Записи Plane
16 опубликованных записей вендора plane.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 50 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-918 Server-Side Request Forgery (SSRF)4
- CWE-639 Authorization Bypass Through User-Controlled Key3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-284 Improper Access Control1
- CWE-943 Improper Neutralization of Special Elements in Data Query Logic1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
16 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
34Наблюдать | CVE-2026-30242Эксплойта нет | Plane: SSRF via Incomplete IP Validation in Webhook URL Serializerplane · plane · CWE-918 | Высокая8,5 | — | 0,3 % | 6 мар. 2026 г. |
33Наблюдать | CVE-2026-46558Proof of concept | Plane: Cross-workspace asset authorization bypass lets any authenticated user read, copy, delete, and overwrite assets in other Plane workspacesplane · plane · CWE-639 | Высокая8,3 | — | 0,4 % | 10 июн. 2026 г. |
30Наблюдать | CVE-2023-2268Эксплойта нет | Plane v0.7.1 - Unauthorized access to filesplane · plane · CWE-862 | Высокая7,5 | — | 0,7 % | 15 июл. 2023 г. |
30Наблюдать | CVE-2026-30244Эксплойта нет | Plane: Unauthenticated Workspace Member Information Disclosureplane · plane · CWE-200 | Высокая7,5 | — | 0,4 % | 6 мар. 2026 г. |
30Наблюдать | CVE-2026-27706Эксплойта нет | Plane Vulnerable to Full Read SSRF via Favicon Fetching in "Add Link" Featureplane · plane · CWE-918 | Высокая7,7 | — | 0,4 % | 25 февр. 2026 г. |
30Наблюдать | CVE-2026-39843Эксплойта нет | Plane has a Server-Side Request Forgery (SSRF) in Favicon Fetchingplane · plane · CWE-918 | Высокая7,7 | — | 0,4 % | 9 апр. 2026 г. |
30Наблюдать | CVE-2026-39374Эксплойта нет | Plane IDOR: Cross-Project Issue Date Modification via Bulk Update Endpointplane · plane · CWE-639 | Высокая7,7 | — | 0,3 % | 7 апр. 2026 г. |
27Наблюдать | CVE-2026-10850Эксплойта нет | Plane 1.3.1 - Stored XSS in intake issue description_htmlplane · plane · CWE-79 | Средняя6,9 | — | 0,2 % | 17 июн. 2026 г. |
26Наблюдать | CVE-2026-40102Эксплойта нет | Plane: ORM Field Reference Injection via `segment` Parameter in Saved Analyticsplane · plane · CWE-943 | Средняя6,5 | — | 0,4 % | 20 мая 2026 г. |
23Наблюдать | CVE-2024-47830Эксплойта нет | Plane allows server side request forgery via /_next/image endpointplane · plane · CWE-918 | Средняя5,8 | — | 0,6 % | 11 окт. 2024 г. |
21Наблюдать | CVE-2025-21616Эксплойта нет | Plane has a Cross-site scripting (XSS) via SVG image uploadplane · plane · CWE-79 | Средняя5,4 | — | 0,3 % | 6 янв. 2025 г. |
19Наблюдать | CVE-2026-27705Эксплойта нет | Plane Vulnerable to Cross-Workspace/Cross-Project Asset Modification via IDOR in ProjectAssetEndpoint.patchplane · plane · CWE-639 | Средняя4,9 | — | 0,4 % | 25 февр. 2026 г. |
18Наблюдать | CVE-2023-30791Эксплойта нет | Plane 0.7.1 - Insecure file uploadplane · plane · CWE-434 | Средняя4,6 | — | 0,5 % | 15 июл. 2023 г. |
17Наблюдать | CVE-2026-27949Эксплойта нет | Plane Exposes User Email (PII and part of credential) in GET Parameterplane · plane · CWE-200 | Средняя4,3 | — | 0,3 % | 7 апр. 2026 г. |
17Наблюдать | CVE-2025-48070Эксплойта нет | Plane has insecure permissions in UserSerializerplane · plane · CWE-276 | Средняя4,3 | — | 0,3 % | 21 мая 2025 г. |
17Наблюдать | CVE-2025-69284Эксплойта нет | In plane.io, a Guest User to a Workspace can still be able to see list of membersplane · plane · CWE-284 | Средняя4,3 | — | 0,2 % | 2 янв. 2026 г. |
- CVE-2026-3024234Наблюдать
Plane: SSRF via Incomplete IP Validation in Webhook URL Serializer
ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %plane · plane6 мар. 2026 г.
