Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-jhgf-2h8h-ggxv | Parse Server has a Cross-Site Scripting (XSS) vulnerability via Unescaped Mustache Template Variables |
Fri, 02 Jan 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Parseplatform
Parseplatform parse-server |
|
| CPEs | cpe:2.3:a:parseplatform:parse-server:*:*:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.0.0:-:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.0.0:alpha10:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.0.0:alpha11:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.0.0:alpha1:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.0.0:alpha2:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.0.0:alpha3:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.0.0:alpha4:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.0.0:alpha5:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.0.0:alpha6:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.0.0:alpha7:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.0.0:alpha8:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.0.0:alpha9:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.1.0:alpha1:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.1.0:alpha2:*:*:*:node.js:*:* |
|
| Vendors & Products |
Parseplatform
Parseplatform parse-server |
|
| Metrics |
cvssV3_1
|
Tue, 16 Dec 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 16 Dec 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Parse Community
Parse Community parse Server |
|
| Vendors & Products |
Parse Community
Parse Community parse Server |
Tue, 16 Dec 2025 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions prior to 8.6.1 and 9.1.0-alpha.3, a Reflected Cross-Site Scripting (XSS) vulnerability exists in Parse Server's password reset and email verification HTML pages. The patch, available in versions 8.6.1 and 9.1.0-alpha.3, escapes user controlled values that are inserted into the HTML pages. No known workarounds are available. | |
| Title | Parse Server vulnerable to Cross-Site Scripting (XSS) via Unescaped Mustache Template Variables | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-12-16T21:20:24.376Z
Reserved: 2025-12-15T16:16:22.744Z
Link: CVE-2025-68115
Updated: 2025-12-16T21:20:20.347Z
Status : Analyzed
Published: 2025-12-16T01:15:53.543
Modified: 2026-01-02T16:49:12.500
Link: CVE-2025-68115
No data.
OpenCVE Enrichment
Updated: 2025-12-16T17:09:35Z
Github GHSA