CVE Tools

Parse-community

83 CVEs tracked since 2022. Since Sep 2022, none of them reached CISA KEV.

Parse-community CVEs per month

Sep 2022 to Jul 2026. Point at a month, or focus the strip and use the arrow keys.
Parse-community CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2022-0930
2022-10null or fewer
2022-11null or fewer
2022-12null or fewer
2023-01null or fewer
2023-02null or fewer
2023-03null or fewer
2023-04null or fewer
2023-05null or fewer
2023-06null or fewer
2023-07null or fewer
2023-08null or fewer
2023-09null or fewer
2023-10null or fewer
2023-11null or fewer
2023-12null or fewer
2024-01null or fewer
2024-02null or fewer
2024-03null or fewer
2024-04null or fewer
2024-05null or fewer
2024-06null or fewer
2024-07null or fewer
2024-08null or fewer
2024-09null or fewer
2024-10null or fewer
2024-11null or fewer
2024-12null or fewer
2025-01null or fewer
2025-02null or fewer
2025-03null or fewer
2025-04null or fewer
2025-05null or fewer
2025-06null or fewer
2025-07null or fewer
2025-08null or fewer
2025-09null or fewer
2025-10null or fewer
2025-11null or fewer
2025-12null or fewer
2026-01null or fewer
2026-02null or fewer
2026-03650
2026-04null or fewer
2026-05null or fewer
2026-0680
2026-0770

Products

The products that kept showing up in Parse-community's monthly top three, with their CVEs summed over those months.

  1. Parse-server834 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Parse-community.

  1. CVE-2026-100631Parse Server 9.0.0 Unauthenticated Installation Deletion via Operator Injection7.5
  2. CVE-2026-100632Parse Server 9.0.0 before 9.10.1 Protected Fields Disclosure via LiveQuery6.5
  3. CVE-2026-87806Parse Server 9.0.0 Authentication Bypass via LDAP Empty Password7.4
  4. CVE-2026-66009Parse Server 9.0.0 Information Disclosure via GraphQL Error Messages—
  5. CVE-2026-66008Parse Server 9.0.0 Information Disclosure via GraphQL Error Messages—
  6. CVE-2026-64627Parse Server 9.0.0 Schema Disclosure via GraphQL Variable Coercion—
  7. CVE-2026-61448Parse Server 9.0.0 Stored XSS via malformed Content-Type—
  8. CVE-2026-57481Parse Server: LiveQuery discloses object data to a subscriber across an ACL read-access change—
  9. CVE-2026-57480Parse Server: Denial of service via exponential-time processing of deeply nested query operators—
  10. CVE-2026-55778Parse Server: Stored XSS via non-standard file extension bypassing file upload extension blocklist—
  11. CVE-2021-47987Parse Server - Arbitrary Code Execution via Malicious Version Tags7.5
  12. CVE-2021-47986Parse Server - Unreviewed Code Execution via Malicious Version Tags7.5
  13. CVE-2026-53726Parse Server: Relation `$relatedTo` query bypasses `protectedFields` and owning-object ACL—
  14. CVE-2026-53725Parse Server: Endpoints `/login` and `/verifyPassword` disclose MFA secrets and protected fields when `_User` get is denied—
  15. CVE-2026-53724Parse Server: Stored XSS via trailing-dot filename bypassing file upload extension blocklist—

The record

Peak rank
#19 in Mar 2026
Busiest month shown
Mar 2026, 65 CVEs
Months with a KEV entry
0 since Sep 2022
Monthly snapshots
4 since 2022
Parse-community's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store