- CVE-2026-4655833Наблюдать
Plane: Cross-workspace asset authorization bypass lets any authenticated user read, copy, delete, and overwrite assets in other Plane workspaces
ВысокаяCVSS 8,3Proof of conceptEPSS 0 %plane · plane10 июн. 2026 г.
- CVE-2023-226830Наблюдать
Plane v0.7.1 - Unauthorized access to files
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %plane · plane15 июл. 2023 г.
- CVE-2026-3024430Наблюдать
Plane: Unauthenticated Workspace Member Information Disclosure
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %plane · plane6 мар. 2026 г.
- CVE-2026-2770630Наблюдать
Plane Vulnerable to Full Read SSRF via Favicon Fetching in "Add Link" Feature
ВысокаяCVSS 7,7Эксплойта нетEPSS 0 %plane · plane25 февр. 2026 г.
- CVE-2026-3984330Наблюдать
Plane has a Server-Side Request Forgery (SSRF) in Favicon Fetching
ВысокаяCVSS 7,7Эксплойта нетEPSS 0 %plane · plane9 апр. 2026 г.
- CVE-2026-3937430Наблюдать
Plane IDOR: Cross-Project Issue Date Modification via Bulk Update Endpoint
ВысокаяCVSS 7,7Эксплойта нетEPSS 0 %plane · plane7 апр. 2026 г.
- CVE-2026-1085027Наблюдать
Plane 1.3.1 - Stored XSS in intake issue description_html
СредняяCVSS 6,9Эксплойта нетEPSS 0 %plane · plane17 июн. 2026 г.
- CVE-2026-4010226Наблюдать
Plane: ORM Field Reference Injection via `segment` Parameter in Saved Analytics
СредняяCVSS 6,5Эксплойта нетEPSS 0 %plane · plane20 мая 2026 г.
- CVE-2024-4783023Наблюдать
Plane allows server side request forgery via /_next/image endpoint
СредняяCVSS 5,8Эксплойта нетEPSS 1 %plane · plane11 окт. 2024 г.
- CVE-2025-2161621Наблюдать
Plane has a Cross-site scripting (XSS) via SVG image upload
СредняяCVSS 5,4Эксплойта нетEPSS 0 %plane · plane6 янв. 2025 г.
- CVE-2026-2770519Наблюдать
Plane Vulnerable to Cross-Workspace/Cross-Project Asset Modification via IDOR in ProjectAssetEndpoint.patch
СредняяCVSS 4,9Эксплойта нетEPSS 0 %plane · plane25 февр. 2026 г.
- CVE-2023-3079118Наблюдать
Plane 0.7.1 - Insecure file upload
СредняяCVSS 4,6Эксплойта нетEPSS 1 %plane · plane15 июл. 2023 г.
- CVE-2026-2794917Наблюдать
Plane Exposes User Email (PII and part of credential) in GET Parameter
СредняяCVSS 4,3Эксплойта нетEPSS 0 %plane · plane7 апр. 2026 г.
- CVE-2025-4807017Наблюдать
Plane has insecure permissions in UserSerializer
СредняяCVSS 4,3Эксплойта нетEPSS 0 %plane · plane21 мая 2025 г.
- CVE-2025-6928417Наблюдать
In plane.io, a Guest User to a Workspace can still be able to see list of members
СредняяCVSS 4,3Эксплойта нетEPSS 0 %plane · plane2 янв. 2026 г.