An express module providing a Parse-compatible API server
82%
Total Score
95
100
100
65
50
| Title | Versions | Severity |
|---|---|---|
CVE-2026-55778 parse-server is vulnerable to Unrestricted Upload of File with Dangerous Type in versions 9.0.0 - 9.9.1-alpha.11 and 0.0.0 - 8.6.80. | 0.0.0 - 8.6.809.0.0 - 9.9.1-alpha.11 | Low |
CVE-2026-53726 parse-server is vulnerable to Authorization Bypass Through User-Controlled Key in versions 9.0.0 - 9.9.1-alpha.6 and 0.0.0 - 8.6.80. | 0.0.0 - 8.6.809.0.0 - 9.9.1-alpha.6 | Medium |
CVE-2026-53725 parse-server is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 9.8.0 - 9.9.1-alpha.5. | 9.8.0 - 9.9.1-alpha.5 | Medium |
CVE-2026-53724 parse-server is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 9.0.0 - 9.9.1-alpha.4 and 0.0.0 - 8.6.78. | 0.0.0 - 8.6.789.0.0 - 9.9.1-alpha.4 | Low |
CVE-2026-50008 parse-server is vulnerable to Incorrect Authorization in versions 9.8.0 - 9.9.1-alpha.3. | 9.8.0 - 9.9.1-alpha.3 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
ws Version 8.20.0 | — | — |
tv4 Version 1.3.0 | — | — |
cors Version 2.8.6 | — | — |
mime Version 4.1.0 | — | — |
parse Version 8.6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant