Technology · npm
parse-server (npm) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 42 vulnerabilities in parse-server (npm): 0 in the last 7 days and 7 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-66009, was published on 24 July 2026.
- Last 7 days
- 0
- Last 90 days
- 7
- Critical, all time
- 1
- Exploited in the wild
- 0
About parse-server (npm)
An open-source backend framework that can be deployed to any infrastructure that can run Node.js.
Latest parse-server (npm) vulnerabilities
- CVE-2026-66009: Parse Community Parse Server information disclosure in GraphQL error messagesinfoCVSS 6.3
- CVE-2026-66008: Parse Community Parse Server information disclosure in GraphQL error messagesinfoCVSS 6.3
- CVE-2026-64627: Parse Community Parse Server schema disclosure in GraphQL variable coercioninfoCVSS 6.9
- CVE-2026-61448: Parse Server stored XSS via malformed Content-Type bypassinfoCVSS 2.1
- CVE-2026-57481: Parse Server information disclosure in LiveQuery ACL transitionsmediumCVSS 4EPSS 0.5%
- CVE-2026-57480: Parse Community Parse Server denial of service via nested query operatorsmediumCVSS 4EPSS 0.6%
- CVE-2026-55778: Parse Server stored XSS via file upload extension bypassmediumCVSS 4EPSS 0.5%
- CVE-2021-47987: Parse Community Parse Server supply chain compromise via incorrect Git tagshighCVSS 7.5
- Parse Server information disclosure in LiveQuery ACL changeslowCVSS 2.3
- Parse Server denial of service via nested query operatorshighCVSS 8.7
- CVE-2026-53726: Parse Server authorization bypass in $relatedTo queriesmediumCVSS 4EPSS 0.5%
- CVE-2026-53725: Parse Server MFA secret disclosure in login and verifyPassword endpointsmediumCVSS 4EPSS 0.4%
- CVE-2026-53724: Parse Server stored XSS via trailing dot filename bypassmediumCVSS 4EPSS 0.5%
- CVE-2026-50008: Parse Server authorization bypass via batch sub-requestsmediumCVSS 4EPSS 0.6%
- CVE-2026-47248: Parse Server schema disclosure via GraphQL error suggestionsmediumCVSS 4EPSS 0.5%
- CVE-2026-43930: Parse Platform Parse Server race condition in SMS MFA loginmediumCVSS 5.9EPSS 0.3%
- CVE-2026-39321: Parse Community Parse Server timing side-channel in login endpointlowCVSS 3.7EPSS 0.4%
- CVE-2026-39381: Parse Community Parse Server information exposure in sessions/me endpointmediumCVSS 4.3EPSS 0.3%
- CVE-2026-35200: Parse Server stored XSS via Content-Type mismatch in file uploadsmediumCVSS 5.4EPSS 0.3%
- CVE-2026-34784: Parse Platform Parse Server authorization bypass via HTTP Range requestshighCVSS 7.5EPSS 0.5%
- CVE-2026-34215: Parse Platform Parse Server sensitive information exposure in verify password endpointmediumCVSS 6.5EPSS 0.5%
- CVE-2026-34595: Parse Community Parse Server type confusion in LiveQuery protectedFieldsmediumCVSS 4.3EPSS 0.4%
- CVE-2026-34574: Parse Platform Parse Server session immutability bypassmediumCVSS 5.4EPSS 0.3%
- CVE-2026-34573: Parse Community Parse Server DoS in GraphQL complexity validatorhighCVSS 7.5EPSS 0.9%
- CVE-2026-34532: Parse Community Parse Server auth bypass in Cloud FunctionscriticalCVSS 9.1EPSS 0.5%
Most severe parse-server (npm) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-34532: Parse Community Parse Server auth bypass in Cloud FunctionscriticalCVSS 9.1EPSS 0.5%
- CVE-2026-34373: Parse Platform Parse Server origin validation bypass in GraphQL APIhighCVSS 8.8EPSS 0.2%
- Parse Server denial of service via nested query operatorshighCVSS 8.7
- CVE-2026-34573: Parse Community Parse Server DoS in GraphQL complexity validatorhighCVSS 7.5EPSS 0.9%
- CVE-2026-34784: Parse Platform Parse Server authorization bypass via HTTP Range requestshighCVSS 7.5EPSS 0.5%
- CVE-2021-47987: Parse Community Parse Server supply chain compromise via incorrect Git tagshighCVSS 7.5
- CVE-2026-34215: Parse Platform Parse Server sensitive information exposure in verify password endpointmediumCVSS 6.5EPSS 0.5%
- CVE-2026-43930: Parse Platform Parse Server race condition in SMS MFA loginmediumCVSS 5.9EPSS 0.3%
- CVE-2026-34574: Parse Platform Parse Server session immutability bypassmediumCVSS 5.4EPSS 0.3%
- CVE-2026-35200: Parse Server stored XSS via Content-Type mismatch in file uploadsmediumCVSS 5.4EPSS 0.3%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 4 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 3 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/parse-server.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "parse-server (npm) vulnerabilities", https://junglewise.ai/threats/technologies/parse-server, 26 September 2026.