Known vulnerabilities in Parse Community Parse Server

Vendor: Parse Community
Website: https://parseplatform.org/
Total Security Bulletins: 22

Security bulletins (22)

Secuity bulletin Severity Status Published
SB2025122316: SSRF in Parse Server Instagram OAuth adapter Medium
Patched
23.12.2025
SB2025122315: Reflected XSS in Parse Server Low
Patched
23.12.2025
SB2025122314: Security restrictions bypass in Parse Server CI/CD infrastructure Medium
Patched
23.12.2025
SB2025110554: Denial of service via SSRF in Parse Server Medium
Patched
05.11.2025
SB2024030404: SQL injection in Parse Server High
Patched
04.03.2024
SB2023102404: Denial of service in Parse Server Medium
Patched
24.10.2023
SB2023090542: Improper access control in Parse Server Medium
Patched
05.09.2023
SB2023062920: Prototype pollution in Parse Server High
Patched
29.06.2023
SB2023013102: IP spoofing in Parse Server Medium
Patched
31.01.2023
SB2022112219: Prototype pollution in Parse Server High
Patched
22.11.2022
SB2022112218: Prototype pollution in Parse Server Low
Patched
22.11.2022
SB2022112217: Prototype pollution in Parse Server High
Patched
22.11.2022
SB2022101703: Denial of service in Parse Server Medium
Patched
17.10.2022
SB2022090731: Information disclosure in Parse Server High
Patched
07.09.2022
SB2022062736: Authentication bypass in Apple Game Center High
Patched
27.06.2022
SB2022031509: Remote code execution in parse-server High
Patched
15.03.2022
SB2022031417: Command Injection in parse-server High
Patched
14.03.2022
SB2021100512: Information disclosure in Parse Community Parse Server Medium
Patched
05.10.2021
SB2021093003: Information disclosure in Parse Server Low
Patched
30.09.2021
SB2021082712: Information disclosure in Parse Server Medium
Patched
27.08.2021
SB2020110217: Information disclosure in Parse Server Low
Patched
02.11.2020