parse-server vulnerabilities

An express module providing a Parse-compatible API server

  • latest version

    8.2.5

  • latest non vulnerable version

  • first published

    12 years ago

  • latest version published

    13 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the parse-server package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Exposure of Sensitive System Information to an Unauthorized Control Sphere

    >=5.3.0 <7.5.3>=8.0.0 <8.2.2
    • M
    Improper Authentication

    <7.5.2>=8.0.0 <8.0.2
    • H
    Improper Authorization

    <6.5.9>=7.0.0 <7.3.0
    • H
    SQL Injection

    <6.5.7>=7.0.0 <7.1.0
    • C
    Improper Input Validation

    <6.5.5>=7.0.0-alpha.1 <7.0.0-alpha.29
    • C
    SQL Injection

    <6.5.0>=7.0.0-alpha.1 <7.0.0-alpha.20
    • H
    Uncontrolled Resource Consumption ('Resource Exhaustion')

    >=1.0.0 <5.5.6>=6.0.0 <6.3.1
    • H
    Access Restriction Bypass

    >=1.0.0 <5.5.5>=6.0.0 <6.2.2
    • C
    Prototype Pollution

    <5.5.2>=6.0.0-alpha.1 <6.2.1
    • M
    Arbitrary File Upload

    <5.5.0>=6.0.0 <6.2.0
    • H
    Authentication Bypass

    <5.4.1
    • H
    Prototype Pollution

    <4.10.20>=5.0.0 <5.3.3
    • H
    Prototype Pollution

    <4.10.19>=5.0.0 <5.3.2
    • C
    Prototype Pollution

    <4.10.18>=5.0.0 <5.3.1
    • H
    Denial of Service (DoS)

    <4.10.17>=5.0.0 <5.2.8
    • M
    Authentication Bypass

    <4.10.15>=5.0.0 <5.2.6
    • L
    Improper Authentication

    <4.10.16>=5.0.0 <5.2.7
    • M
    Information Exposure

    <4.10.14>=5.0.0 <5.2.5
    • H
    Information Exposure

    <4.10.13>=5.0.0 <5.2.4
    • H
    Denial of Service (DoS)

    <4.10.12>=5.0.0 <5.2.3
    • C
    Authentication Bypass

    <4.10.11>=5.0.0 <5.2.2
    • H
    Authentication Bypass

    <4.10.10>=5.0.0 <5.2.1
    • C
    Prototype Pollution

    <4.10.7
    • H
    Improper Authentication

    <4.10.4
    • H
    Unsafe Dependency Resolution

    >=4.6.0 <4.10.0>=4.0.3 <4.1.0>=4.0.0-beta1 <4.0.2
    • H
    Denial of Service (DoS)

    <4.10.3
    • M
    Information Exposure

    <4.5.1
    • M
    Insecure Storage of Sensitive Information

    >=3.10.0 <4.5.0
    • M
    Operation on a Resource after Expiration or Release

    <4.4.0
    • M
    Access Restriction Bypass

    >=3.5.0 <4.3.0
    • H
    Improper Input Validation

    <4.1.0
    • H
    Denial of Service (DoS)

    <3.4.1
    • M
    Account Enumeration

    <3.6.0

    Package versions

    474 VERSIONS IN TOTAL See all versions
    versionpublisheddirect vulnerabilities
    8.3.0-alpha.715 Oct, 2025
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    8.3.0-alpha.614 Oct, 2025
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    8.3.0-alpha.514 Oct, 2025
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    8.3.0-alpha.49 Oct, 2025
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    8.3.0-alpha.37 Oct, 2025
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    8.3.0-alpha.23 Oct, 2025
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    8.3.0-alpha.13 Oct, 2025
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    8.2.52 Oct, 2025
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    8.2.5-alpha.121 Sep, 2025
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    8.2.41 Sep, 2025
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L