Parseplatform

Parse-server

100 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.05%
  • Veröffentlicht 11.03.2026 18:02:57
  • Zuletzt bearbeitet 13.03.2026 18:24:36

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.6 and 8.6.32, the protectedFields class-level permission (CLP) can be bypassed using dot-notation in query WHERE clauses and ...

  • EPSS 0.04%
  • Veröffentlicht 11.03.2026 18:01:16
  • Zuletzt bearbeitet 13.03.2026 18:24:50

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.5 and 8.6.31, a SQL injection vulnerability exists in the PostgreSQL storage adapter when processing Increment operations on ...

  • EPSS 0.06%
  • Veröffentlicht 11.03.2026 17:54:33
  • Zuletzt bearbeitet 13.03.2026 18:25:43

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.4 and 8.6.30, an attacker can upload a file with a file extension or content type that is not blocked by the default configur...

  • EPSS 0.07%
  • Veröffentlicht 11.03.2026 17:16:58
  • Zuletzt bearbeitet 13.03.2026 18:54:46

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.2 and 8.6.28, an attacker can use a dot-notation field name in combination with the sort query parameter to inject SQL into t...

  • EPSS 0.04%
  • Veröffentlicht 11.03.2026 17:14:16
  • Zuletzt bearbeitet 13.03.2026 18:54:26

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. A SQL injection vulnerability exists in the PostgreSQL storage adapter when processing Increment operations on nested object fields using dot nota...

  • EPSS 0.14%
  • Veröffentlicht 10.03.2026 21:41:48
  • Zuletzt bearbeitet 11.03.2026 14:28:08

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.13 and 8.6.26, the LDAP authentication adapter is vulnerable to LDAP injection. User-supplied input (authData.id) is interpol...

  • EPSS 0.1%
  • Veröffentlicht 10.03.2026 20:51:14
  • Zuletzt bearbeitet 11.03.2026 18:30:54

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.12 and 8.6.25, the _GraphQLConfig and _Audience internal classes can be read, modified, and deleted via the generic /classes/...

  • EPSS 0.06%
  • Veröffentlicht 10.03.2026 20:48:47
  • Zuletzt bearbeitet 11.03.2026 18:42:38

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior o 9.5.2-alpha.10 and 8.6.23, Parse Server's rate limiting middleware is applied at the Express middleware layer, but the batch request endpo...

  • EPSS 0.11%
  • Veröffentlicht 10.03.2026 20:46:40
  • Zuletzt bearbeitet 11.03.2026 19:04:03

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.9. and 8.6.22, the OAuth2 authentication adapter, when configured without the useridField option, only verifies that a token ...

  • EPSS 0.06%
  • Veröffentlicht 10.03.2026 20:45:15
  • Zuletzt bearbeitet 11.03.2026 19:50:29

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.7 and 8.6.20, Parse Server's internal tables, which store Relation field mappings such as role memberships, can be directly a...