Parse Server

Vendor:

First CVE: Jul 29, 2019 · Active for 6 years

102
Total CVEs
More Total CVEs than 99% of tracked products
12.8
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 42% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Parse Server over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 29, 2019
6 years ago
Most Recent CVE
May 12, 2026
73 days ago

CVE Severity & Scoring

Parse Server102 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network102 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low90 (88.2%)
High12 (11.8%)
Unknown0 (0.0%)
User Interaction
None95 (93.1%)
Unknown0 (0.0%)
Required7 (6.9%)
Privileges Required
Low25 (24.5%)
High7 (6.9%)
None70 (68.6%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (102 CVEs).

102 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Parse Server is an open source http web server backend. In versions prior to 4.10.7 there is a Remote Code Execution (RCE) vulnerability in Parse Server. This vulnerability affects
Mar 12, 202210.060NONO
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Versions prior to 4.10.18, and prior to 5.3.1 on the 5.X branch, are vulnera
Nov 10, 20229.852NONO
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.12 and 8.6.38, an unauthenticated attacker can take ove
Mar 12, 20269.832NONO
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.10 and 9.5.0-alpha.11, the Google, Apple, and Facebook
Mar 7, 20269.832NONO
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.67 and 9.7.0-alpha.11, an attacker can bypass Cloud Fu
Mar 31, 20269.131NONO
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.5 and 8.6.31, a SQL injection vulnerability exists in t
Mar 11, 20269.831NONO
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. A SQL injection vulnerability exists in the PostgreSQL storage adapter when
Mar 11, 20269.831NONO
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.2 and 8.6.28, an attacker can use a dot-notation field
Mar 11, 20269.831NONO
Parse Server is an open source backend that can be deployed to any infrastructure that runs Node.js. In versions prior to 8.6.0-alpha.2, a GitHub CI workflow is triggered in a way
Dec 12, 20259.831NONO
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions prior to 5.3.2 or 4.10.19, keywords that are specified in the Pa
Nov 10, 20229.831NONO

Exploit Exposure

Signals from CVEs in this product scope (102 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (102 CVEs).

Media Mentions

Signals from CVEs in this product scope (102 CVEs).

Top CNAs Publishing CVEs For Parse Server

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.9.015.90.2%00
9.8.024.00.2%00
9.7.115.40.2%00
9.7.086.30.3%00
9.6.0336.30.4%00
9.5.2118.40.4%00
9.5.117.50.5%00
9.5.086.50.4%00
9.4.117.20.4%00
9.3.127.60.2%00
9.1.026.40.3%00
9.0.026.30.2%00
8.6.019.80.4%00
7.0.029.41.1%00
6.5.0110.01.0%00