Plane

Plane

17 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Medienbericht
  • EPSS 0.23%
  • Veröffentlicht 21.07.2026 16:42:52
  • Zuletzt bearbeitet 23.07.2026 15:29:23

Plane contains a multi‑tenant authorization flaw in its asset‑management API that allows authenticated users from one workspace to access, delete, or duplicate assets belonging to another workspace by providing only the victim workspace slug and asse...

Exploit
  • EPSS 0.17%
  • Veröffentlicht 17.06.2026 14:39:51
  • Zuletzt bearbeitet 23.06.2026 14:47:07

Plane CE 1.3.1 allows a low-privileged project member to submit arbitrary HTML/JS in the description_html field when creating an intake work item through the API v1 intake endpoint.

Exploit
  • EPSS 0.28%
  • Veröffentlicht 10.06.2026 15:42:06
  • Zuletzt bearbeitet 12.06.2026 00:49:47

Plane is an open-source project management tool. Prior to version 1.3.1, there is a cross-workspace asset authorization bypass lets any authenticated user read, copy, delete, and overwrite assets in other Plane workspaces. This issue has been patched...

Exploit
  • EPSS 0.3%
  • Veröffentlicht 20.05.2026 22:16:37
  • Zuletzt bearbeitet 23.07.2026 15:10:00

Plane is an open-source project management tool. In versions 1.3.0 and below, SavedAnalyticEndpoint passes the user-controlled segment query parameter directly to a Django F() expression without validation (unlike the regular AnalyticsEndpoint, which...

Exploit
  • EPSS 0.25%
  • Veröffentlicht 09.04.2026 15:43:34
  • Zuletzt bearbeitet 17.04.2026 20:08:53

Plane is an an open-source project management tool. From 0.28.0 to before 1.3.0, the remediation of GHSA-jcc6-f9v6-f7jw is incomplete which could lead to the same full read Server-Side Request Forgery when a normal html page contains a link tag with ...

  • EPSS 0.17%
  • Veröffentlicht 07.04.2026 20:26:25
  • Zuletzt bearbeitet 24.07.2026 23:10:00

Plane is an an open-source project management tool. Prior to 1.3.0, a vulnerability was identified in Plane's authentication flow where a user's email address is included as a query parameter in the URL during error handling (e.g., when an invalid ma...

Exploit
  • EPSS 0.21%
  • Veröffentlicht 07.04.2026 19:37:31
  • Zuletzt bearbeitet 24.07.2026 21:10:00

Plane is an an open-source project management tool. Prior to 1.3.0, the IssueBulkUpdateDateEndpoint allows a project member (ADMIN or MEMBER) to modify the start_date and target_date of ANY issue across the entire Plane instance, regardless of worksp...

  • EPSS 0.28%
  • Veröffentlicht 06.03.2026 21:19:24
  • Zuletzt bearbeitet 10.03.2026 16:17:24

Plane is an an open-source project management tool. Prior to version 1.2.3, the webhook URL validation in plane/app/serializers/webhook.py only checks ip.is_loopback, allowing attackers with workspace ADMIN role to create webhooks pointing to private...

  • EPSS 0.38%
  • Veröffentlicht 06.03.2026 21:19:12
  • Zuletzt bearbeitet 10.03.2026 16:23:32

Plane is an an open-source project management tool. Prior to version 1.2.2, unauthenticated attackers can enumerate workspace members and extract sensitive information including email addresses, user roles, and internal identifiers. The vulnerability...

  • EPSS 0.21%
  • Veröffentlicht 25.02.2026 15:56:11
  • Zuletzt bearbeitet 27.02.2026 17:36:19

Plane is an an open-source project management tool. Prior to version 1.2.2, a Full Read Server-Side Request Forgery (SSRF) vulnerability has been identified in the "Add Link" feature. This flaw allows an authenticated attacker with general user privi...