CVE-2026-87806Parse Server 9.0.0 Authentication Bypass via LDAP Empty Password Exploitation status Not known exploited Fix YesAffected product P parse-server Published 09/09/2026 Severity Critical CVE-2026-66009Parse Server 9.0.0 Information Disclosure via GraphQL Error Messages Exploitation status Not known exploited Fix YesAffected product P parse-server Published 07/24/2026 Severity Medium CVE-2026-66008Parse Server 9.0.0 Information Disclosure via GraphQL Error Messages Exploitation status Not known exploited Fix YesAffected product P parse-server Published 07/24/2026 Severity Medium CVE-2026-64627Parse Server 9.0.0 Schema Disclosure via GraphQL Variable Coercion Exploitation status Not known exploited Fix YesAffected product P parse-server Published 07/21/2026 Severity Medium CVE-2026-61448Parse Server 9.0.0 Stored XSS via malformed Content-Type Exploitation status Not known exploited Fix YesAffected product P parse-server Published 07/11/2026 Severity Low CVE-2026-57481Parse Server: LiveQuery discloses object data to a subscriber across an ACL read-access change Exploitation status Not known exploited Fix YesAffected product P parse-server Published 07/08/2026 Severity Low CVE-2026-57480Parse Server: Denial of service via exponential-time processing of deeply nested query operators Exploitation status Not known exploited Fix YesAffected product P parse-server Published 07/08/2026 Severity High CVE-2026-55778Parse Server: Stored XSS via non-standard file extension bypassing file upload extension blocklist Exploitation status Not known exploited Fix YesAffected product P parse-server Published 07/08/2026 Severity Low CVE-2021-47987Parse Server - Arbitrary Code Execution via Malicious Version Tags Exploitation status Not known exploited Fix YesAffected product P parse-server Published 06/25/2026 Severity High CVE-2021-47986Parse Server - Unreviewed Code Execution via Malicious Version Tags Exploitation status Not known exploited Fix YesAffected product P parse-server Published 06/25/2026 Severity High CVE-2026-53726Parse Server: Relation `$relatedTo` query bypasses `protectedFields` and owning-object ACL Exploitation status Not known exploited Fix YesAffected product P parse-server Published 06/12/2026 Severity Medium CVE-2026-53725Parse Server: Endpoints `/login` and `/verifyPassword` disclose MFA secrets and protected fields when `_User` get is denied Exploitation status Not known exploited Fix YesAffected product P parse-server Published 06/12/2026 Severity Medium CVE-2026-53724Parse Server: Stored XSS via trailing-dot filename bypassing file upload extension blocklist Exploitation status Not known exploited Fix YesAffected product P parse-server Published 06/12/2026 Severity Low CVE-2026-50008Parse Server: Server option routeAllowList is bypassable through batch sub-requests Exploitation status Not known exploited Fix YesAffected product P parse-server Published 06/12/2026 Severity Medium CVE-2026-47138Parse Server: Pre-authentication denial of service via client version header regex backtracking Exploitation status Not known exploited Fix YesAffected product P parse-server Published 06/12/2026 Severity High CVE-2026-47248Parse Server: GraphQL "Did you mean" validation suggestions disclose schema to unauthenticated callers Exploitation status Not known exploited Fix YesAffected product P parse-server Published 06/12/2026 Severity Medium CVE-2026-43930Parse Server: MFA SMS one-time password accepted twice under concurrent login Exploitation status Not known exploited Fix YesAffected product P parse-server Published 05/12/2026 Severity Low CVE-2026-39381Parse Server's Endpoint `/sessions/me` bypasses `_Session` `protectedFields` Exploitation status Not known exploited Fix YesAffected product P parse-server Published 04/07/2026 Severity Medium CVE-2026-39321Parse Server has a login timing side-channel reveals user existence Exploitation status Not known exploited Fix YesAffected product P parse-server Published 04/07/2026 Severity Medium CVE-2026-35200Parse Server has a file upload Content-Type override via extension mismatch Exploitation status Not known exploited Fix YesAffected product P parse-server Published 04/06/2026 Severity Low CVE-2026-34784Parse Server: Streaming file download