
CVE-2026-30948 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.4 and 8.6.17, a stored cross-site scripti… https://www.cve.org/CVERecord?id=CVE-2026-30948
Post summary
The text discloses a stored cross‑site scripting flaw in Parse Server affecting versions before 9.5.2‑alpha.4 and 8.6.17, without indicating any PoC, exploit, or active usage.
