Skip to content
Noroxi

Plane records

16 published records for vendor plane.

All records

16 records
  • Plane: SSRF via Incomplete IP Validation in Webhook URL Serializer

    HighCVSS 8.5No exploitEPSS 0%

    plane · planeMar 6, 2026

  • Plane: Cross-workspace asset authorization bypass lets any authenticated user read, copy, delete, and overwrite assets in other Plane workspaces

    HighCVSS 8.3Proof of conceptEPSS 0%

    plane · planeJun 10, 2026

  • CVE-2023-2268
    30Monitor

    Plane v0.7.1 - Unauthorized access to files

    HighCVSS 7.5No exploitEPSS 1%

    plane · planeJul 15, 2023

  • Plane: Unauthenticated Workspace Member Information Disclosure

    HighCVSS 7.5No exploitEPSS 0%

    plane · planeMar 6, 2026

  • Plane Vulnerable to Full Read SSRF via Favicon Fetching in "Add Link" Feature

    HighCVSS 7.7No exploitEPSS 0%

    plane · planeFeb 25, 2026

  • Plane has a Server-Side Request Forgery (SSRF) in Favicon Fetching

    HighCVSS 7.7No exploitEPSS 0%

    plane · planeApr 9, 2026

  • Plane IDOR: Cross-Project Issue Date Modification via Bulk Update Endpoint

    HighCVSS 7.7No exploitEPSS 0%

    plane · planeApr 7, 2026

  • Plane 1.3.1 - Stored XSS in intake issue description_html

    MediumCVSS 6.9No exploitEPSS 0%

    plane · planeJun 17, 2026

  • Plane: ORM Field Reference Injection via `segment` Parameter in Saved Analytics

    MediumCVSS 6.5No exploitEPSS 0%

    plane · planeMay 20, 2026

  • Plane allows server side request forgery via /_next/image endpoint

    MediumCVSS 5.8No exploitEPSS 1%

    plane · planeOct 11, 2024

  • Plane has a Cross-site scripting (XSS) via SVG image upload

    MediumCVSS 5.4No exploitEPSS 0%

    plane · planeJan 6, 2025

  • Plane Vulnerable to Cross-Workspace/Cross-Project Asset Modification via IDOR in ProjectAssetEndpoint.patch

    MediumCVSS 4.9No exploitEPSS 0%

    plane · planeFeb 25, 2026

  • Plane 0.7.1 - Insecure file upload

    MediumCVSS 4.6No exploitEPSS 1%

    plane · planeJul 15, 2023

  • Plane Exposes User Email (PII and part of credential) in GET Parameter

    MediumCVSS 4.3No exploitEPSS 0%

    plane · planeApr 7, 2026

  • Plane has insecure permissions in UserSerializer

    MediumCVSS 4.3No exploitEPSS 0%

    plane · planeMay 21, 2025

  • In plane.io, a Guest User to a Workspace can still be able to see list of members

    MediumCVSS 4.3No exploitEPSS 0%

    plane · planeJan 2, 2026