bypasses afterFind file trigger authorization Exploitation status Not known exploited Fix YesAffected product P parse-server Published 03/31/2026 Severity High CVE-2026-34215Parse Server: Auth data exposed via verify password endpoint Exploitation status Not known exploited Fix YesAffected product P parse-server Published 03/31/2026 Severity High CVE-2026-34595Parse Server: LiveQuery protected-field guard bypass via array-like logical operator value Exploitation status Not known exploited Fix YesAffected product P parse-server Published 03/31/2026 Severity Medium CVE-2026-34574Parse Server: Session field immutability bypass via falsy-value guard Exploitation status Not known exploited Fix YesAffected product P parse-server Published 03/31/2026 Severity Medium CVE-2026-34573Parse Server: GraphQL complexity validator exponential fragment traversal DoS Exploitation status Not known exploited Fix YesAffected product P parse-server Published 03/31/2026 Severity High CVE-2026-34532Parse Server: Cloud function validator bypass via prototype chain traversal Exploitation status Not known exploited Fix YesAffected product P parse-server Published 03/31/2026 Severity Critical CVE-2026-34373Parse Server: GraphQL API endpoint ignores CORS origin restriction Exploitation status Not known exploited Fix YesAffected product P parse-server Published 03/31/2026 Severity Medium CVE-2026-34363Parse Server: LiveQuery protected field leak via shared mutable state across concurrent subscribers Exploitation status Not known exploited Fix YesAffected product P parse-server Published 03/31/2026 Severity High CVE-2026-34224Parse Server: MFA single-use token bypass via concurrent authData login requests Exploitation status Not known exploited Fix YesAffected product P parse-server Published 03/31/2026 Severity Low CVE-2026-33627Parse Server: Auth data exposed via /users/me endpoint Exploitation status Not known exploited Fix YesAffected product P parse-server Published 03/24/2026 Severity High CVE-2026-33624Parse Server: MFA recovery code single-use bypass via concurrent requests Exploitation status Not known exploited Fix YesAffected product P parse-server Published 03/24/2026 Severity Low CVE-2026-33539Parse Server: SQL injection via aggregate and distinct field names in PostgreSQL adapter Exploitation status Not known exploited Fix YesAffected product P parse-server Published 03/24/2026 Severity High CVE-2026-33538Parse Server: Denial of service via unindexed database query for unconfigured auth providers Exploitation status Not known exploited Fix YesAffected product P parse-server Published 03/24/2026 Severity High CVE-2026-33527Parse Server: Session update endpoint allows overwriting server-generated session fields Exploitation status Not known exploited Fix YesAffected product P parse-server Published 03/24/2026 Severity Medium CVE-2026-33508Parse Server: LiveQuery subscription query depth bypass Exploitation status Not known exploited Fix YesAffected product P parse-server Published 03/24/2026 Severity High CVE-2026-33498Parse Server: Query condition depth bypass via pre-validation transform pipeline Exploitation status Not known exploited Fix YesAffected product P parse-server Published 03/24/2026 Severity High CVE-2026-33429Parse Server: Protected field change detection oracle via LiveQuery watch parameter Exploitation status Not known exploited Fix YesAffected product P parse-server Published 03/24/2026 Severity Medium CVE-2026-33421Parse Server: LiveQuery bypasses CLP pointer permission enforcement Exploitation status Not known exploited Fix YesAffected product P parse-server Published 03/24/2026 Severity High CVE-2026-33409Parse Server: Auth provider validation bypass on login via partial authData Exploitation status Not known exploited Fix YesAffected product P parse-server Published 03/24/2026 Severity High CVE-2026-33323Parse Server: Email verification resend page leaks user existence Exploitation status Not known exploited Fix YesAffected product P parse-server Published 03/24/2026 Severity Medium CVE-2026-33163Parse Server leaks protected fields via LiveQuery afterEvent trigger Exploitation status Not known exploited Fix Not confirmed Affected product P parse-server Published 03/18/2026 Severity High