CVE-2026-55778
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.9.1-alpha.11 and 8.6.81,
CVSS
—
Sin CVSS
EPSS
0.4%
p33
KEV
—
Exploit Today
10
0-100
Publicado: 8 jul 2026 · Última mod.: 10 jul 2026 · CWE-434
0.4%EPSS · 30 días0.4%
2026-07-092026-07-20
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.9.1-alpha.11 and 8.6.81, the default fileUpload.fileExtensions blocklist could be bypassed by uploading a file with a non-standard or compound extension and dangerous content type, allowing storage adapters such as S3 and GCS to serve attacker-supplied active content and enable stored cross-site scripting. This issue is fixed in versions 9.9.1-alpha.11 and 8.6.81.
- github.comhttps://github.com/parse-community/parse-server/commit/97c6a78d19f976ec756c1295f08a8fccab90799a
- github.comhttps://github.com/parse-community/parse-server/commit/be12a60d65b6e140481882037fb896b1f951df50
- github.comhttps://github.com/parse-community/parse-server/pull/10505
- github.comhttps://github.com/parse-community/parse-server/pull/10506
- github.comhttps://github.com/parse-community/parse-server/releases/tag/8.6.81
- github.comhttps://github.com/parse-community/parse-server/releases/tag/9.9.1-alpha.11
- github.comhttps://github.com/parse-community/parse-server/security/advisories/GHSA-v8x7-r927-cc93
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-164477.3 ALT—
———A vulnerability has been found in D-Link DNS-320 1.0.2. Impacted is an unknown function of the file /web/jquery/uploader/multi_uploadify.php. The manipulation of the argument Filedata[] leads to unrestricted upload. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.41mCVE-2026-163327.3 ALT—
———A vulnerability was detected in D-Link DNS-320 1.0.2. This impacts an unknown function of the file /mydlink/multi_uploadify.php. Performing a manipulation of the argument Filedata[] results in unrestricted upload. The attack is possible to be carried out remotely. The exploit is now public and may be used.12hCVE-2026-163317.3 ALT—
———A security vulnerability has been detected in D-Link DNS-320 1.0.2. This affects an unknown function of the file /web/function/save_ajax.php. Such manipulation of the argument Malicious Handler leads to unrestricted upload. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.14hCVE-2026-163307.3 ALT—
———A weakness has been identified in D-Link DNS-320 1.0.2. The impacted element is an unknown function of the file /web/jquery/uploader/uploadify.php. This manipulation of the argument https:/ucn9h68n9289.feishu.cn/wiki/JJcTwHz7aiKeq6kSItMcoeSUnMc?from=from_copylink causes unrestricted upload. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.14hCVE-2026-163297.3 ALT—
———A vulnerability was identified in D-Link DNS-320 1.0.2. Impacted is an unknown function of the file /photo_center/php/uploadify.php. The manipulation of the argument Malicious Handler leads to unrestricted upload. The attack may be initiated remotely. The exploit is publicly available and might be used.14hCVE-2026-163277.3 ALT—
———A vulnerability was determined in D-Link DNS-320 1.0.2. This issue affects some unknown processing of the file /web/web_file/upload.php. Executing a manipulation of the argument File can lead to unrestricted upload. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.2h