CVE-2026-87806Parse Server 9.0.0 Authentication Bypass via LDAP Empty Password | Exploitation statusNot known exploited | FixYes | Published09/09/2026 | SeverityCritical |
|---|
CVE-2026-66009Parse Server 9.0.0 Information Disclosure via GraphQL Error Messages | Exploitation statusNot known exploited | FixYes | Published07/24/2026 | SeverityMedium |
|---|
CVE-2026-66008Parse Server 9.0.0 Information Disclosure via GraphQL Error Messages | Exploitation statusNot known exploited | FixYes | Published07/24/2026 | SeverityMedium |
|---|
CVE-2026-64627Parse Server 9.0.0 Schema Disclosure via GraphQL Variable Coercion | Exploitation statusNot known exploited | FixYes | Published07/21/2026 | SeverityMedium |
|---|
CVE-2026-61448Parse Server 9.0.0 Stored XSS via malformed Content-Type | Exploitation statusNot known exploited | FixYes | Published07/11/2026 | SeverityLow |
|---|
CVE-2026-57481Parse Server: LiveQuery discloses object data to a subscriber across an ACL read-access change | Exploitation statusNot known exploited | FixYes | Published07/08/2026 | SeverityLow |
|---|
CVE-2026-57480Parse Server: Denial of service via exponential-time processing of deeply nested query operators | Exploitation statusNot known exploited | FixYes | Published07/08/2026 | SeverityHigh |
|---|
CVE-2026-55778Parse Server: Stored XSS via non-standard file extension bypassing file upload extension blocklist | Exploitation statusNot known exploited | FixYes | Published07/08/2026 | SeverityLow |
|---|
CVE-2021-47987Parse Server - Arbitrary Code Execution via Malicious Version Tags | Exploitation statusNot known exploited | FixYes | Published06/25/2026 | SeverityHigh |
|---|
CVE-2021-47986Parse Server - Unreviewed Code Execution via Malicious Version Tags | Exploitation statusNot known exploited | FixYes | Published06/25/2026 | SeverityHigh |
|---|
CVE-2026-53726Parse Server: Relation `$relatedTo` query bypasses `protectedFields` and owning-object ACL | Exploitation statusNot known exploited | FixYes | Published06/12/2026 | SeverityMedium |
|---|
CVE-2026-53725Parse Server: Endpoints `/login` and `/verifyPassword` disclose MFA secrets and protected fields when `_User` get is denied | Exploitation statusNot known exploited | FixYes | Published06/12/2026 | SeverityMedium |
|---|
CVE-2026-53724Parse Server: Stored XSS via trailing-dot filename bypassing file upload extension blocklist | Exploitation statusNot known exploited | FixYes | Published06/12/2026 | SeverityLow |
|---|
CVE-2026-50008Parse Server: Server option routeAllowList is bypassable through batch sub-requests | Exploitation statusNot known exploited | FixYes | Published06/12/2026 | SeverityMedium |
|---|
CVE-2026-47138Parse Server: Pre-authentication denial of service via client version header regex backtracking | Exploitation statusNot known exploited | FixYes | Published06/12/2026 | SeverityHigh |
|---|
CVE-2026-47248Parse Server: GraphQL "Did you mean" validation suggestions disclose schema to unauthenticated callers | Exploitation statusNot known exploited | FixYes | Published06/12/2026 | SeverityMedium |
|---|
CVE-2026-43930Parse Server: MFA SMS one-time password accepted twice under concurrent login | Exploitation statusNot known exploited | FixYes | Published05/12/2026 | SeverityLow |
|---|
CVE-2026-39381Parse Server's Endpoint `/sessions/me` bypasses `_Session` `protectedFields` | Exploitation statusNot known exploited | FixYes | Published04/07/2026 | SeverityMedium |
|---|
CVE-2026-39321Parse Server has a login timing side-channel reveals user existence | Exploitation statusNot known exploited | FixYes | Published04/07/2026 | SeverityMedium |
|---|
CVE-2026-35200Parse Server has a file upload Content-Type override via extension mismatch | Exploitation statusNot known exploited | FixYes | Published04/06/2026 | SeverityLow |
|---|