CVE-2026-33042Parse Server affected by empty authData bypassing credential requirement on signup Exploitation status Not known exploited Fix Not confirmed Affected product P parse-server Published 03/18/2026 Severity Medium CVE-2026-32944Parse Server crash via deeply nested query condition operators Exploitation status Not known exploited Fix Not confirmed Affected product P parse-server Published 03/18/2026 Severity High CVE-2026-32943Parse Server has a password reset token single-use bypass via concurrent requests Exploitation status Not known exploited Fix Not confirmed Affected product P parse-server Published 03/18/2026 Severity Low CVE-2026-32886Parse Server's Cloud function dispatch crashes server via prototype chain traversal Exploitation status Not known exploited Fix Not confirmed Affected product P parse-server Published 03/18/2026 Severity High CVE-2026-32878Parse Server vulnerable to schema poisoning via prototype pollution in deep copy Exploitation status Not known exploited Fix Not confirmed Affected product P parse-server Published 03/18/2026 Severity Medium CVE-2026-32770Parse Server: LiveQuery subscription with invalid regular expression crashes server Exploitation status Not known exploited Fix Not confirmed Affected product P parse-server Published 03/18/2026 Severity Medium CVE-2026-32742Parse Server session creation endpoint allows overwriting server-generated session fields Exploitation status Not known exploited Fix Not confirmed Affected product P parse-server Published 03/18/2026 Severity Medium CVE-2026-32728Parse Server has a stored XSS filter bypass via Content-Type MIME parameter and missing XML extension blocklist entries Exploitation status Not known exploited Fix Not confirmed Affected product P parse-server Published 03/18/2026 Severity High CVE-2026-32594Parse Server GraphQL WebSocket endpoint bypasses security middleware Exploitation status Not known exploited Fix YesAffected product P parse-server Published 03/13/2026 Severity Medium CVE-2026-32269Parse Server OAuth2 adapter app ID validation sends wrong token to introspection endpoint Exploitation status Not known exploited Fix YesAffected product P parse-server Published 03/12/2026 Severity Medium CVE-2026-32248Parse Server: Account takeover via operator injection in authentication data identifier Exploitation status Not known exploited Fix YesAffected product P parse-server Published 03/12/2026 Severity Critical CVE-2026-32242Parse Server OAuth2 adapter shares mutable state across providers via singleton instance Exploitation status Not known exploited Fix YesAffected product P parse-server Published 03/12/2026 Severity Critical CVE-2026-32234Parse Server has a SQL injection via query field name when using PostgreSQL Exploitation status Not known exploited Fix YesAffected product P parse-server Published 03/11/2026 Severity Medium CVE-2026-32098Parse Server has a protected fields bypass via LiveQuery subscription WHERE clause Exploitation status Not known exploited Fix YesAffected product P parse-server Published 03/11/2026 Severity Medium CVE-2026-31901Parse Server has user enumeration via email verification endpoint Exploitation status Not known exploited Fix YesAffected product P parse-server Published 03/11/2026 Severity Medium CVE-2026-31875Parse Server MFA recovery codes not consumed after use Exploitation status Not known exploited Fix YesAffected product P parse-server Published 03/11/2026 Severity High CVE-2026-31872Parse Server has a protected fields bypass via dot-notation in query and sort Exploitation status Not known exploited Fix YesAffected product P parse-server Published 03/11/2026 Severity High CVE-2026-31871Parse Server has a SQL Injection via dot-notation sub-key name in `Increment` operation on PostgreSQL Exploitation status Not known exploited Fix YesAffected product P parse-server Published 03/11/2026 Severity Critical CVE-2026-31868Parse Server has Stored XSS via file upload of HTML-renderable file types Exploitation status Not known exploited Fix YesAffected product P parse-server Published 03/11/2026 Severity Medium CVE-2026-31856Parse Server has a SQL injection via `Increment` operation on nested object field in PostgreSQL Exploitation status Not known exploited Fix YesAffected