Vulnerability index

Browse CVEs

12 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Plane MEDIUM 5.4
CVE-2026-10850

Plane CE 1.3.1 allows a low-privileged project member to submit arbitrary HTML/JS in the description_html field when creating an intake work item thr…

No fix yet
Fix from $1,600 2026-06-17
Plane HIGH 8.3
CVE-2026-46558

Plane is an open-source project management tool. Prior to version 1.3.1, there is a cross-workspace asset authorization bypass lets any authenticated…

Fix: 1.3.1+
Fix from $1,950 2026-06-10
Plane MEDIUM 6.5
CVE-2026-40102

Plane is an open-source project management tool. In versions 1.3.0 and below, SavedAnalyticEndpoint passes the user-controlled segment query paramete…

Fix: 1.3.1+
Fix from $1,600 2026-05-20
Plane HIGH 7.7
CVE-2026-39843

Plane is an an open-source project management tool. From 0.28.0 to before 1.3.0, the remediation of GHSA-jcc6-f9v6-f7jw is incomplete which could lea…

Fix: 1.3.0+
Fix from $1,950 2026-04-09
Plane HIGH 7.7
CVE-2026-39374

Plane is an an open-source project management tool. Prior to 1.3.0, the IssueBulkUpdateDateEndpoint allows a project member (ADMIN or MEMBER) to modi…

Fix: 1.3.0+
Fix from $1,950 2026-04-07
Plane HIGH 8.5
CVE-2026-30242

Plane is an an open-source project management tool. Prior to version 1.2.3, the webhook URL validation in plane/app/serializers/webhook.py only check…

Fix: 1.2.3+
Fix from $1,950 2026-03-06
Plane HIGH 7.5
CVE-2026-30244

Plane is an an open-source project management tool. Prior to version 1.2.2, unauthenticated attackers can enumerate workspace members and extract sen…

Fix: 1.2.2+
Fix from $1,950 2026-03-06
Plane HIGH 7.7
CVE-2026-27706

Plane is an an open-source project management tool. Prior to version 1.2.2, a Full Read Server-Side Request Forgery (SSRF) vulnerability has been ide…

Fix: 1.2.2+
Fix from $1,950 2026-02-25
Plane MEDIUM 6.5
CVE-2026-27705

Plane is an an open-source project management tool. Prior to version 1.2.2, the `ProjectAssetEndpoint.patch()` method in `apps/api/plane/app/views/as…

Fix: 1.2.2+
Fix from $1,600 2026-02-25
Plane MEDIUM 5.4
CVE-2025-21616

Plane is an open-source project management tool. A cross-site scripting (XSS) vulnerability has been identified in Plane versions prior to 0.23. The …

Fix: 0.23.0+
Fix from $1,600 2025-01-06
Plane MEDIUM 5.8
CVE-2024-47830

Plane is an open-source project management tool. Plane uses the ** wildcard support to retrieve the image from any hostname as in /web/next.config.js…

Fix: 0.23.0+
Fix from $1,600 2024-10-11
Plane HIGH 7.5
CVE-2023-2268

Plane version 0.7.1 allows an unauthenticated attacker to view all stored server files of all users.

No fix yet
Fix from $1,950 2023-07-15