Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Plane — Vulnerabilities & Security Advisories 21

All 21 CVE vulnerabilities found in Plane, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for the open-source project Plane, a product within the Plane vendor ecosystem, focusing primarily on implementation flaws in its issue and project management features. The collection covers a wide range of security weaknesses, including cross-site scripting, privilege escalation, and improper input validation, documented across the project’s full advisory history from its initial public release through the present. Readers can use this hub to track the vendor’s security advisories, understand the specific classes of weaknesses that have affected the software, and review the complete vulnerability timeline to assess historical risk trends and remediation patterns.

Vendor: Plane

CVE ID Title CVSS Severity Published
CVE-2026-86174 Plane through 1.4.2 Arbitrary Comment Write via Public Deploy Board CWE-639 4.3 Medium 2026-09-05
CVE-2026-15342 CVE-2026-15342 - - 2026-07-21
CVE-2026-10850 Plane 1.3.1 - Stored XSS in intake issue description_html CWE-79 - - 2026-06-17
CVE-2026-46558 Plane: Cross-workspace asset authorization bypass lets any authenticated user read, copy, delete, and overwrite assets in other Plane workspaces CWE-639 8.3 High 2026-06-10
CVE-2026-40102 Plane: ORM Field Reference Injection via `segment` Parameter in Saved Analytics CWE-943 6.5 Medium 2026-05-20
CVE-2026-39843 Plane has a Server-Side Request Forgery (SSRF) in Favicon Fetching CWE-918 7.7 High 2026-04-09
CVE-2026-27949 Plane Exposes User Email (PII and part of credential) in GET Parameter CWE-200 2.0 Low 2026-04-07
CVE-2026-39374 Plane IDOR: Cross-Project Issue Date Modification via Bulk Update Endpoint CWE-639 6.5 Medium 2026-04-07
CVE-2026-30242 Plane: SSRF via Incomplete IP Validation in Webhook URL Serializer CWE-918 8.5 High 2026-03-06
CVE-2026-30244 Plane: Unauthenticated Workspace Member Information Disclosure CWE-284 7.5 High 2026-03-06
CVE-2026-27706 Plane Vulnerable to Full Read SSRF via Favicon Fetching in "Add Link" Feature CWE-918 7.7 High 2026-02-25
CVE-2026-27705 Plane Vulnerable to Cross-Workspace/Cross-Project Asset Modification via IDOR in ProjectAssetEndpoint.patch CWE-639 6.5AI Medium AI 2026-02-25
CVE-2025-69284 In plane.io, a Guest User to a Workspace can still be able to see list of members CWE-284 4.3 Medium 2026-01-02
CVE-2025-62716 Plane Vulnerable to Cross-Site Scripting via Open Redirect in ?next_path Parameter CWE-79 8.1 High 2025-10-24
CVE-2025-55203 Plane Stored XSS in Add Work Item Functionality CWE-79 5.4 Medium 2025-08-15
CVE-2025-48070 Plane has insecure permissions in UserSerializer CWE-276 3.5 Low 2025-05-21
CVE-2025-21616 Plane has a Cross-site scripting (XSS) via SVG image upload CWE-79 5.4 Medium 2025-01-06
CVE-2024-47830 Plane allows server side request forgery via /_next/image endpoint CWE-918 9.3 Critical 2024-10-11
CVE-2024-31461 Plane Server-Side Request Forgery (SSRF) Vulnerability CWE-918 9.1 Critical 2024-04-10
CVE-2023-30791 Plane 0.7.1 - Insecure file upload CWE-434 7.1 High 2023-07-15
CVE-2023-2268 Plane v0.7.1 - Unauthorized access to files CWE-862 7.1 High 2023-07-15

All 21 known CVE vulnerabilities affecting Plane with full Chinese analysis, references, and POCs where available.