Skip to content

Known CVE

Parse Server < 8.6.21 / 9.x < 9.5.2 - Session Token Exfiltration

Parse Server < 8.6.21 / 9.x < 9.5.2 contains an information disclosure vulnerability caused by improper handling of the redirectClassNameForKey query parameter, letting authenticated or unauthenticated attackers exfiltrate session tokens, exploit requires ability to create or update an object with a new relation field depending on Class-Level Permissions.

CVE-2026-30965

Critical2026CVSS 9.9CWE-863

cve2026 · parse · parse-server · session-hijack · auth-bypass

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website