📦 Parse Server

by Parseplatform

🔍 What is Parse Server?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-67727

CRITICAL CVSS 9.8 Dec 12, 2025

This CVE describes a GitHub Actions workflow vulnerability in Parse Server that grants elevated permissions to CI/CD pipelines. It allows unauthorized access to GitHub secrets and write permissions, p...

CVE-2024-27298

CRITICAL CVSS 10.0 Mar 1, 2024

This SQL injection vulnerability in parse-server allows attackers to execute arbitrary SQL commands when the server is configured with PostgreSQL. It affects all parse-server deployments using Postgre...

CVE-2023-36475

CRITICAL CVSS 9.8 Jun 28, 2023

This vulnerability in Parse Server allows attackers to perform prototype pollution attacks that can lead to remote code execution through the MongoDB BSON parser. Any Parse Server deployment prior to ...

CVE-2022-24760

CRITICAL CVSS 10.0 Mar 12, 2022

CVE-2022-24760 is a critical Remote Code Execution vulnerability in Parse Server caused by prototype pollution in DatabaseController.js. It allows attackers to execute arbitrary code on affected serve...

CVE-2024-47183

HIGH CVSS 8.1 Oct 4, 2024

Parse Server versions before 6.5.9 and 7.3.0 with allowCustomObjectId enabled are vulnerable to privilege escalation. An attacker who can create new users can set custom object IDs to gain unauthorize...

CVE-2023-46119

HIGH CVSS 7.5 Oct 25, 2023

Parse Server crashes when processing file uploads without file extensions, causing denial of service. This affects all Parse Server deployments running vulnerable versions, potentially disrupting back...

CVE-2023-41058

HIGH CVSS 7.5 Sep 4, 2023

Parse Server deployments using the beforeFind Cloud Code trigger as a security layer are vulnerable to query manipulation bypass. This allows attackers to potentially access data they shouldn't have p...

CVE-2023-22474

HIGH CVSS 8.7 Feb 3, 2023

Parse Server versions before 5.4.1 incorrectly trust the x-forwarded-for header to determine client IP addresses when not behind a proxy. This allows attackers to spoof their IP address, potentially b...

CVE-2022-31112

HIGH CVSS 8.2 Jun 30, 2022

Parse Server LiveQuery improperly exposes protected fields to clients, allowing unauthorized access to sensitive data. This affects all Parse Server deployments using LiveQuery functionality with prot...

CVE-2022-31089

HIGH CVSS 7.5 Jun 27, 2022

Parse Server versions before 4.10.12 and 5.2.3 crash when processing certain invalid file requests, causing denial of service. This affects all Parse Server deployments, with single-instance deploymen...

CVE-2022-31083

HIGH CVSS 8.6 Jun 17, 2022

Parse Server's Apple Game Center authentication adapter had a certificate validation flaw that allowed attackers to bypass authentication by providing a fake certificate URL. This affects all Parse Se...

CVE-2022-24901

HIGH CVSS 7.5 May 4, 2022

This vulnerability allows attackers to bypass authentication in Parse Server's Apple Game Center adapter by exploiting improper URL validation of Apple certificates. Attackers can potentially gain una...

CVE-2021-41109

HIGH CVSS 7.5 Sep 30, 2021

Parse Server versions before 4.10.4 expose user session tokens in LiveQuery payloads when users subscribe to Parse.User class updates. This allows attackers to capture session tokens during user sign-...

CVE-2025-68150

MEDIUM CVSS 6.5 Dec 16, 2025

Parse Server's Instagram authentication adapter allows attackers to specify custom API URLs, enabling Server-Side Request Forgery (SSRF) attacks. This could lead to authentication bypass if malicious ...

CVE-2025-68115

MEDIUM CVSS 6.1 Dec 16, 2025

Parse Server versions before 8.6.1 and 9.1.0-alpha.3 contain a reflected cross-site scripting (XSS) vulnerability in password reset and email verification pages. Attackers can inject malicious scripts...