« Volver al listado

Plane

Plane: vulnerabilidades y CVE

Plane tiene 22 vulnerabilidades publicadas, 14 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE22
Últimos 12 meses14
Críticas2
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-86174Media (5.3)0.34%—5 sept 2026
Plane through 1.4.2 fails to validate that issues belong to the deploy board's project in the public comment endpoint. Authenticated attackers can post comments to arbitrary issues across workspaces by supplying an…
CVE-2026-15342Media (6.5)0.38%—21 jul 2026
Plane contains a multi‑tenant authorization flaw in its asset‑management API that allows authenticated users from one workspace to access, delete, or duplicate assets belonging to another workspace by providing only the…
CVE-2026-10850Media (6.9)0.17%—17 jun 2026
Plane CE 1.3.1 allows a low-privileged project member to submit arbitrary HTML/JS in the description_html field when creating an intake work item through the API v1 intake endpoint.
CVE-2026-46558Alta (8.3)0.40%—10 jun 2026
Plane is an open-source project management tool. Prior to version 1.3.1, there is a cross-workspace asset authorization bypass lets any authenticated user read, copy, delete, and overwrite assets in other Plane…
CVE-2026-40102Media (6.5)0.41%—20 may 2026
Plane is an open-source project management tool. In versions 1.3.0 and below, SavedAnalyticEndpoint passes the user-controlled segment query parameter directly to a Django F() expression without validation (unlike the…
CVE-2026-39843Alta (7.7)0.35%—9 abr 2026
Plane is an an open-source project management tool. From 0.28.0 to before 1.3.0, the remediation of GHSA-jcc6-f9v6-f7jw is incomplete which could lead to the same full read Server-Side Request Forgery when a normal html…
CVE-2026-27949Media (4.3)0.29%—7 abr 2026
Plane is an an open-source project management tool. Prior to 1.3.0, a vulnerability was identified in Plane's authentication flow where a user's email address is included as a query parameter in the URL during error…
CVE-2026-39374Alta (7.7)0.31%—7 abr 2026
Plane is an an open-source project management tool. Prior to 1.3.0, the IssueBulkUpdateDateEndpoint allows a project member (ADMIN or MEMBER) to modify the start_date and target_date of ANY issue across the entire Plane…
CVE-2026-30244Alta (7.5)0.42%—6 mar 2026
Plane is an an open-source project management tool. Prior to version 1.2.2, unauthenticated attackers can enumerate workspace members and extract sensitive information including email addresses, user roles, and internal…
CVE-2026-30242Alta (8.5)0.33%—6 mar 2026
Plane is an an open-source project management tool. Prior to version 1.2.3, the webhook URL validation in plane/app/serializers/webhook.py only checks ip.is_loopback, allowing attackers with workspace ADMIN role to…
CVE-2026-27706Alta (7.7)0.37%—25 feb 2026
Plane is an an open-source project management tool. Prior to version 1.2.2, a Full Read Server-Side Request Forgery (SSRF) vulnerability has been identified in the "Add Link" feature. This flaw allows an authenticated…
CVE-2026-27705Media (4.9)0.39%—25 feb 2026
Plane is an an open-source project management tool. Prior to version 1.2.2, the `ProjectAssetEndpoint.patch()` method in `apps/api/plane/app/views/asset/v2.py` (lines 579–593) performs a global asset lookup using only…
CVE-2025-69284Media (4.3)0.19%—2 ene 2026
Plane is an an open-source project management tool. In plane.io, a guest user doesn't have a permission to access https[:]//app[.]plane[.]so/[:]slug/settings. Prior to Plane version 1.2.0, a problem occurs when the…
CVE-2025-62716Alta (8.1)0.32%—24 oct 2025
Plane is open-source project management software. Prior to version 1.1.0, an open redirect vulnerability in the ?next_path query parameter allows attackers to supply arbitrary schemes (e.g., javascript:) that are passed…
CVE-2025-55203Media (5.4)0.21%—15 ago 2025
Plane is open-source project management software. Prior to version 0.28.0, a stored cross-site scripting (XSS) vulnerability exists in the description_html field of Plane. This flaw allows an attacker to inject…
CVE-2025-50251Crítica (9.1)0.31%—13 ago 2025
Server side request forgery (SSRF) vulnerability in makeplane plane 0.23.1 via the password recovery.
CVE-2025-48070Media (4.3)0.26%—21 may 2025
Plane is open-source project management software. Versions prior to 0.23 have insecure permissions in UserSerializer that allows users to change fields that are meant to be read-only, such as email. This can lead to…
CVE-2025-21616Media (5.4)0.27%—6 ene 2025
Plane is an open-source project management tool. A cross-site scripting (XSS) vulnerability has been identified in Plane versions prior to 0.23. The vulnerability allows authenticated users to upload SVG files…
CVE-2024-47830Media (5.8)0.57%—11 oct 2024
Plane is an open-source project management tool. Plane uses the ** wildcard support to retrieve the image from any hostname as in /web/next.config.js. This may permit an attacker to induce the server side into…
CVE-2024-31461Crítica (9.1)0.67%—10 abr 2024
Plane, an open-source project management tool, has a Server-Side Request Forgery (SSRF) vulnerability in versions prior to 0.17-dev. This issue may allow an attacker to send arbitrary requests from the server hosting…
CVE-2023-30791Media (4.6)0.53%—15 jul 2023
Plane version 0.7.1-dev allows an attacker to change the avatar of his profile, which allows uploading files with HTML extension that interprets both HTML and JavaScript.
CVE-2023-2268Alta (7.5)0.66%—15 jul 2023
Plane version 0.7.1 allows an unauthenticated attacker to view all stored server files of all users.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1210 Exploitation of Remote Services5
  2. T1090 Proxy4
  3. T1190 Exploit Public-Facing Application2
  4. T1005 Data from Local System1
  5. T1059.007 JavaScript1
  6. T1078 Valid Accounts1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.