#VU125005 Cross-site scripting in Parse Server - CVE-2026-32728
Published: April 6, 2026 / Updated: April 7, 2026
Parse Server
Parse Community
Description
The vulnerability allows a remote user to conduct stored cross-site scripting attacks and disclose sensitive information.
The vulnerability exists due to improper neutralization of input during web page generation in the file upload extension validation logic when processing uploaded files with a Content-Type header containing a MIME parameter or XML-based file extensions missing from the default blocklist. A remote user can upload a specially crafted file to conduct stored cross-site scripting attacks and disclose sensitive information.
User interaction is required for a victim to load the stored active content in a browser.