PT-2025-51360 · Unknown · Parse Server

Published

2025-12-16

·

Updated

2026-01-02

·

CVE-2025-68115

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Parse Server versions prior to 8.6.1 Parse Server versions prior to 9.1.0-alpha.3
Description Parse Server, an open source backend deployable on Node.js infrastructures, contains a Reflected Cross-Site Scripting (XSS) issue in its password reset and email verification HTML pages. The issue stems from a lack of proper escaping of user-controlled values inserted into these HTML pages. The patch escapes these values, resolving the problem.
Recommendations Update to Parse Server version 8.6.1 or later. Update to Parse Server version 9.1.0-alpha.3 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

BIT-PARSE-2025-68115
CVE-2025-68115
GHSA-JHGF-2H8H-GGXV

Affected Products

Parse Server