Parse Platform maintains a focused backend-as-a-service framework and related tooling that, despite a narrow product roster, occupies a prominent position in the vulnerability landscape due to the security-critical role of backend infrastructure and data management. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and concentrate in foundational components such as Parse Server, Parse Dashboard, and the JavaScript SDK, reflecting the exposure inherent to authentication, authorization, and data-access layers. The recurring weakness classes—including incorrect authorization, improper authentication, prototype pollution, sensitive information exposure, and SQL injection—underscore the persistent challenge of securing object-oriented backends against access-control bypasses and injection attacks that can directly compromise application data and user trust. Defenders deploying Parse Platform should prioritize security updates for server-side components and treat access-control and authentication disclosures as high-urgency; live exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Parseplatform over time
Signals from CVEs in this vendor scope (108 CVEs).
108 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-24760CRITICAL Parse Server is an open source http web server backend. In versions prior to 4.10.7 there is a Remote Code Execution (RCE) vulnerability in Parse Server. This vulnerability affects | Mar 12, 2022 | 10.0 | 60 | NO | NO |
CVE-2022-39396CRITICAL Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Versions prior to 4.10.18, and prior to 5.3.1 on the 5.X branch, are vulnera | Nov 10, 2022 | 9.8 | 52 | NO | NO |
CVE-2026-34532CRITICAL Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.67 and 9.7.0-alpha.11, an attacker can bypass Cloud Fu | Mar 31, 2026 | 9.1 | 33 | NO | NO |
CVE-2026-32248CRITICAL Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.12 and 8.6.38, an unauthenticated attacker can take ove | Mar 12, 2026 | 9.8 | 32 | NO | NO |
CVE-2026-30863CRITICAL Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.10 and 9.5.0-alpha.11, the Google, Apple, and Facebook | Mar 7, 2026 | 9.8 | 32 | NO | NO |
CVE-2026-34373HIGH Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.66 and 9.7.0-alpha.10, the GraphQL API endpoint does n | Mar 31, 2026 | 8.8 | 31 | NO | NO |
CVE-2026-31871CRITICAL Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.5 and 8.6.31, a SQL injection vulnerability exists in t | Mar 11, 2026 | 9.8 | 31 | NO | NO |
CVE-2026-31856CRITICAL Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. A SQL injection vulnerability exists in the PostgreSQL storage adapter when | Mar 11, 2026 | 9.8 | 31 | NO | NO |
CVE-2026-31840CRITICAL Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.2 and 8.6.28, an attacker can use a dot-notation field | Mar 11, 2026 | 9.8 | 31 | NO | NO |
CVE-2025-67727CRITICAL Parse Server is an open source backend that can be deployed to any infrastructure that runs Node.js. In versions prior to 8.6.0-alpha.2, a GitHub CI workflow is triggered in a way | Dec 12, 2025 | 9.8 | 31 | NO | NO |
Signals from CVEs in this vendor scope (108 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Parseplatform.
Media articles that mention a CVE ID that affects a product developed by Parseplatform — matched by CVE ID, not by vendor name.