CVE-2026-34784Parse Server: Streaming file download bypasses afterFind file trigger authorization | Exploitation statusNot known exploited | FixYes | Published03/31/2026 | SeverityHigh |
|---|
CVE-2026-34215Parse Server: Auth data exposed via verify password endpoint | Exploitation statusNot known exploited | FixYes | Published03/31/2026 | SeverityHigh |
|---|
CVE-2026-34595Parse Server: LiveQuery protected-field guard bypass via array-like logical operator value | Exploitation statusNot known exploited | FixYes | Published03/31/2026 | SeverityMedium |
|---|
CVE-2026-34574Parse Server: Session field immutability bypass via falsy-value guard | Exploitation statusNot known exploited | FixYes | Published03/31/2026 | SeverityMedium |
|---|
CVE-2026-34573Parse Server: GraphQL complexity validator exponential fragment traversal DoS | Exploitation statusNot known exploited | FixYes | Published03/31/2026 | SeverityHigh |
|---|
CVE-2026-34532Parse Server: Cloud function validator bypass via prototype chain traversal | Exploitation statusNot known exploited | FixYes | Published03/31/2026 | SeverityCritical |
|---|
CVE-2026-34373Parse Server: GraphQL API endpoint ignores CORS origin restriction | Exploitation statusNot known exploited | FixYes | Published03/31/2026 | SeverityMedium |
|---|
CVE-2026-34363Parse Server: LiveQuery protected field leak via shared mutable state across concurrent subscribers | Exploitation statusNot known exploited | FixYes | Published03/31/2026 | SeverityHigh |
|---|
CVE-2026-34224Parse Server: MFA single-use token bypass via concurrent authData login requests | Exploitation statusNot known exploited | FixYes | Published03/31/2026 | SeverityLow |
|---|
CVE-2026-33627Parse Server: Auth data exposed via /users/me endpoint | Exploitation statusNot known exploited | FixYes | Published03/24/2026 | SeverityHigh |
|---|
CVE-2026-33624Parse Server: MFA recovery code single-use bypass via concurrent requests | Exploitation statusNot known exploited | FixYes | Published03/24/2026 | SeverityLow |
|---|
CVE-2026-33539Parse Server: SQL injection via aggregate and distinct field names in PostgreSQL adapter | Exploitation statusNot known exploited | FixYes | Published03/24/2026 | SeverityHigh |
|---|
CVE-2026-33538Parse Server: Denial of service via unindexed database query for unconfigured auth providers | Exploitation statusNot known exploited | FixYes | Published03/24/2026 | SeverityHigh |
|---|
CVE-2026-33527Parse Server: Session update endpoint allows overwriting server-generated session fields | Exploitation statusNot known exploited | FixYes | Published03/24/2026 | SeverityMedium |
|---|
CVE-2026-33508Parse Server: LiveQuery subscription query depth bypass | Exploitation statusNot known exploited | FixYes | Published03/24/2026 | SeverityHigh |
|---|
CVE-2026-33498Parse Server: Query condition depth bypass via pre-validation transform pipeline | Exploitation statusNot known exploited | FixYes | Published03/24/2026 | SeverityHigh |
|---|
CVE-2026-33429Parse Server: Protected field change detection oracle via LiveQuery watch parameter | Exploitation statusNot known exploited | FixYes | Published03/24/2026 | SeverityMedium |
|---|
CVE-2026-33421Parse Server: LiveQuery bypasses CLP pointer permission enforcement | Exploitation statusNot known exploited | FixYes | Published03/24/2026 | SeverityHigh |
|---|
CVE-2026-33409Parse Server: Auth provider validation bypass on login via partial authData | Exploitation statusNot known exploited | FixYes | Published03/24/2026 | SeverityHigh |
|---|
CVE-2026-33323Parse Server: Email verification resend page leaks user existence | Exploitation statusNot known exploited | FixYes | Published03/24/2026 | SeverityMedium |
|---|
CVE-2026-33163Parse Server leaks protected fields via LiveQuery afterEvent trigger | Exploitation statusNot known exploited | FixNot confirmed | Published03/18/2026 | SeverityHigh |
|---|
