OsVault/npm/parse-server
npm7 critical

parse-server

104 known vulnerabilities · 7 critical · 19 high

CVE-2022-39225MEDIUM

parse-server's session object properties can be updated by foreign user if object ID is known

Published Sep 21, 2022
CVE-2022-39396CRITICAL

Remote code execution via MongoDB BSON parser through prototype pollution

Published Nov 8, 2022
CVE-2022-41878HIGH

Parse Server vulnerable to Prototype Pollution via Cloud Code Webhooks or Cloud Code Triggers

Published Nov 9, 2022
CVE-2022-36079HIGH

Parse Server vulnerable to brute force guessing of user sensitive data via search patterns

Published Sep 16, 2022
CVE-2024-29027CRITICAL

Server crashes on invalid Cloud Function or Cloud Job name

Published Mar 19, 2024
CVE-2020-5251HIGH

Information disclosure in parse-server

Published Mar 4, 2020
CVE-2026-33409

Parse Server has an auth provider validation bypass on login via partial authData

Published Mar 19, 2026
CVE-2025-53364

Parse Server exposes the data schema via GraphQL API

Published Jul 10, 2025
CVE-2026-30962

Parse Server has a protected fields bypass via logical query operators

Published Mar 11, 2026
CVE-2026-30947

Parse Server has a bypass of class-level permissions in LiveQuery

Published Mar 11, 2026
CVE-2026-32944

Parse Server crash via deeply nested query condition operators

Published Mar 17, 2026
CVE-2026-30229

parse-server's endpoint `/loginAs` allows `readOnlyMasterKey` to gain full read and write access as any user

Published Mar 6, 2026
CVE-2026-32234

Parse Server has a SQL injection via query field name when using PostgreSQL

Published Mar 12, 2026
CVE-2024-47183

Parse Server's custom object ID allows to acquire role privileges

Published Oct 4, 2024
CVE-2026-31901

Parse Server vulnerable to user enumeration via email verification endpoint

Published Mar 11, 2026
CVE-2026-30854

Parse Server: GraphQL `__type` introspection bypass via inline fragments when public introspection is disabled

Published Mar 9, 2026
CVE-2023-46119HIGH

Parse Server may crash when uploading file without extension

Published Oct 24, 2023
CVE-2026-33421

Parse Server's LiveQuery bypasses CLP pointer permission enforcement

Published Mar 20, 2026
CVE-2026-31875

Parse Server's MFA recovery codes not consumed after use

Published Mar 11, 2026
CVE-2026-32770

Parse Server LiveQuery subscription with invalid regular expression crashes server

Published Mar 17, 2026
CVE-2026-30925

Parse Server has Regular Expression Denial of Service (ReDoS) via `$regex` query in LiveQuery

Published Mar 10, 2026
CVE-2026-32742

Parse Server session creation endpoint allows overwriting server-generated session fields

Published Mar 17, 2026
CVE-2026-30966

Parse Server has role escalation and CLP bypass via direct `_Join` table write

Published Mar 11, 2026
CVE-2026-30939

Parse Server has Denial of Service (DoS) and Cloud Function Dispatch Bypass via Prototype Chain Resolution

Published Mar 10, 2026
CVE-2026-32594

Parse Server's GraphQL WebSocket endpoint bypasses security middleware

Published Mar 13, 2026
CVE-2026-30850

Parse Server: File metadata endpoint bypasses `beforeFind` / `afterFind` trigger authorization

Published Mar 9, 2026
CVE-2026-31856

Parse Server vulnerable to SQL injection via `Increment` operation on nested object field in PostgreSQL

Published Mar 11, 2026
CVE-2026-32269

Parse Server OAuth2 adapter app ID validation sends wrong token to introspection endpoint

Published Mar 13, 2026
CVE-2026-32878

Parse Server vulnerable to schema poisoning via prototype pollution in deep copy

Published Mar 17, 2026
CVE-2024-27298CRITICAL

ZDI-CAN-19105: Parse Server literalizeRegexPart SQL Injection

Published Mar 1, 2024
CVE-2026-30941

Parse Server has a NoSQL injection via token type in password reset and email verification endpoints

Published Mar 11, 2026
CVE-2022-31112HIGH

Protected fields exposed via LiveQuery

Published Jul 6, 2022
CVE-2026-33508

Parse Server LiveQuery subscription query depth bypass

Published Mar 20, 2026
CVE-2026-30965

Parse Server vulnerable to session token exfiltration via `redirectClassNameForKey` query parameter

Published Mar 11, 2026
CVE-2026-31828

Parse Server vulnerable to LDAP injection via unsanitized user input in DN and group filter construction

Published Mar 11, 2026
CVE-2026-33042

Parse Server affected by empty authData bypassing credential requirement on signup

