Vulnerability index

Browse CVEs

12 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2026-10850 Plane CE 1.3.1 allows a low-privileged project member to submit arbitrary HTML/JS in the description_html field when creating an intake work item thr… Plane No fix yet Fix from $1,6002026-06-17 HIGH 8.3 CVE-2026-46558 Plane is an open-source project management tool. Prior to version 1.3.1, there is a cross-workspace asset authorization bypass lets any authenticated… Plane 1.3.1+ Fix from $1,9502026-06-10 MEDIUM 6.5 CVE-2026-40102 Plane is an open-source project management tool. In versions 1.3.0 and below, SavedAnalyticEndpoint passes the user-controlled segment query paramete… Plane 1.3.1+ Fix from $1,6002026-05-20 HIGH 7.7 CVE-2026-39843 Plane is an an open-source project management tool. From 0.28.0 to before 1.3.0, the remediation of GHSA-jcc6-f9v6-f7jw is incomplete which could lea… Plane 1.3.0+ Fix from $1,9502026-04-09 HIGH 7.7 CVE-2026-39374 Plane is an an open-source project management tool. Prior to 1.3.0, the IssueBulkUpdateDateEndpoint allows a project member (ADMIN or MEMBER) to modi… Plane 1.3.0+ Fix from $1,9502026-04-07 HIGH 8.5 CVE-2026-30242 Plane is an an open-source project management tool. Prior to version 1.2.3, the webhook URL validation in plane/app/serializers/webhook.py only check… Plane 1.2.3+ Fix from $1,9502026-03-06 HIGH 7.5 CVE-2026-30244 Plane is an an open-source project management tool. Prior to version 1.2.2, unauthenticated attackers can enumerate workspace members and extract sen… Plane 1.2.2+ Fix from $1,9502026-03-06 HIGH 7.7 CVE-2026-27706 Plane is an an open-source project management tool. Prior to version 1.2.2, a Full Read Server-Side Request Forgery (SSRF) vulnerability has been ide… Plane 1.2.2+ Fix from $1,9502026-02-25 MEDIUM 6.5 CVE-2026-27705 Plane is an an open-source project management tool. Prior to version 1.2.2, the `ProjectAssetEndpoint.patch()` method in `apps/api/plane/app/views/as… Plane 1.2.2+ Fix from $1,6002026-02-25 MEDIUM 5.4 CVE-2025-21616 Plane is an open-source project management tool. A cross-site scripting (XSS) vulnerability has been identified in Plane versions prior to 0.23. The … Plane 0.23.0+ Fix from $1,6002025-01-06 MEDIUM 5.8 CVE-2024-47830 Plane is an open-source project management tool. Plane uses the ** wildcard support to retrieve the image from any hostname as in /web/next.config.js… Plane 0.23.0+ Fix from $1,6002024-10-11 HIGH 7.5 CVE-2023-2268 Plane version 0.7.1 allows an unauthenticated attacker to view all stored server files of all users. Plane No fix yet Fix from $1,9502023-07-15