CVE-2026-27804
- EPSS 0.04%
- Veröffentlicht 25.02.2026 23:48:20
- Zuletzt bearbeitet 04.03.2026 03:09:41
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.3 and 9.1.1-alpha.4, an unauthenticated attacker can forge a Google authentication token with `alg: "none"` to log in as any...
CVE-2025-68150
- EPSS 0.1%
- Veröffentlicht 16.12.2025 18:15:09
- Zuletzt bearbeitet 02.01.2026 16:39:47
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.2 and 9.1.1-alpha.1, the Instagram authentication adapter allows clients to specify a custom API URL via the `apiURL` parame...
CVE-2025-68115
- EPSS 0.04%
- Veröffentlicht 16.12.2025 00:56:23
- Zuletzt bearbeitet 02.01.2026 16:49:12
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions prior to 8.6.1 and 9.1.0-alpha.3, a Reflected Cross-Site Scripting (XSS) vulnerability exists in Parse Server's password reset and ema...
CVE-2025-67727
- EPSS 0.07%
- Veröffentlicht 12.12.2025 06:35:52
- Zuletzt bearbeitet 22.12.2025 18:59:23
Parse Server is an open source backend that can be deployed to any infrastructure that runs Node.js. In versions prior to 8.6.0-alpha.2, a GitHub CI workflow is triggered in a way that grants the GitHub Actions workflow elevated permissions, giving i...
CVE-2024-47183
- EPSS 0.38%
- Veröffentlicht 04.10.2024 15:15:13
- Zuletzt bearbeitet 25.02.2026 17:47:53
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. If the Parse Server option allowCustomObjectId: true is set, an attacker that is allowed to create a new user can set a custom object ID for that ...
- EPSS 1.9%
- Veröffentlicht 19.03.2024 19:15:06
- Zuletzt bearbeitet 17.12.2025 21:33:11
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 6.5.5 and 7.0.0-alpha.29, calling an invalid Parse Server Cloud Function name or Cloud Job name crashes the server and may allow...
- EPSS 0.31%
- Veröffentlicht 01.03.2024 18:15:28
- Zuletzt bearbeitet 03.12.2025 20:52:52
parse-server is a Parse Server for Node.js / Express. This vulnerability allows SQL injection when Parse Server is configured to use the PostgreSQL database. The vulnerability has been fixed in 6.5.0 and 7.0.0-alpha.20.
CVE-2023-46119
- EPSS 0.57%
- Veröffentlicht 25.10.2023 18:17:36
- Zuletzt bearbeitet 21.11.2024 08:27:55
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Parse Server crashes when uploading a file without extension. This vulnerability has been patched in versions 5.5.6 and 6.3.1.
CVE-2023-41058
- EPSS 0.21%
- Veröffentlicht 04.09.2023 23:15:47
- Zuletzt bearbeitet 21.11.2024 08:20:28
Parse Server is an open source backend server. In affected versions the Parse Cloud trigger `beforeFind` is not invoked in certain conditions of `Parse.Query`. This can pose a vulnerability for deployments where the `beforeFind` trigger is used as a ...
CVE-2023-36475
- EPSS 7.55%
- Veröffentlicht 28.06.2023 23:15:21
- Zuletzt bearbeitet 21.11.2024 08:09:47
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 5.5.2 and 6.2.1, an attacker can use a prototype pollution sink to trigger a remote code execution through the MongoDB BSON pars...