Plane records
16 published records for vendor plane.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 50%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-918 Server-Side Request Forgery (SSRF)4
- CWE-639 Authorization Bypass Through User-Controlled Key3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-284 Improper Access Control1
- CWE-943 Improper Neutralization of Special Elements in Data Query Logic1
The weakness classes this vendor ships most often: where to look.
CWEAll records
16 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
34Monitor | CVE-2026-30242No exploit | Plane: SSRF via Incomplete IP Validation in Webhook URL Serializerplane · plane · CWE-918 | High8.5 | — | 0.3% | Mar 6, 2026 |
33Monitor | CVE-2026-46558Proof of concept | Plane: Cross-workspace asset authorization bypass lets any authenticated user read, copy, delete, and overwrite assets in other Plane workspacesplane · plane · CWE-639 | High8.3 | — | 0.4% | Jun 10, 2026 |
30Monitor | CVE-2023-2268No exploit | Plane v0.7.1 - Unauthorized access to filesplane · plane · CWE-862 | High7.5 | — | 0.7% | Jul 15, 2023 |
30Monitor | CVE-2026-30244No exploit | Plane: Unauthenticated Workspace Member Information Disclosureplane · plane · CWE-200 | High7.5 | — | 0.4% | Mar 6, 2026 |
30Monitor | CVE-2026-27706No exploit | Plane Vulnerable to Full Read SSRF via Favicon Fetching in "Add Link" Featureplane · plane · CWE-918 | High7.7 | — | 0.4% | Feb 25, 2026 |
30Monitor | CVE-2026-39843No exploit | Plane has a Server-Side Request Forgery (SSRF) in Favicon Fetchingplane · plane · CWE-918 | High7.7 | — | 0.4% | Apr 9, 2026 |
30Monitor | CVE-2026-39374No exploit | Plane IDOR: Cross-Project Issue Date Modification via Bulk Update Endpointplane · plane · CWE-639 | High7.7 | — | 0.3% | Apr 7, 2026 |
27Monitor | CVE-2026-10850No exploit | Plane 1.3.1 - Stored XSS in intake issue description_htmlplane · plane · CWE-79 | Medium6.9 | — | 0.2% | Jun 17, 2026 |
26Monitor | CVE-2026-40102No exploit | Plane: ORM Field Reference Injection via `segment` Parameter in Saved Analyticsplane · plane · CWE-943 | Medium6.5 | — | 0.4% | May 20, 2026 |
23Monitor | CVE-2024-47830No exploit | Plane allows server side request forgery via /_next/image endpointplane · plane · CWE-918 | Medium5.8 | — | 0.6% | Oct 11, 2024 |
21Monitor | CVE-2025-21616No exploit | Plane has a Cross-site scripting (XSS) via SVG image uploadplane · plane · CWE-79 | Medium5.4 | — | 0.3% | Jan 6, 2025 |
19Monitor | CVE-2026-27705No exploit | Plane Vulnerable to Cross-Workspace/Cross-Project Asset Modification via IDOR in ProjectAssetEndpoint.patchplane · plane · CWE-639 | Medium4.9 | — | 0.4% | Feb 25, 2026 |
18Monitor | CVE-2023-30791No exploit | Plane 0.7.1 - Insecure file uploadplane · plane · CWE-434 | Medium4.6 | — | 0.5% | Jul 15, 2023 |
17Monitor | CVE-2026-27949No exploit | Plane Exposes User Email (PII and part of credential) in GET Parameterplane · plane · CWE-200 | Medium4.3 | — | 0.3% | Apr 7, 2026 |
17Monitor | CVE-2025-48070No exploit | Plane has insecure permissions in UserSerializerplane · plane · CWE-276 | Medium4.3 | — | 0.3% | May 21, 2025 |
17Monitor | CVE-2025-69284No exploit | In plane.io, a Guest User to a Workspace can still be able to see list of membersplane · plane · CWE-284 | Medium4.3 | — | 0.2% | Jan 2, 2026 |
- CVE-2026-3024234Monitor
Plane: SSRF via Incomplete IP Validation in Webhook URL Serializer
HighCVSS 8.5No exploitEPSS 0%plane · planeMar 6, 2026
- CVE-2026-4655833Monitor
Plane: Cross-workspace asset authorization bypass lets any authenticated user read, copy, delete, and overwrite assets in other Plane workspaces
HighCVSS 8.3Proof of conceptEPSS 0%plane · planeJun 10, 2026
- CVE-2023-226830Monitor
Plane v0.7.1 - Unauthorized access to files
HighCVSS 7.5No exploitEPSS 1%plane · planeJul 15, 2023
- CVE-2026-3024430Monitor
Plane: Unauthenticated Workspace Member Information Disclosure
HighCVSS 7.5No exploitEPSS 0%plane · planeMar 6, 2026
- CVE-2026-2770630Monitor
Plane Vulnerable to Full Read SSRF via Favicon Fetching in "Add Link" Feature
HighCVSS 7.7No exploitEPSS 0%plane · planeFeb 25, 2026
- CVE-2026-3984330Monitor
Plane has a Server-Side Request Forgery (SSRF) in Favicon Fetching
HighCVSS 7.7No exploitEPSS 0%plane · planeApr 9, 2026
- CVE-2026-3937430Monitor
Plane IDOR: Cross-Project Issue Date Modification via Bulk Update Endpoint
HighCVSS 7.7No exploitEPSS 0%plane · planeApr 7, 2026
- CVE-2026-1085027Monitor
Plane 1.3.1 - Stored XSS in intake issue description_html
MediumCVSS 6.9No exploitEPSS 0%plane · planeJun 17, 2026
- CVE-2026-4010226Monitor
Plane: ORM Field Reference Injection via `segment` Parameter in Saved Analytics
MediumCVSS 6.5No exploitEPSS 0%plane · planeMay 20, 2026
- CVE-2024-4783023Monitor
Plane allows server side request forgery via /_next/image endpoint
MediumCVSS 5.8No exploitEPSS 1%plane · planeOct 11, 2024
- CVE-2025-2161621Monitor
Plane has a Cross-site scripting (XSS) via SVG image upload
MediumCVSS 5.4No exploitEPSS 0%plane · planeJan 6, 2025
- CVE-2026-2770519Monitor
Plane Vulnerable to Cross-Workspace/Cross-Project Asset Modification via IDOR in ProjectAssetEndpoint.patch
MediumCVSS 4.9No exploitEPSS 0%plane · planeFeb 25, 2026
- CVE-2023-3079118Monitor
Plane 0.7.1 - Insecure file upload
MediumCVSS 4.6No exploitEPSS 1%plane · planeJul 15, 2023
- CVE-2026-2794917Monitor
Plane Exposes User Email (PII and part of credential) in GET Parameter
MediumCVSS 4.3No exploitEPSS 0%plane · planeApr 7, 2026
- CVE-2025-4807017Monitor
Plane has insecure permissions in UserSerializer
MediumCVSS 4.3No exploitEPSS 0%plane · planeMay 21, 2025
- CVE-2025-6928417Monitor
In plane.io, a Guest User to a Workspace can still be able to see list of members
MediumCVSS 4.3No exploitEPSS 0%plane · planeJan 2, 2026