CVE-2026-33042Parse Server affected by empty authData bypassing credential requirement on signup | Exploitation statusNot known exploited | FixNot confirmed | Published03/18/2026 | SeverityMedium |
|---|
CVE-2026-32944Parse Server crash via deeply nested query condition operators | Exploitation statusNot known exploited | FixNot confirmed | Published03/18/2026 | SeverityHigh |
|---|
CVE-2026-32943Parse Server has a password reset token single-use bypass via concurrent requests | Exploitation statusNot known exploited | FixNot confirmed | Published03/18/2026 | SeverityLow |
|---|
CVE-2026-32886Parse Server's Cloud function dispatch crashes server via prototype chain traversal | Exploitation statusNot known exploited | FixNot confirmed | Published03/18/2026 | SeverityHigh |
|---|
CVE-2026-32878Parse Server vulnerable to schema poisoning via prototype pollution in deep copy | Exploitation statusNot known exploited | FixNot confirmed | Published03/18/2026 | SeverityMedium |
|---|
CVE-2026-32770Parse Server: LiveQuery subscription with invalid regular expression crashes server | Exploitation statusNot known exploited | FixNot confirmed | Published03/18/2026 | SeverityMedium |
|---|
CVE-2026-32742Parse Server session creation endpoint allows overwriting server-generated session fields | Exploitation statusNot known exploited | FixNot confirmed | Published03/18/2026 | SeverityMedium |
|---|
CVE-2026-32728Parse Server has a stored XSS filter bypass via Content-Type MIME parameter and missing XML extension blocklist entries | Exploitation statusNot known exploited | FixNot confirmed | Published03/18/2026 | SeverityHigh |
|---|
CVE-2026-32594Parse Server GraphQL WebSocket endpoint bypasses security middleware | Exploitation statusNot known exploited | FixYes | Published03/13/2026 | SeverityMedium |
|---|
CVE-2026-32269Parse Server OAuth2 adapter app ID validation sends wrong token to introspection endpoint | Exploitation statusNot known exploited | FixYes | Published03/12/2026 | SeverityMedium |
|---|
CVE-2026-32248Parse Server: Account takeover via operator injection in authentication data identifier | Exploitation statusNot known exploited | FixYes | Published03/12/2026 | SeverityCritical |
|---|
CVE-2026-32242Parse Server OAuth2 adapter shares mutable state across providers via singleton instance | Exploitation statusNot known exploited | FixYes | Published03/12/2026 | SeverityCritical |
|---|
CVE-2026-32234Parse Server has a SQL injection via query field name when using PostgreSQL | Exploitation statusNot known exploited | FixYes | Published03/11/2026 | SeverityMedium |
|---|
CVE-2026-32098Parse Server has a protected fields bypass via LiveQuery subscription WHERE clause | Exploitation statusNot known exploited | FixYes | Published03/11/2026 | SeverityMedium |
|---|
CVE-2026-31901Parse Server has user enumeration via email verification endpoint | Exploitation statusNot known exploited | FixYes | Published03/11/2026 | SeverityMedium |
|---|
CVE-2026-31875Parse Server MFA recovery codes not consumed after use | Exploitation statusNot known exploited | FixYes | Published03/11/2026 | SeverityHigh |
|---|
CVE-2026-31872Parse Server has a protected fields bypass via dot-notation in query and sort | Exploitation statusNot known exploited | FixYes | Published03/11/2026 | SeverityHigh |
|---|
CVE-2026-31871Parse Server has a SQL Injection via dot-notation sub-key name in `Increment` operation on PostgreSQL | Exploitation statusNot known exploited | FixYes | Published03/11/2026 | SeverityCritical |
|---|
CVE-2026-31868Parse Server has Stored XSS via file upload of HTML-renderable file types | Exploitation statusNot known exploited | FixYes | Published03/11/2026 | SeverityMedium |
|---|
CVE-2026-31856Parse Server has a SQL injection via `Increment` operation on nested object field in PostgreSQL | Exploitation statusNot known exploited | FixYes | Published03/11/2026 | SeverityCritical |
