Known CVE
Parse Server < 8.6.21 / 9.x < 9.5.2 - Session Token Exfiltration
Parse Server < 8.6.21 / 9.x < 9.5.2 contains an information disclosure vulnerability caused by improper handling of the redirectClassNameForKey query parameter, letting authenticated or unauthenticated attackers exfiltrate session tokens, exploit requires ability to create or update an object with a new relation field depending on Class-Level Permissions.
CVE-2026-30965
Critical2026CVSS 9.9CWE-863
cve2026 · parse · parse-server · session-hijack · auth-bypass
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website