product P parse-server Published 03/11/2026 Severity Critical CVE-2026-31840Parse Server has a SQL injection via dot-notation field name in PostgreSQL Exploitation status Not known exploited Fix YesAffected product P parse-server Published 03/11/2026 Severity Critical CVE-2026-31828Parse Server has an LDAP injection via unsanitized user input in DN and group filter construction Exploitation status Not known exploited Fix YesAffected product P parse-server Published 03/10/2026 Severity Medium CVE-2026-31800Parse Server: Classes `_GraphQLConfig` and `_Audience` master key bypass via generic class routes Exploitation status Not known exploited Fix YesAffected product P parse-server Published 03/10/2026 Severity High CVE-2026-30972Parse Server has a rate limit bypass via batch request endpoint Exploitation status Not known exploited Fix YesAffected product P parse-server Published 03/10/2026 Severity Medium CVE-2026-30967Parse Server OAuth2 authentication adapter account takeover via identity spoofing Exploitation status Not known exploited Fix YesAffected product P parse-server Published 03/10/2026 Severity High CVE-2026-30966Parse Server role escalation and CLP bypass via direct `_Join` table write Exploitation status Not known exploited Fix YesAffected product P parse-server Published 03/10/2026 Severity Critical CVE-2026-30965Parse Server session token exfiltration via `redirectClassNameForKey` query parameter Exploitation status Not known exploited Fix YesAffected product P parse-server Published 03/10/2026 Severity Critical CVE-2026-30962Parse Server has a protected fields bypass via logical query operators Exploitation status Not known exploited Fix YesAffected product P parse-server Published 03/10/2026 Severity High CVE-2026-30949Parse Server is missing audience validation in Keycloak authentication adapter Exploitation status Not known exploited Fix YesAffected product P parse-server Published 03/10/2026 Severity High CVE-2026-30948Parse Server has stored cross-site scripting (XSS) via SVG file upload Exploitation status Not known exploited Fix YesAffected product P parse-server Published 03/10/2026 Severity High CVE-2026-30947Parse Server ha a bypass of class-level permissions in LiveQuery Exploitation status Not known exploited Fix YesAffected product P parse-server Published 03/10/2026 Severity High CVE-2026-30946Parse Server affected by denial-of-service via unbounded query complexity in REST and GraphQL API Exploitation status Not known exploited Fix YesAffected product P parse-server Published 03/10/2026 Severity High CVE-2026-30941Parse Server has a NoSQL injection via token type in password reset and email verification endpoints Exploitation status Not known exploited Fix YesAffected product P parse-server Published 03/10/2026 Severity High CVE-2026-30939Parse Server has Denial of Service (DoS) and Cloud Function Dispatch Bypass via Prototype Chain Resolution Exploitation status Not known exploited Fix YesAffected product P parse-server Published 03/10/2026 Severity High CVE-2026-30938Parse Server has denylist `requestKeywordDenylist` keyword scan bypass through nested object placement Exploitation status Not known exploited Fix YesAffected product P parse-server Published 03/10/2026 Severity Medium CVE-2026-30925Parse Server affected by Regular Expression Denial of Service (ReDoS) via `$regex` query in LiveQuery Exploitation status Not known exploited Fix YesAffected product P parse-server Published 03/09/2026 Severity High CVE-2026-30854Parse Server: GraphQL `__type` introspection bypass via inline fragments when public introspection is disabled Exploitation status Not known exploited Fix YesAffected product P parse-server Published 03/07/2026 Severity Medium CVE-2026-30850Parse Server: File metadata endpoint bypasses `beforeFind` / `afterFind` trigger authorization Exploitation status Not known exploited Fix YesAffected product P parse-server Published 03/07/2026 Severity Medium CVE-2026-30848Parse Server: `PagesRouter` path traversal allows reading files outside configured pages directory Exploitation status Not known exploited Fix YesAffected product P parse-server Published 03/07/2026 Severity Medium CVE-2026-30863Parse Server: JWT audience validation bypass in Google, Apple, and