|---|
CVE-2026-31840Parse Server has a SQL injection via dot-notation field name in PostgreSQL | Exploitation statusNot known exploited | FixYes | Published03/11/2026 | SeverityCritical |
|---|
CVE-2026-31828Parse Server has an LDAP injection via unsanitized user input in DN and group filter construction | Exploitation statusNot known exploited | FixYes | Published03/10/2026 | SeverityMedium |
|---|
CVE-2026-31800Parse Server: Classes `_GraphQLConfig` and `_Audience` master key bypass via generic class routes | Exploitation statusNot known exploited | FixYes | Published03/10/2026 | SeverityHigh |
|---|
CVE-2026-30972Parse Server has a rate limit bypass via batch request endpoint | Exploitation statusNot known exploited | FixYes | Published03/10/2026 | SeverityMedium |
|---|
CVE-2026-30967Parse Server OAuth2 authentication adapter account takeover via identity spoofing | Exploitation statusNot known exploited | FixYes | Published03/10/2026 | SeverityHigh |
|---|
CVE-2026-30966Parse Server role escalation and CLP bypass via direct `_Join` table write | Exploitation statusNot known exploited | FixYes | Published03/10/2026 | SeverityCritical |
|---|
CVE-2026-30965Parse Server session token exfiltration via `redirectClassNameForKey` query parameter | Exploitation statusNot known exploited | FixYes | Published03/10/2026 | SeverityCritical |
|---|
CVE-2026-30962Parse Server has a protected fields bypass via logical query operators | Exploitation statusNot known exploited | FixYes | Published03/10/2026 | SeverityHigh |
|---|
CVE-2026-30949Parse Server is missing audience validation in Keycloak authentication adapter | Exploitation statusNot known exploited | FixYes | Published03/10/2026 | SeverityHigh |
|---|
CVE-2026-30948Parse Server has stored cross-site scripting (XSS) via SVG file upload | Exploitation statusNot known exploited | FixYes | Published03/10/2026 | SeverityHigh |
|---|
CVE-2026-30947Parse Server ha a bypass of class-level permissions in LiveQuery | Exploitation statusNot known exploited | FixYes | Published03/10/2026 | SeverityHigh |
|---|
CVE-2026-30946Parse Server affected by denial-of-service via unbounded query complexity in REST and GraphQL API | Exploitation statusNot known exploited | FixYes | Published03/10/2026 | SeverityHigh |
|---|
CVE-2026-30941Parse Server has a NoSQL injection via token type in password reset and email verification endpoints | Exploitation statusNot known exploited | FixYes | Published03/10/2026 | SeverityHigh |
|---|
CVE-2026-30939Parse Server has Denial of Service (DoS) and Cloud Function Dispatch Bypass via Prototype Chain Resolution | Exploitation statusNot known exploited | FixYes | Published03/10/2026 | SeverityHigh |
|---|
CVE-2026-30938Parse Server has denylist `requestKeywordDenylist` keyword scan bypass through nested object placement | Exploitation statusNot known exploited | FixYes | Published03/10/2026 | SeverityMedium |
|---|
CVE-2026-30925Parse Server affected by Regular Expression Denial of Service (ReDoS) via `$regex` query in LiveQuery | Exploitation statusNot known exploited | FixYes | Published03/09/2026 | SeverityHigh |
|---|
CVE-2026-30854Parse Server: GraphQL `__type` introspection bypass via inline fragments when public introspection is disabled | Exploitation statusNot known exploited | FixYes | Published03/07/2026 | SeverityMedium |
|---|
CVE-2026-30850Parse Server: File metadata endpoint bypasses `beforeFind` / `afterFind` trigger authorization | Exploitation statusNot known exploited | FixYes | Published03/07/2026 | SeverityMedium |
|---|
CVE-2026-30848Parse Server: `PagesRouter` path traversal allows reading files outside configured pages directory | Exploitation statusNot known exploited | FixYes | Published03/07/2026 | SeverityMedium |
|---|
