Where
-Infinity
0

npm/parse-serverParse Server: Relation `$relatedTo` query bypasses `protectedFields` and owning-object ACL

Risk 33
Severity
6.9
First published (updated )

npm/parse-serverParse Server: Server option routeAllowList is bypassable through batch sub-requests

Risk 41
Severity
6.9
First published (updated )

🚨 14 npm/PyPI/AI Supply-Chain Threats Today (2026-05-26): Critical Worms, Parse Server DoS, and AI RCEs

First published (updated )
Social
reddit

npm/parse-serverParse Server: Streaming file download bypasses afterFind file trigger authorization

Risk 43
Severity
8.2
First published (updated )

parseplatform Parse-server Node.jsParse Server: LiveQuery protected-field guard bypass via array-like logical operator value

Risk 26
Severity
5.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

parseplatform Parse-server Node.jsParse Server: GraphQL complexity validator exponential fragment traversal DoS

Risk 43
Severity
8.2
First published (updated )

parseplatform Parse-server Node.jsParse Server: Cloud function validator bypass via prototype chain traversal

Risk 63
Severity
9.1
First published (updated )

parseplatform Parse-server Node.jsParse Server: Auth data exposed via /users/me endpoint

Risk 29
Severity
7.1
EPSS
0.06%
First published (updated )

parseplatform Parse-server Node.jsParse Server: MFA recovery code single-use bypass via concurrent requests

Risk 12
Severity
2.1
EPSS
0.03%
First published (updated )

parseplatform Parse-server Node.jsParse Server has a password reset token single-use bypass via concurrent requests

Risk 13
Severity
2.3
EPSS
0.03%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

parseplatform Parse-server Node.jsParse Server GraphQL WebSocket endpoint bypasses security middleware

Risk 36
Severity
6.9
EPSS
0.08%
First published (updated )

parseplatform Parse-server Node.jsParse Server OAuth2 adapter app ID validation sends wrong token to introspection endpoint

Risk 28
Severity
6.5
EPSS
0.05%
First published (updated )

parseplatform Parse-server Node.jsParse Server has a SQL injection via query field name when using PostgreSQL

Risk 28
Severity
5.1
EPSS
0.04%
First published (updated )

parseplatform Parse-server Node.jsParse Server has a protected fields bypass via LiveQuery subscription WHERE clause

Risk 31
Severity
6.9
EPSS
0.04%
First published (updated )

parseplatform Parse-server Node.jsParse Server has an LDAP injection via unsanitized user input in DN and group filter construction

Risk 56
Severity
6
EPSS
0.09%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

parseplatform Parse-server Node.jsParse Server: Classes `_GraphQLConfig` and `_Audience` master key bypass via generic class routes

Risk 47
Severity
8.8
EPSS
0.09%
First published (updated )

parseplatform Parse-server Node.jsParse Server has a rate limit bypass via batch request endpoint

Risk 31
Severity
7.5
EPSS
0.05%
First published (updated )

parseplatform Parse-server Node.jsParse Server role escalation and CLP bypass via direct `_Join` table write

Risk 58
Severity
10
EPSS
0.06%
First published (updated )

parseplatform Parse-server Node.jsParse Server session token exfiltration via `redirectClassNameForKey` query parameter

Risk 49
Severity
9.9
EPSS
0.06%
First published (updated )

parseplatform Parse-server Node.jsParse Server has a protected fields bypass via logical query operators

Risk 29
Severity
7.1
EPSS
0.03%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

parseplatform Parse-server Node.jsParse Server is missing audience validation in Keycloak authentication adapter

Risk 41
Severity
8.8
EPSS
0.03%
First published (updated )

parseplatform Parse-server Node.jsParse Server has stored cross-site scripting (XSS) via SVG file upload

Risk 45
Severity
8.3
EPSS
0.02%
First published (updated )

npm/parse-serverParse Server ha a bypass of class-level permissions in LiveQuery

Risk 33
Severity
8.7
EPSS
0.02%
First published (updated )

npm/parse-serverParse Server affected by denial-of-service via unbounded query complexity in REST and GraphQL API

Risk 33
Severity
8.7
EPSS
0.02%
First published (updated )

npm/parse-serverParse Server has a NoSQL injection via token type in password reset and email verification endpoints

Risk 33
Severity
8.7
EPSS
0.05%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

parseplatform Parse-server Node.jsParse Server affected by Regular Expression Denial of Service (ReDoS) via `$regex` query in LiveQuery

Risk 31
Severity
8.2
EPSS
0.02%
First published (updated )

parseplatform Parse-server Node.jsParse Server: GraphQL `__type` introspection bypass via inline fragments when public introspection is disabled

Risk 23
Severity
6.9
EPSS
0.06%
First published (updated )

parseplatform Parse-server Node.jsParse Server: File metadata endpoint bypasses `beforeFind` / `afterFind` trigger authorization

Risk 21
Severity
6.3
EPSS
0.05%
First published (updated )

parseplatform Parse-server Node.jsParse Server: `PagesRouter` path traversal allows reading files outside configured pages directory

Risk 21
Severity
6.3
EPSS
0.07%
First published (updated )

parseplatform Parse-server Node.jsParse Server: JWT audience validation bypass in Google, Apple, and Facebook authentication adapters

Risk 61
Severity
9.8
EPSS
0.08%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203