | Medium (6.9) | 0.47% | — | Jul 21, 2026 | Parse Server versions >= 9.0.0 before 9.10.0-alpha.4 and versions before 8.6.85 contain a schema disclosure vulnerability. When the GraphQL API is mounted with public introspection disabled (graphQLPublicIntrospection:… |
| CVE-2026-61448 | Low (2.1) | 0.41% | — | Jul 11, 2026 | Parse Server is affected by a stored cross-site scripting (XSS) vulnerability in versions >= 9.0.0, < 9.10.0-alpha.2 and <= 8.6.83. When an uploaded file's extension is not recognized by the mime package, Parse Server… |
| CVE-2026-57481 | Low (2.3) | 0.53% | — | Jul 8, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.9.1-alpha.13 and 8.6.83, a LiveQuery subscriber could receive object field values they were not… |
| CVE-2026-57480 | High (8.7) | 0.59% | — | Jul 8, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.9.1-alpha.12 and 8.6.82, deeply nested $or, $and, and $nor query condition operators in the REST API or… |
| CVE-2021-47987 | High (7.7) | 0.18% | — | Jun 25, 2026 | Parse Server before 4.10.0 was affected by a supply chain incident in which incorrect version tags were pushed to the official repository pointing to an unreviewed personal fork of a contributor with write access. No… |
| CVE-2026-53726 | Medium (6.9) | 0.48% | — | Jun 12, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.80 and 9.9.1-alpha.6, a relation query using the $relatedTo operator could read the… |
| CVE-2026-53725 | Medium (5.9) | 0.43% | — | Jun 12, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. From version 9.8.0 to before version 9.9.1-alpha.5, apps that enable MFA and deny get on the _User class via… |
| CVE-2026-53724 | Low (2.1) | 0.49% | — | Jun 12, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.79 and 9.9.1-alpha.4, the default file upload extension blocklist can be bypassed by… |
| CVE-2026-50008 | Medium (6.9) | 0.60% | — | Jun 12, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. From version 9.8.0 to before version 9.9.1-alpha.3, the routeAllowList server option restricts external client… |
| CVE-2026-47248 | Medium (6.9) | 0.51% | — | Jun 12, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.78 and 9.9.1-alpha.2, Parse Server's GraphQL endpoint discloses schema metadata to… |
| CVE-2026-47138 | High (8.7) | 0.91% | — | Jun 12, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.77 and 9.9.1-alpha.1, an unauthenticated attacker who knows a publicly-known Parse… |
| CVE-2025-64502 | Medium (6.9) | 0.42% | — | Nov 10, 2025 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. The MongoDB `explain()` method provides detailed information about query execution plans, including index usage,… |
| CVE-2025-64430 | High (7.5) | 0.60% | — | Nov 7, 2025 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions 4.2.0 through 7.5.3, and 8.0.0 through 8.3.1-alpha.1, there is a Server-Side Request Forgery (SSRF)… |
| CVE-2025-53364 | Medium (5.3) | 0.94% | — | Jul 10, 2025 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Starting in 5.3.0 and before 7.5.3 and 8.2.2, the Parse Server GraphQL API previously allowed public access to the… |
| CVE-2025-30168 | Medium (6.9) | 0.40% | — | Mar 21, 2025 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 7.5.2 and 8.0.2, the 3rd party authentication handling of Parse Server allows the authentication… |
| CVE-2024-39309 | Critical (9.8) | 20% | — | Jul 1, 2024 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. A vulnerability in versions prior to 6.5.7 and 7.1.0 allows SQL injection when Parse Server is configured to use… |
| CVE-2020-15126 | Medium (6.5) | 1.1% | — | Jul 22, 2020 | In parser-server from version 3.5.0 and before 4.3.0, an authenticated user using the viewer GraphQL query can by pass all read security on his User object and can also by pass all objects linked via relation or Pointer… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.