Parse Server
Vendor:
First CVE: Jul 29, 2019 · Active for 6 years
102
Total CVEs
More Total CVEs than 99% of tracked products
12.8
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 42% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Parse Server over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 29, 2019
6 years ago
Most Recent CVE
May 12, 2026
73 days ago
CVE Severity & Scoring
Parse Server102 CVEs
36%
39%
19%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network102 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low90 (88.2%)
High12 (11.8%)
Unknown0 (0.0%)
User Interaction
None95 (93.1%)
Unknown0 (0.0%)
Required7 (6.9%)
Privileges Required
Low25 (24.5%)
High7 (6.9%)
None70 (68.6%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (102 CVEs).
102 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-24760CRITICAL Parse Server is an open source http web server backend. In versions prior to 4.10.7 there is a Remote Code Execution (RCE) vulnerability in Parse Server. This vulnerability affects | Mar 12, 2022 | 10.0 | 60 | NO | NO |
CVE-2022-39396CRITICAL Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Versions prior to 4.10.18, and prior to 5.3.1 on the 5.X branch, are vulnera | Nov 10, 2022 | 9.8 | 52 | NO | NO |
CVE-2026-32248CRITICAL Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.12 and 8.6.38, an unauthenticated attacker can take ove | Mar 12, 2026 | 9.8 | 32 | NO | NO |
CVE-2026-30863CRITICAL Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.10 and 9.5.0-alpha.11, the Google, Apple, and Facebook | Mar 7, 2026 | 9.8 | 32 | NO | NO |
CVE-2026-34532CRITICAL Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.67 and 9.7.0-alpha.11, an attacker can bypass Cloud Fu | Mar 31, 2026 | 9.1 | 31 | NO | NO |
CVE-2026-31871CRITICAL Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.5 and 8.6.31, a SQL injection vulnerability exists in t | Mar 11, 2026 | 9.8 | 31 | NO | NO |
CVE-2026-31856CRITICAL Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. A SQL injection vulnerability exists in the PostgreSQL storage adapter when | Mar 11, 2026 | 9.8 | 31 | NO | NO |
CVE-2026-31840CRITICAL Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.2 and 8.6.28, an attacker can use a dot-notation field | Mar 11, 2026 | 9.8 | 31 | NO | NO |
CVE-2025-67727CRITICAL Parse Server is an open source backend that can be deployed to any infrastructure that runs Node.js. In versions prior to 8.6.0-alpha.2, a GitHub CI workflow is triggered in a way | Dec 12, 2025 | 9.8 | 31 | NO | NO |
CVE-2022-41878CRITICAL Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions prior to 5.3.2 or 4.10.19, keywords that are specified in the Pa | Nov 10, 2022 | 9.8 | 31 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (102 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (102 CVEs).
Media Mentions
Signals from CVEs in this product scope (102 CVEs).
Top CNAs Publishing CVEs For Parse Server
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.9.0 | 1 | 5.9 | 0.2% | 0 | 0 |
| 9.8.0 | 2 | 4.0 | 0.2% | 0 | 0 |
| 9.7.1 | 1 | 5.4 | 0.2% | 0 | 0 |
| 9.7.0 | 8 | 6.3 | 0.3% | 0 | 0 |
| 9.6.0 | 33 | 6.3 | 0.4% | 0 | 0 |
| 9.5.2 | 11 | 8.4 | 0.4% | 0 | 0 |
| 9.5.1 | 1 | 7.5 | 0.5% | 0 | 0 |
| 9.5.0 | 8 | 6.5 | 0.4% | 0 | 0 |
| 9.4.1 | 1 | 7.2 | 0.4% | 0 | 0 |
| 9.3.1 | 2 | 7.6 | 0.2% | 0 | 0 |
| 9.1.0 | 2 | 6.4 | 0.3% | 0 | 0 |
| 9.0.0 | 2 | 6.3 | 0.2% | 0 | 0 |
| 8.6.0 | 1 | 9.8 | 0.4% | 0 | 0 |
| 7.0.0 | 2 | 9.4 | 1.1% | 0 | 0 |
| 6.5.0 | 1 | 10.0 | 1.0% | 0 | 0 |