Detects Parse Server instances using PostgreSQL where the sort/order query parameter accepts dot-notation field names with unescaped single quotes in sub-field values. An attacker with the Application ID and REST API key (typically exposed in client-side code) can inject arbitrary SQL via the order parameter, enabling full database access.
Is your app exploitable through CVE-2026-31840?
Scan your domain free