Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

makeplane — Vulnerabilities & Security Advisories 17

Browse all 17 CVE security advisories affecting makeplane. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Makeplane provides collaborative software development tools, primarily serving DevOps teams for project management and code collaboration. Historically, the platform has been vulnerable to multiple remote code execution (RCE) flaws, cross-site scripting (XSS) attacks, and privilege escalation issues, accounting for most of its 14 recorded CVEs. Security researchers have identified consistent patterns in input validation failures and insufficient access controls across different versions. While no major public security incidents have been widely documented, the accumulation of CVEs suggests ongoing challenges in secure coding practices, particularly in handling user-supplied data and maintaining proper privilege boundaries between different user roles.

Found 17 results / 17 Clear Filters
Top products by makeplane: plane
CVE ID Title CVSS Severity Published
CVE-2026-86174 Plane through 1.4.2 Arbitrary Comment Write via Public Deploy Board — plane CWE-639 4.3 Medium 2026-09-05
CVE-2026-46558 Plane: Cross-workspace asset authorization bypass lets any authenticated user read, copy, delete, and overwrite assets in other Plane workspaces — plane CWE-639 8.3 High 2026-06-10
CVE-2026-40102 Plane: ORM Field Reference Injection via `segment` Parameter in Saved Analytics — plane CWE-943 6.5 Medium 2026-05-20
CVE-2026-39843 Plane has a Server-Side Request Forgery (SSRF) in Favicon Fetching — plane CWE-918 7.7 High 2026-04-09
CVE-2026-27949 Plane Exposes User Email (PII and part of credential) in GET Parameter — plane CWE-200 2.0 Low 2026-04-07
CVE-2026-39374 Plane IDOR: Cross-Project Issue Date Modification via Bulk Update Endpoint — plane CWE-639 6.5 Medium 2026-04-07
CVE-2026-30242 Plane: SSRF via Incomplete IP Validation in Webhook URL Serializer — plane CWE-918 8.5 High 2026-03-06
CVE-2026-30244 Plane: Unauthenticated Workspace Member Information Disclosure — plane CWE-284 7.5 High 2026-03-06
CVE-2026-27706 Plane Vulnerable to Full Read SSRF via Favicon Fetching in "Add Link" Feature — plane CWE-918 7.7 High 2026-02-25
CVE-2026-27705 Plane Vulnerable to Cross-Workspace/Cross-Project Asset Modification via IDOR in ProjectAssetEndpoint.patch — plane CWE-639 6.5AI Medium AI 2026-02-25
CVE-2025-69284 In plane.io, a Guest User to a Workspace can still be able to see list of members — plane CWE-284 4.3 Medium 2026-01-02
CVE-2025-62716 Plane Vulnerable to Cross-Site Scripting via Open Redirect in ?next_path Parameter — plane CWE-79 8.1 High 2025-10-24
CVE-2025-55203 Plane Stored XSS in Add Work Item Functionality — plane CWE-79 5.4 Medium 2025-08-15
CVE-2025-48070 Plane has insecure permissions in UserSerializer — plane CWE-276 3.5 Low 2025-05-21
CVE-2025-21616 Plane has a Cross-site scripting (XSS) via SVG image upload — plane CWE-79 5.4 Medium 2025-01-06
CVE-2024-47830 Plane allows server side request forgery via /_next/image endpoint — plane CWE-918 9.3 Critical 2024-10-11
CVE-2024-31461 Plane Server-Side Request Forgery (SSRF) Vulnerability — plane CWE-918 9.1 Critical 2024-04-10

This page lists every published CVE security advisory associated with makeplane. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.