Known Vulnerabilities for Parse Server by Parseplatform
Listed below are 1 of the newest known vulnerabilities associated with "Parse Server" by "Parseplatform".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-64627 json | Parse Server versions >= 9.0.0 before 9.10.0-alpha.4 and versions before 8.6.85 contain a schema disclosure vulnerability. Wh... | Not Provided | 2026-07-21 | 2026-07-21 |
| CVE-2026-61448 json | Parse Server is affected by a stored cross-site scripting (XSS) vulnerability in versions >= 9.0.0, < 9.10.0-alpha.2 and <= 8... | Not Provided | 2026-07-11 | 2026-07-13 |
| CVE-2026-59249 json | Inconsistent interpretation of HTTP requests (HTTP response smuggling) vulnerability in elixir-mint mint allows a malicious H... | Not Provided | 2026-07-16 | 2026-07-16 |
| CVE-2026-58051 json | libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but does not zero-initialize new entries before parsing pop... | Not Provided | 2026-06-28 | 2026-06-29 |
| CVE-2026-57481 json | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.9.1-alpha.... | Not Provided | 2026-07-08 | 2026-07-10 |
| CVE-2026-57480 json | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.9.1-alpha.... | Not Provided | 2026-07-08 | 2026-07-09 |
| CVE-2026-55778 json | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.9.1-alpha.... | Not Provided | 2026-07-08 | 2026-07-09 |
| CVE-2026-54892 json | Inefficient algorithmic complexity in Plug's nested-parameter decoder allows an unauthenticated remote attacker to cause deni... | Not Provided | 2026-06-23 | 2026-06-23 |
| CVE-2026-54760 json | Langroid is a framework for building large-language-model-powered applications. Prior to version 0.65.1, the `SQLChatAgent` S... | Not Provided | 2026-07-10 | 2026-07-10 |
| CVE-2026-54466 json | websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.7.5, the frame format in draft versions of th... | Not Provided | 2026-07-17 | 2026-07-20 |