Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
423 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.4) | 0.18% | — | PlaneAI | 5/10/2026 | 5/10/2026 | Plane is an open-source project management tool. Prior to 1.4.0, BulkDeleteIssuesEndpoint and SubIssuesEndpoint in apps/api/plane/app/views/issue/ accept body- or URL-supplied issue IDs and operate on them without checking that the IDs belong to the caller's workspace and project. The permission decorator on each… | |
| Aplazada | Alta (8.7) | 0.25% | — | PlaneAI | 5/10/2026 | 6/10/2026 | Plane is an open-source project management tool. Prior to 1.4.0, two endpoint families fail to verify that nested resource identifiers belong to the workspace and project named in the URL. An authenticated user can read or modify estimates from another workspace through PATCH… | |
| Aplazada | Media (5.4) | 0.22% | — | PlaneAI | 5/10/2026 | 5/10/2026 | Plane is an open-source project management tool. Prior to 1.4.0, the issue-relation endpoint accepts issue UUIDs in the request body without validating that they belong to the caller's workspace. An authenticated user can create relations linking their own issues to issues in any other workspace on the instance,… | |
| Aplazada | Media (6.8) | 0.29% | — | PlaneAI | 5/10/2026 | 5/10/2026 | Plane is an open-source project management tool. Prior to 1.4.0, Plane's project update endpoint authorizes the caller against the workspace slug in the request URL but loads the target project globally by UUID without binding it to that workspace. An administrator of one workspace can modify a project in another… | |
| Aplazada | Media (4.3) | 0.20% | — | PlaneAI | 5/10/2026 | 5/10/2026 | Plane is an open-source project management tool. Prior to 1.4.0, GET /api/workspaces/{slug}/cycles/ through WorkspaceCyclesEndpoint and GET /api/workspaces/{slug}/modules/ through WorkspaceModulesEndpoint return records from every project in a workspace without checking whether the requester belongs to each project.… | |
| Aplazada | Media (6.5) | 0.30% | — | PlaneAI | 5/10/2026 | 5/10/2026 | Plane is an open-source project management tool. Prior to 1.4.0, GET /api/v1/workspaces/{slug}/projects/{project_id}/members/ returns the complete project-member roster, including each member's email address, first and last name, display name, avatar, and role. ProjectMemberPermission gates the endpoint, but its… | |
| Aplazada | Media (5.4) | 0.18% | — | PlaneAI | 5/10/2026 | 6/10/2026 | Plane is an open-source project management tool. Prior to 1.4.0, WorkspaceOwnerPermission does not require is_active=True when checking whether a user is a workspace owner. A deactivated user can therefore remain authorized as the workspace owner and retain owner-level access. This issue is fixed in 1.4.0. | |
| Aplazada | Media (6.5) | 0.32% | — | PlaneAI | 5/10/2026 | 5/10/2026 | Plane is an open-source project management tool. Prior to 1.4.0, Plane exposes the workspace-scoped GET /api/assets/v2/workspaces/{workspace_slug}/download/{asset_id}/ endpoint for project-bound FileAsset objects without enforcing access to the asset's owning project. An authenticated user who belongs to the same… | |
| Aplazada | Media (5.3) | 0.38% | — | PlaneAI | 5/10/2026 | 5/10/2026 | Plane is an open-source project management tool. Prior to 1.4.0, the unauthenticated public issues endpoint accepts group_by and sub_group_by query parameters and passes them without an allowlist to grouped paginators, where they are used as ORM field names by F(field), .values(field), .order_by(field), and Window… | |
| Aplazada | Media (5.4) | 0.19% | — | PlaneAI | 5/10/2026 | 5/10/2026 | Plane is an open-source project management tool. Prior to 1.4.0, a Project Member with role 15 can send a PATCH request to the project-member update endpoint at /api/workspaces/{workspace_slug}/projects/{project_id}/members/{member_pk}/ to change another user's project role. The role-update logic blocks only a new… | |
| Aplazada | Media (4.3) | 0.24% | — | PlaneAI | 5/10/2026 | 5/10/2026 | Plane is an open-source project management tool. Prior to 1.4.0, the modules endpoint accepts issue UUIDs in the URL path without validating that they belong to the caller's workspace. An authenticated user can link issues from any workspace to modules in their own workspace. This issue is fixed in 1.4.0. | |
