CVE-2026-31872
- EPSS 0.05%
- Veröffentlicht 11.03.2026 18:02:57
- Zuletzt bearbeitet 13.03.2026 18:24:36
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.6 and 8.6.32, the protectedFields class-level permission (CLP) can be bypassed using dot-notation in query WHERE clauses and ...
CVE-2026-31871
- EPSS 0.04%
- Veröffentlicht 11.03.2026 18:01:16
- Zuletzt bearbeitet 13.03.2026 18:24:50
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.5 and 8.6.31, a SQL injection vulnerability exists in the PostgreSQL storage adapter when processing Increment operations on ...
CVE-2026-31868
- EPSS 0.06%
- Veröffentlicht 11.03.2026 17:54:33
- Zuletzt bearbeitet 13.03.2026 18:25:43
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.4 and 8.6.30, an attacker can upload a file with a file extension or content type that is not blocked by the default configur...
CVE-2026-31840
- EPSS 0.07%
- Veröffentlicht 11.03.2026 17:16:58
- Zuletzt bearbeitet 13.03.2026 18:54:46
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.2 and 8.6.28, an attacker can use a dot-notation field name in combination with the sort query parameter to inject SQL into t...
CVE-2026-31856
- EPSS 0.04%
- Veröffentlicht 11.03.2026 17:14:16
- Zuletzt bearbeitet 13.03.2026 18:54:26
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. A SQL injection vulnerability exists in the PostgreSQL storage adapter when processing Increment operations on nested object fields using dot nota...
CVE-2026-31828
- EPSS 0.14%
- Veröffentlicht 10.03.2026 21:41:48
- Zuletzt bearbeitet 11.03.2026 14:28:08
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.13 and 8.6.26, the LDAP authentication adapter is vulnerable to LDAP injection. User-supplied input (authData.id) is interpol...
CVE-2026-31800
- EPSS 0.1%
- Veröffentlicht 10.03.2026 20:51:14
- Zuletzt bearbeitet 11.03.2026 18:30:54
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.12 and 8.6.25, the _GraphQLConfig and _Audience internal classes can be read, modified, and deleted via the generic /classes/...
CVE-2026-30972
- EPSS 0.06%
- Veröffentlicht 10.03.2026 20:48:47
- Zuletzt bearbeitet 11.03.2026 18:42:38
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior o 9.5.2-alpha.10 and 8.6.23, Parse Server's rate limiting middleware is applied at the Express middleware layer, but the batch request endpo...
CVE-2026-30967
- EPSS 0.11%
- Veröffentlicht 10.03.2026 20:46:40
- Zuletzt bearbeitet 11.03.2026 19:04:03
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.9. and 8.6.22, the OAuth2 authentication adapter, when configured without the useridField option, only verifies that a token ...
- EPSS 0.06%
- Veröffentlicht 10.03.2026 20:45:15
- Zuletzt bearbeitet 11.03.2026 19:50:29
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.7 and 8.6.20, Parse Server's internal tables, which store Relation field mappings such as role memberships, can be directly a...