Facebook authentication adapters Exploitation status Not known exploited Fix YesAffected product P parse-server Published 03/07/2026 Severity Critical CVE-2026-30835Parse Server: Malformed `$regex` query leaks database error details in API response Exploitation status Not known exploited Fix YesAffected product P parse-server Published 03/06/2026 Severity Medium CVE-2026-30229Parse Server: Endpoint `/loginAs` allows `readOnlyMasterKey` to gain full read and write access as any user Exploitation status Not known exploited Fix YesAffected product P parse-server Published 03/06/2026 Severity High CVE-2026-30228Parse Server: File creation and deletion bypasses `readOnlyMasterKey` write restriction Exploitation status Not known exploited Fix YesAffected product P parse-server Published 03/06/2026 Severity Medium CVE-2026-29182Parse Server: Cloud Hooks and Cloud Jobs bypass `readOnlyMasterKey` write restriction Exploitation status Not known exploited Fix YesAffected product P parse-server Published 03/06/2026 Severity High CVE-2026-27804Parse Server: Account takeover via JWT algorithm confusion in Google auth adapter Exploitation status Not known exploited Fix Not confirmed Affected product P parse-server Published 02/25/2026 Severity Critical CVE-2026-27595Parse Dashboard has incomplete authentication on AI Agent endpoint Exploitation status Not known exploited Fix Not confirmed Affected product P parse-dashboard Published 02/25/2026 Severity Critical CVE-2026-27610Parse Dashboard Has a Cache Key Collision that Leaks Master Key to Read-Only Sessions Exploitation status Not known exploited Fix Not confirmed Affected product P parse-dashboard Published 02/25/2026 Severity High CVE-2026-27609Parse Dashboard Missing CSRF Protection on Agent Endpoint Exploitation status Not known exploited Fix Not confirmed Affected product P parse-dashboard Published 02/25/2026 Severity High CVE-2026-27608Parse Dashboard Missing Authorization on Agent Endpoint Exploitation status Not known exploited Fix Not confirmed Affected product P parse-dashboard Published 02/25/2026 Severity Critical CVE-2025-68150Parse Server has Server-Side Request Forgery (SSRF) in Instagram OAuth Adapter Exploitation status Not known exploited Fix YesAffected product P parse-server Published 12/16/2025 Severity High CVE-2025-68115Parse Server vulnerable to Cross-Site Scripting (XSS) via Unescaped Mustache Template Variables Exploitation status Not known exploited Fix Not confirmed Affected product P parse-server Published 12/16/2025 Severity Medium CVE-2025-67727Parse Server GitHub CI workflow vulnerable to RCE through Improper Privilege Management Exploitation status Not known exploited Fix Not confirmed Affected product P parse-server Published 12/12/2025 Severity Medium CVE-2025-64502Parse Server allows public `explain` queries which may expose sensitive database performance information and schema details Exploitation status Not known exploited Fix Not confirmed Affected product P parse-server Published 11/10/2025 Severity Medium CVE-2025-64430Parse Server Vulnerable to Server-Side Request Forgery (SSRF) in File Upload via URI Format Exploitation status Not known exploited Fix YesAffected product P parse-server Published 11/07/2025 Severity High CVE-2025-62374Parse Javascript SDK vulnerable to prototype pollution in `Parse.Object` and internal APIs Exploitation status Not known exploited Fix YesAffected product P Parse-SDK-JS Published 10/14/2025 Severity Medium CVE-2025-53364Parse Server exposes the data schema via GraphQL API Exploitation status Not known exploited Fix YesAffected product P parse-server Published 07/10/2025 Severity Medium CVE-2025-30168Parse Server has an OAuth login vulnerability Exploitation status Not known exploited Fix YesAffected product P parse-server Published 03/21/2025 Severity Medium CVE-2024-47183Parse Server's custom object ID allows to acquire role privileges Exploitation status Public exploit Fix YesAffected product P parse-server Published 10/04/2024 Severity High CVE-2024-39309ZDI-CAN-23894: Parse Server literalizeRegexPart SQL Injection Authentication Bypass Vulnerability Exploitation status Not known exploited Fix Not confirmed Affected product P parse-server Published 07/01/2024 Severity Critical