Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Parseplatform

First CVE: Jul 29, 2019Active for: 7 yearsTotal CVEs: 108
43.1
VTI Score
High

Parse Platform maintains a focused backend-as-a-service framework and related tooling that, despite a narrow product roster, occupies a prominent position in the vulnerability landscape due to the security-critical role of backend infrastructure and data management. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and concentrate in foundational components such as Parse Server, Parse Dashboard, and the JavaScript SDK, reflecting the exposure inherent to authentication, authorization, and data-access layers. The recurring weakness classes—including incorrect authorization, improper authentication, prototype pollution, sensitive information exposure, and SQL injection—underscore the persistent challenge of securing object-oriented backends against access-control bypasses and injection attacks that can directly compromise application data and user trust. Defenders deploying Parse Platform should prioritize security updates for server-side components and treat access-control and authentication disclosures as high-urgency; live exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
108
Total CVEs
More Total CVEs than 99% of tracked vendors
3.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 50% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Parseplatform over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 29, 2019
6 years ago
Most Recent CVE
May 12, 2026
74 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (108 CVEs).

108 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-24760CRITICAL
Parse Server is an open source http web server backend. In versions prior to 4.10.7 there is a Remote Code Execution (RCE) vulnerability in Parse Server. This vulnerability affects
Mar 12, 202210.060NONO
CVE-2022-39396CRITICAL
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Versions prior to 4.10.18, and prior to 5.3.1 on the 5.X branch, are vulnera
Nov 10, 20229.852NONO
CVE-2026-34532CRITICAL
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.67 and 9.7.0-alpha.11, an attacker can bypass Cloud Fu
Mar 31, 20269.133NONO
CVE-2026-32248CRITICAL
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.12 and 8.6.38, an unauthenticated attacker can take ove
Mar 12, 20269.832NONO
CVE-2026-30863CRITICAL
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.10 and 9.5.0-alpha.11, the Google, Apple, and Facebook
Mar 7, 20269.832NONO
CVE-2026-34373HIGH
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.66 and 9.7.0-alpha.10, the GraphQL API endpoint does n
Mar 31, 20268.831NONO
CVE-2026-31871CRITICAL
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.5 and 8.6.31, a SQL injection vulnerability exists in t
Mar 11, 20269.831NONO
CVE-2026-31856CRITICAL
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. A SQL injection vulnerability exists in the PostgreSQL storage adapter when
Mar 11, 20269.831NONO
CVE-2026-31840CRITICAL
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.2 and 8.6.28, an attacker can use a dot-notation field
Mar 11, 20269.831NONO
CVE-2025-67727CRITICAL
Parse Server is an open source backend that can be deployed to any infrastructure that runs Node.js. In versions prior to 8.6.0-alpha.2, a GitHub CI workflow is triggered in a way
Dec 12, 20259.831NONO
View all 108 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products108 CVEs
37%
40%
18%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network108 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low95 (88.0%)
High13 (12.0%)
Unknown0 (0.0%)
User Interaction
None100 (92.6%)
Unknown0 (0.0%)
Required8 (7.4%)
Privileges Required
Low28 (25.9%)
High7 (6.5%)
None73 (67.6%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (108 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Parseplatform.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Parseplatform — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Parseplatform's Products

View all 3 CNAs →

Top CWEs