Published Mar 17, 2026
CVE-2026-33624

Parse Server: MFA recovery code single-use bypass via concurrent requests

Published Mar 24, 2026
CVE-2020-15126MEDIUM

GraphQL: Security breach on Viewer query

Published Jul 22, 2020
CVE-2019-1020012HIGH

Parse Server before v3.4.1 vulnerable to Denial of Service

Published Jun 13, 2019
CVE-2020-15270MEDIUM

receiving subscription objects with deleted session

Published Oct 27, 2020
CVE-2025-30168

Parse Server has an OAuth login vulnerability

Published Mar 21, 2025
CVE-2025-68150

Parse Server is vulnerable to Server-Side Request Forgery (SSRF) via Instagram OAuth Adapter

Published Dec 16, 2025
CVE-2026-32728

Parse Server has a stored XSS filter bypass via Content-Type MIME parameter and missing XML extension blocklist entries

Published Mar 16, 2026
CVE-2023-36475CRITICAL

Parse Server vulnerable to remote code execution via MongoDB BSON parser through prototype pollution

Published Jun 30, 2023
CVE-2026-30949

Parse Server missing audience validation in Keycloak authentication adapter

Published Mar 11, 2026
CVE-2026-33498

Parse Server has a query condition depth bypass via pre-validation transform pipeline

Published Mar 20, 2026
CVE-2020-26288HIGH

Parse Server stores password in plain text

Published Dec 28, 2020
CVE-2023-32689MEDIUM

Phishing attack vulnerability by uploading malicious HTML file

Published May 31, 2023
CVE-2024-39309CRITICAL

ZDI-CAN-23894: Parse Server literalizeRegexPart SQL Injection Authentication Bypass Vulnerability

Published Jul 1, 2024
CVE-2026-30946

Parse Server affected by denial-of-service via unbounded query complexity in REST and GraphQL API

Published Mar 11, 2026
GHSA-g4v2-qx3q-4p64

Parse Server's Endpoint `/sessions/me` bypasses `_Session` `protectedFields`

Published Apr 8, 2026
CVE-2022-24760CRITICAL

Command injection in Parse Server through prototype pollution

Published Mar 11, 2022
CVE-2025-64430

Parse Server Vulnerable to Server-Side Request Forgery (SSRF) in File Upload via URI Format

Published Nov 5, 2025
CVE-2022-39231LOW

parse-server auth adapter app ID validation can be circumvented

Published Sep 21, 2022
CVE-2026-30967

Parse Server OAuth2 authentication adapter account takeover via identity spoofing

Published Mar 11, 2026
CVE-2026-31800

Parse Server: Classes `_GraphQLConfig` and `_Audience` master key bypass via generic class routes

Published Mar 11, 2026
CVE-2026-30848

Parse Server: `PagesRouter` path traversal allows reading files outside configured pages directory

Published Mar 9, 2026
CVE-2026-33538

Parse Server: Denial of Service via unindexed database query for unconfigured auth providers

Published Mar 24, 2026
CVE-2026-30948

Parse Server vulnerable to stored cross-site scripting (XSS) via SVG file upload

Published Mar 11, 2026
CVE-2019-1020013MEDIUM

Sensitive Data Exposure in parse-server

Published Jul 11, 2019
CVE-2022-41879HIGH

Parse Server is vulnerable to Prototype Pollution via Cloud Code Webhooks

Published Nov 10, 2022
CVE-2026-30835

parse-server: Malformed `$regex` query leaks database error details in API response

Published Mar 6, 2026
CVE-2026-33539

Parse Server has SQL Injection through aggregate and distinct field names in PostgreSQL adapter

Published Mar 24, 2026
CVE-2025-68115

Parse Server has a Cross-Site Scripting (XSS) vulnerability via Unescaped Mustache Template Variables

Published Dec 16, 2025
GHSA-mmpq-5hcv-hf2v

Parse Server has a login timing side-channel reveals user existence

Published Apr 8, 2026
CVE-2026-31871

Parse Server vulnerable to SQL Injection via dot-notation sub-key name in `Increment` operation on PostgreSQL

Published Mar 11, 2026
CVE-2022-39313HIGH

parse-server crashes when receiving file download request with invalid byte range

Published Oct 18, 2022
CVE-2026-32098

Parse Server has a protected fields bypass via LiveQuery subscription WHERE clause

Published Mar 12, 2026
CVE-2026-33527

Parse Server's Session Update endpoint allows overwriting server-generated session fields

Published Mar 24, 2026
CVE-2026-30938

Parse Server has denylist `requestKeywordDenylist` keyword scan bypass through nested object placement

