VYPR

Parse Server

by Parseplatform

Source repositories

CVEs (103)

  • CVE-2026-33624LowMar 24, 2026
    risk 0.11cvss 2.7epss 0.00

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.60 and 9.6.0-alpha.54, an attacker who obtains a user's password and a single MFA recovery code can reuse that recovery code an unlimited number of times…

  • CVE-2021-47986HigJun 25, 2026
    risk 0.00cvss 7.5epss 0.00

    Parse Server before 4.10.0 contains a supply chain vulnerability where incorrect version tags were pushed to the repository linking to unreviewed code in a personal fork. Attackers could exploit this by specifying affected version tags in dependency declarations to execute…

  • CVE-2025-67727CriDec 12, 2025
    risk 0.00cvss 9.8epss 0.00

    Parse Server is an open source backend that can be deployed to any infrastructure that runs Node.js. In versions prior to 8.6.0-alpha.2, a GitHub CI workflow is triggered in a way that grants the GitHub Actions workflow elevated permissions, giving it access to GitHub secrets…

Page 6 of 6