CVE-2026-30863Parse Server: JWT audience validation bypass in Google, Apple, and Facebook authentication adapters | Exploitation statusNot known exploited | FixYes | Published03/07/2026 | SeverityCritical |
|---|
CVE-2026-30835Parse Server: Malformed `$regex` query leaks database error details in API response | Exploitation statusNot known exploited | FixYes | Published03/06/2026 | SeverityMedium |
|---|
CVE-2026-30229Parse Server: Endpoint `/loginAs` allows `readOnlyMasterKey` to gain full read and write access as any user | Exploitation statusNot known exploited | FixYes | Published03/06/2026 | SeverityHigh |
|---|
CVE-2026-30228Parse Server: File creation and deletion bypasses `readOnlyMasterKey` write restriction | Exploitation statusNot known exploited | FixYes | Published03/06/2026 | SeverityMedium |
|---|
CVE-2026-29182Parse Server: Cloud Hooks and Cloud Jobs bypass `readOnlyMasterKey` write restriction | Exploitation statusNot known exploited | FixYes | Published03/06/2026 | SeverityHigh |
|---|
CVE-2026-27804Parse Server: Account takeover via JWT algorithm confusion in Google auth adapter | Exploitation statusNot known exploited | FixNot confirmed | Published02/25/2026 | SeverityCritical |
|---|
CVE-2025-68150Parse Server has Server-Side Request Forgery (SSRF) in Instagram OAuth Adapter | Exploitation statusNot known exploited | FixYes | Published12/16/2025 | SeverityHigh |
|---|
CVE-2025-68115Parse Server vulnerable to Cross-Site Scripting (XSS) via Unescaped Mustache Template Variables | Exploitation statusNot known exploited | FixNot confirmed | Published12/16/2025 | SeverityMedium |
|---|
CVE-2025-67727Parse Server GitHub CI workflow vulnerable to RCE through Improper Privilege Management | Exploitation statusNot known exploited | FixNot confirmed | Published12/12/2025 | SeverityMedium |
|---|
CVE-2025-64502Parse Server allows public `explain` queries which may expose sensitive database performance information and schema details | Exploitation statusNot known exploited | FixNot confirmed | Published11/10/2025 | SeverityMedium |
|---|
CVE-2025-64430Parse Server Vulnerable to Server-Side Request Forgery (SSRF) in File Upload via URI Format | Exploitation statusNot known exploited | FixYes | Published11/07/2025 | SeverityHigh |
|---|
CVE-2025-53364Parse Server exposes the data schema via GraphQL API | Exploitation statusNot known exploited | FixYes | Published07/10/2025 | SeverityMedium |
|---|
CVE-2025-30168Parse Server has an OAuth login vulnerability | Exploitation statusNot known exploited | FixYes | Published03/21/2025 | SeverityMedium |
|---|
CVE-2024-47183Parse Server's custom object ID allows to acquire role privileges | Exploitation statusPublic exploit | FixYes | Published10/04/2024 | SeverityHigh |
|---|
CVE-2024-39309ZDI-CAN-23894: Parse Server literalizeRegexPart SQL Injection Authentication Bypass Vulnerability | Exploitation statusNot known exploited | FixNot confirmed | Published07/01/2024 | SeverityCritical |
|---|
CVE-2024-29027Parse Server crash and RCE via invalid Cloud Function or Cloud Job name | Exploitation statusNot known exploited | FixNot confirmed | Published03/19/2024 | SeverityCritical |
|---|
CVE-2024-27298Parse Server literalizeRegexPart SQL Injection | Exploitation statusPublic exploit | FixYes | Published03/01/2024 | SeverityCritical |
|---|
CVE-2023-46119Parse Server may crash when uploading file without extension | Exploitation statusNot known exploited | FixYes | Published10/25/2023 | SeverityHigh |
|---|
CVE-2023-41058Trigger `beforeFind` not invoked in internal query pipeline in parse-server | Exploitation statusNot known exploited | FixYes | Published09/04/2023 | SeverityHigh |
|---|
CVE-2023-36475Parse Server vulnerable to remote code execution via MongoDB BSON parser through prototype pollution | Exploitation statusNot known exploited | FixYes | Published06/28/2023 | SeverityCritical |
|---|