Published Mar 10, 2026
CVE-2026-33429

Parse Server has a protected field change detection oracle via LiveQuery watch parameter

Published Mar 20, 2026
CVE-2026-34363MEDIUM
Risk: 26.51/100

LiveQuery protected field leak via shared mutable state across concurrent subscribers

Published Mar 30, 2026
CVE-2026-31840

Parse Server: SQL injection via dot-notation field name in PostgreSQL

Published Mar 10, 2026
CVE-2022-31083HIGH

Authentication bypass vulnerability in Apple Game Center auth adapter

Published Jun 17, 2022
CVE-2023-22474HIGH

Parse Server option `masterKeyIps` vulnerability to IP spoofing

Published Jan 31, 2023
CVE-2026-32943

Parse Server has a password reset token single-use bypass via concurrent requests

Published Mar 17, 2026
CVE-2026-31868

Parse Server vulnerable to stored XSS via file upload of HTML-renderable file types

Published Mar 11, 2026
CVE-2026-34215MEDIUM
Risk: 32.51/100

Parse Server exposes auth data via verify password endpoint

Published Mar 29, 2026
CVE-2026-33627

Parse Server exposes auth data via /users/me endpoint

Published Mar 24, 2026
CVE-2026-27804

Parse Server: Account takeover via JWT algorithm confusion in Google auth adapter

Published Feb 25, 2026
CVE-2026-30863

Parse Server: JWT audience validation bypass in Google, Apple, and Facebook authentication adapters

Published Mar 9, 2026
CVE-2026-33163

Parse Server leaks protected fields via LiveQuery afterEvent trigger

Published Mar 18, 2026
CVE-2026-32886

Parse Server's Cloud function dispatch crashes server via prototype chain traversal

Published Mar 17, 2026
CVE-2026-32248

Parse Server: Account takeover via operator injection in authentication data identifier

Published Mar 12, 2026
CVE-2026-33323

Parse Server email verification resend page leaks user existence

Published Mar 19, 2026
CVE-2026-34595MEDIUM
Risk: 21.51/100

Parse Server has a LiveQuery protected-field guard bypass via array-like logical operator value

Published Apr 1, 2026
CVE-2026-32242

Parse Server's OAuth2 adapter shares mutable state across providers via singleton instance

Published Mar 12, 2026
CVE-2026-30228

parse-server's file creation and deletion bypasses `readOnlyMasterKey` write restriction

Published Mar 6, 2026
CVE-2022-24901HIGH

Authentication bypass and denial of service (DoS) vulnerabilities in Apple Game Center auth adapter

Published May 4, 2022
CVE-2026-29182

Parse Server's Cloud Hooks and Cloud Jobs bypass `readOnlyMasterKey` write restriction

Published Mar 5, 2026
CVE-2021-41109HIGH

LiveQuery publishes user session tokens in parse-server

Published Sep 30, 2021
CVE-2023-41058HIGH

Trigger `beforeFind` not invoked in internal query pipeline when fetching pointer

Published Sep 4, 2023
CVE-2026-34784HIGH
Risk: 37.51/100

Parser Server's streaming file download bypasses afterFind file trigger authorization

Published Apr 1, 2026
CVE-2021-39187HIGH

Parse Server crashes with query parameter

Published Sep 2, 2021
CVE-2022-31089HIGH

Invalid file request can crash server

Published Jun 20, 2022
CVE-2026-34373HIGH
Risk: 44.01/100

GraphQL API endpoint ignores CORS origin restriction

Published Mar 30, 2026
CVE-2026-35200MEDIUM
Risk: 30.18/100

Parse Server: File upload Content-Type override via extension mismatch

Published Apr 4, 2026
CVE-2026-34224MEDIUM
Risk: 22.01/100

Parse Server has an MFA single-use token bypass via concurrent authData login requests

Published Mar 29, 2026
CVE-2021-39138MEDIUM

parse-server new anonymous user session acts as if it's created with password

Published Aug 23, 2021
CVE-2026-30972

Parse Server has a rate limit bypass via batch request endpoint

Published Mar 11, 2026
CVE-2026-34574MEDIUM
Risk: 27.01/100

Parse Server has a session field immutability bypass via falsy-value guard

Published Apr 1, 2026
CVE-2026-34573HIGH
Risk: 37.52/100

parse-server has GraphQL complexity validator exponential fragment traversal DoS

Published Mar 31, 2026
CVE-2026-31872

Parse Server has a protected fields bypass via dot-notation in query and sort

Published Mar 11, 2026
CVE-2026-34532CRITICAL
Risk: 45.51/100

parse-server has cloud function validator bypass via prototype chain traversal

Published Mar 31, 2026
Check your entire dependency tree at onceRun dependency scan →