CVE-2026-31868 | parse-community parse-server up to 8.6.29 XHTML File Parser HTML injection (GHSA-v5hf-f4c3-m5rv)
A vulnerability identified as problematic has been detected in parse-community parse-server up to 8.6.29. Affected by this issue is some unknown functionality of the component XHTML File Parser. This manipulation causes HTML injection.
This vulnerability is tracked as CVE-2026-31868. The attack is possible to be carried out remotely. No exploit exists.
You should upgrade the affected component.