CVE-2025-68115

EUVD-2025-203485
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions prior to 8.6.1 and 9.1.0-alpha.3, a Reflected Cross-Site Scripting (XSS) vulnerability exists in Parse Server's password reset and email verification HTML pages. The patch, available in versions 8.6.1 and 9.1.0-alpha.3, escapes user controlled values that are inserted into the HTML pages. No known workarounds are available.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.1 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 9%
Affected Products (NVD)
VendorProductVersion
parseplatformparse-server
𝑥
< 8.6.1
parseplatformparse-server
9.0.0
parseplatformparse-server
9.0.0:alpha1
parseplatformparse-server
9.0.0:alpha10
parseplatformparse-server
9.0.0:alpha11
parseplatformparse-server
9.0.0:alpha2
parseplatformparse-server
9.0.0:alpha3
parseplatformparse-server
9.0.0:alpha4
parseplatformparse-server
9.0.0:alpha5
parseplatformparse-server
9.0.0:alpha6
parseplatformparse-server
9.0.0:alpha7
parseplatformparse-server
9.0.0:alpha8
parseplatformparse-server
9.0.0:alpha9
parseplatformparse-server
9.1.0:alpha1
parseplatformparse-server
9.1.0:alpha2
𝑥
= Vulnerable software versions