| Aplazada | Media (5.4) | 0.25% | — | PlaneAI | 5/10/2026 | 6/10/2026 | Plane is an open-source project management tool. Prior to 1.4.0, GET /api/users/api-tokens/ allows an authenticated user to retrieve API-token records, while PATCH /api/users/api-tokens/{token_id}/ allows the user to modify the token's allowed_rate_limit field without server-side validation or a maximum value. A user… | |
| Aplazada | Alta (8.7) | 0.25% | — | PlaneAI | 5/10/2026 | 5/10/2026 | Plane is an open-source project management tool. Prior to 1.4.0, aPITokenLogMiddleware logs API keys in plaintext. This allows someone with low privileges to steal user API keys and further escalate their privileges. This issue is fixed in 1.4.0. | |
| Aplazada | Media (6.9) | 0.32% | — | Crossplane RuntimeAI | 4/10/2026 | 6/10/2026 | A vulnerability was detected in crossplane crossplane-runtime up to 2.2.2/2.3.2. This vulnerability affects the function Get of the file pkg/xpkg/client.go of the component ImageConfig. The manipulation results in time-of-check time-of-use. The attack may be launched remotely. Upgrading to version 2.2.3, 2.3.3 and… | |
| Aplazada | Media (6.5) | 0.13% | — | Plugin-planet User Submitted PostsAI | 30/9/2026 | 30/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeff Starr User Submitted Posts allows Stored XSS. This issue affects User Submitted Posts: from n/a through 20260810. | |
| Aplazada | Alta (7) | 0.23% | — | InvoiceplaneAI | 28/9/2026 | 30/9/2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. In version 1.7.2, Users::form() performs no object-level authorization check on user_id = 1. A Secondary Administrator (user_type = 1, user_id != 1) can rewrite the Primary Administrator's user_type to 2 (Guest /… | |
| Aplazada | Alta (8.7) | 0.28% | — | InvoiceplaneAI | 28/9/2026 | 30/9/2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. In version 1.7.2, an authorization guard to Users::change_password(), was added to address a previous authorization flaw that allowed a secondary administrator (user_type=1, user_id != 1) to directly change the password… | |
| Aplazada | Alta (7.5) | 0.30% | — | InvoiceplaneAI | 25/9/2026 | 28/9/2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane fails to revoke administrative privileges after a role downgrade because Admin_Controller trusts the user_type snapshot stored in an existing session instead of revalidating… | |
| Aplazada | Media (4.8) | 0.22% | — | InvoiceplaneAI | 25/9/2026 | 28/9/2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. In version 1.7.2-beta-1, InvoicePlane stores client_email values without enforcing email syntax and renders them unescaped inside double-quoted value attributes in the invoice mailer form and quote mailer form. An… | |
| Aplazada | Media (4.8) | 0.25% | — | InvoiceplaneAI | 25/9/2026 | 28/9/2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane's User_Controller compares the session user_type value with the required role by using PHP's loose inequality operator. Under a non-standard session backend that returns unexpected scalar… | |
| Aplazada | Media (6.5) | 0.26% | — | InvoiceplaneAI | 25/9/2026 | 28/9/2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane's Users::change_password() method accepts a user_id from the URL and updates that account's password without an object-level authorization check. An authenticated secondary administrator can… | |
| Aplazada | Media (5.3) | 0.24% | — | InvoiceplaneAI | 25/9/2026 | 29/9/2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane's Cron::recur() method writes an invalid cron key from the URL path directly to the application log without neutralizing CRLF characters. An unauthenticated requester can place forged log… | |
| Aplazada | Media (6.5) | 0.17% | — | InvoiceplaneAI | 25/9/2026 | 28/9/2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane omits ensure_valid_post_request() from delete methods including Payments::delete(), Recurring::delete(), and User_clients::delete(). Although the routes require POST, they do not validate… | |
| Aplazada | Media (6.5) | 0.17% | — | InvoiceplaneAI | 25/9/2026 | 28/9/2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane exposes Recurring::stop() as a state-changing GET route without CSRF token validation. When an authenticated administrator loads attacker-controlled content that requests… | |
| Aplazada | Media (6) | 0.23% | — | InvoiceplaneAI | 25/9/2026 | 28/9/2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane stores an administrator-controlled custom_field_table value without validating it against the allowed custom-field table names. Mdl_custom_fields::used() later concatenates that stored value… |