İçeriğe atla
Noroxi

Plane kayıtları

plane üreticisine ait 16 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
0
Düzeltme kaydı olan
%50
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

16 kayıt
  • CVE-2026-30242
    34İzleyin

    Plane: SSRF via Incomplete IP Validation in Webhook URL Serializer

    YüksekCVSS 8,5İstismar yokEPSS %0

    plane · plane6 Mar 2026

  • CVE-2026-46558
    33İzleyin

    Plane: Cross-workspace asset authorization bypass lets any authenticated user read, copy, delete, and overwrite assets in other Plane workspaces

    YüksekCVSS 8,3Kavram kanıtıEPSS %0

    plane · plane10 Haz 2026

  • CVE-2023-2268
    30İzleyin

    Plane v0.7.1 - Unauthorized access to files

    YüksekCVSS 7,5İstismar yokEPSS %1

    plane · plane15 Tem 2023

  • CVE-2026-30244
    30İzleyin

    Plane: Unauthenticated Workspace Member Information Disclosure

    YüksekCVSS 7,5İstismar yokEPSS %0

    plane · plane6 Mar 2026

  • CVE-2026-27706
    30İzleyin

    Plane Vulnerable to Full Read SSRF via Favicon Fetching in "Add Link" Feature

    YüksekCVSS 7,7İstismar yokEPSS %0

    plane · plane25 Şub 2026

  • CVE-2026-39843
    30İzleyin

    Plane has a Server-Side Request Forgery (SSRF) in Favicon Fetching

    YüksekCVSS 7,7İstismar yokEPSS %0

    plane · plane9 Nis 2026

  • CVE-2026-39374
    30İzleyin

    Plane IDOR: Cross-Project Issue Date Modification via Bulk Update Endpoint

    YüksekCVSS 7,7İstismar yokEPSS %0

    plane · plane7 Nis 2026

  • CVE-2026-10850
    27İzleyin

    Plane 1.3.1 - Stored XSS in intake issue description_html

    OrtaCVSS 6,9İstismar yokEPSS %0

    plane · plane17 Haz 2026

  • CVE-2026-40102
    26İzleyin

    Plane: ORM Field Reference Injection via `segment` Parameter in Saved Analytics

    OrtaCVSS 6,5İstismar yokEPSS %0

    plane · plane20 May 2026

  • CVE-2024-47830
    23İzleyin

    Plane allows server side request forgery via /_next/image endpoint

    OrtaCVSS 5,8İstismar yokEPSS %1

    plane · plane11 Eki 2024

  • CVE-2025-21616
    21İzleyin

    Plane has a Cross-site scripting (XSS) via SVG image upload

    OrtaCVSS 5,4İstismar yokEPSS %0

    plane · plane6 Oca 2025

  • CVE-2026-27705
    19İzleyin

    Plane Vulnerable to Cross-Workspace/Cross-Project Asset Modification via IDOR in ProjectAssetEndpoint.patch

    OrtaCVSS 4,9İstismar yokEPSS %0

    plane · plane25 Şub 2026

  • CVE-2023-30791
    18İzleyin

    Plane 0.7.1 - Insecure file upload

    OrtaCVSS 4,6İstismar yokEPSS %1

    plane · plane15 Tem 2023

  • CVE-2026-27949
    17İzleyin

    Plane Exposes User Email (PII and part of credential) in GET Parameter

    OrtaCVSS 4,3İstismar yokEPSS %0

    plane · plane7 Nis 2026

  • CVE-2025-48070
    17İzleyin

    Plane has insecure permissions in UserSerializer

    OrtaCVSS 4,3İstismar yokEPSS %0

    plane · plane21 May 2025

  • CVE-2025-69284
    17İzleyin

    In plane.io, a Guest User to a Workspace can still be able to see list of members

    OrtaCVSS 4,3İstismar yokEPSS %0

    plane · plane2 Oca 2026