parse-server
An express module providing a Parse-compatible API server
Security Advisories for parse-server in npm
Critical
about 2 hours ago
Parse Server: SQL injection via dot-notation field name in PostgreSQL
npm
parse-server
High
about 19 hours ago
Parse Server has Denial of Service (DoS) and Cloud Function Dispatch Bypass via Prototype Chain Resolution
npm
parse-server
Moderate
about 19 hours ago
Parse Server has denylist `requestKeywordDenylist` keyword scan bypass through nested object placement
npm
parse-server
High
about 19 hours ago
Parse Server has Regular Expression Denial of Service (ReDoS) via `$regex` query in LiveQuery
npm
parse-server
Critical
1 day ago
Parse Server: JWT audience validation bypass in Google, Apple, and Facebook authentication adapters
npm
parse-server
Moderate
1 day ago
Parse Server: GraphQL `__type` introspection bypass via inline fragments when public introspection is disabled
npm
parse-server
Moderate
1 day ago
Parse Server: File metadata endpoint bypasses `beforeFind` / `afterFind` trigger authorization
npm
parse-server
Moderate
1 day ago
Parse Server: `PagesRouter` path traversal allows reading files outside configured pages directory
npm
parse-server
Moderate
4 days ago
parse-server: Malformed `$regex` query leaks database error details in API response
npm
parse-server
High
4 days ago
parse-server's endpoint `/loginAs` allows `readOnlyMasterKey` to gain full read and write access as any user
npm
parse-server
Moderate
4 days ago
parse-server's file creation and deletion bypasses `readOnlyMasterKey` write restriction
npm
parse-server
High
6 days ago
Parse Server's Cloud Hooks and Cloud Jobs bypass `readOnlyMasterKey` write restriction
npm
parse-server
Critical
13 days ago
Parse Server: Account takeover via JWT algorithm confusion in Google auth adapter
npm
parse-server
High
3 months ago
Parse Server is vulnerable to Server-Side Request Forgery (SSRF) via Instagram OAuth Adapter
npm
parse-server
Moderate
3 months ago
Parse Server has a Cross-Site Scripting (XSS) vulnerability via Unescaped Mustache Template Variables
npm
parse-server
Moderate
4 months ago
Parse Server allows public `explain` queries which may expose sensitive database performance information and schema details
npm
parse-server
High
4 months ago
Parse Server Vulnerable to Server-Side Request Forgery (SSRF) in File Upload via URI Format
npm
parse-server
High
over 1 year ago
Parse Server's custom object ID allows to acquire role privileges
npm
parse-server
Critical
over 1 year ago
ZDI-CAN-23894: Parse Server literalizeRegexPart SQL Injection Authentication Bypass Vulnerability
npm
parse-server
Critical
almost 2 years ago
Server crashes on invalid Cloud Function or Cloud Job name
npm
parse-server
Critical
about 2 years ago
ZDI-CAN-19105: Parse Server literalizeRegexPart SQL Injection
npm
parse-server
High
over 2 years ago
Trigger `beforeFind` not invoked in internal query pipeline when fetching pointer
npm
parse-server
Critical
over 2 years ago
Parse Server vulnerable to remote code execution via MongoDB BSON parser through prototype pollution
npm
parse-server
Moderate
almost 3 years ago
Phishing attack vulnerability by uploading malicious HTML file
npm
parse-server
High
about 3 years ago
Parse Server option `masterKeyIps` vulnerability to IP spoofing
npm
parse-server
High
over 3 years ago
Parse Server is vulnerable to Prototype Pollution via Cloud Code Webhooks
npm
parse-server
High
over 3 years ago
Parse Server vulnerable to Prototype Pollution via Cloud Code Webhooks or Cloud Code Triggers
npm
parse-server
Critical
over 3 years ago
Remote code execution via MongoDB BSON parser through prototype pollution
npm
parse-server
High
over 3 years ago
parse-server crashes when receiving file download request with invalid byte range
npm
parse-server
Low
over 3 years ago
parse-server auth adapter app ID validation can be circumvented
npm
parse-server
Moderate
over 3 years ago
parse-server's session object properties can be updated by foreign user if object ID is known
npm
parse-server
High
over 3 years ago
Parse Server vulnerable to brute force guessing of user sensitive data via search patterns
npm
parse-server
High
over 3 years ago
Authentication bypass vulnerability in Apple Game Center auth adapter
npm
parse-server
High
almost 4 years ago
Authentication bypass and denial of service (DoS) vulnerabilities in Apple Game Center auth adapter
npm
parse-server
Critical
almost 4 years ago
Command injection in Parse Server through prototype pollution
npm
parse-server
Moderate
over 4 years ago
parse-server new anonymous user session acts as if it's created with password
npm
parse-server