Plane kayıtları
plane üreticisine ait 16 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %50
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-918 Server-Side Request Forgery (SSRF)4
- CWE-639 Authorization Bypass Through User-Controlled Key3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-284 Improper Access Control1
- CWE-943 Improper Neutralization of Special Elements in Data Query Logic1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
16 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
34İzleyin | CVE-2026-30242İstismar yok | Plane: SSRF via Incomplete IP Validation in Webhook URL Serializerplane · plane · CWE-918 | Yüksek8,5 | — | %0,3 | 6 Mar 2026 |
33İzleyin | CVE-2026-46558Kavram kanıtı | Plane: Cross-workspace asset authorization bypass lets any authenticated user read, copy, delete, and overwrite assets in other Plane workspacesplane · plane · CWE-639 | Yüksek8,3 | — | %0,4 | 10 Haz 2026 |
30İzleyin | CVE-2023-2268İstismar yok | Plane v0.7.1 - Unauthorized access to filesplane · plane · CWE-862 | Yüksek7,5 | — | %0,7 | 15 Tem 2023 |
30İzleyin | CVE-2026-30244İstismar yok | Plane: Unauthenticated Workspace Member Information Disclosureplane · plane · CWE-200 | Yüksek7,5 | — | %0,4 | 6 Mar 2026 |
30İzleyin | CVE-2026-27706İstismar yok | Plane Vulnerable to Full Read SSRF via Favicon Fetching in "Add Link" Featureplane · plane · CWE-918 | Yüksek7,7 | — | %0,4 | 25 Şub 2026 |
30İzleyin | CVE-2026-39843İstismar yok | Plane has a Server-Side Request Forgery (SSRF) in Favicon Fetchingplane · plane · CWE-918 | Yüksek7,7 | — | %0,4 | 9 Nis 2026 |
30İzleyin | CVE-2026-39374İstismar yok | Plane IDOR: Cross-Project Issue Date Modification via Bulk Update Endpointplane · plane · CWE-639 | Yüksek7,7 | — | %0,3 | 7 Nis 2026 |
27İzleyin | CVE-2026-10850İstismar yok | Plane 1.3.1 - Stored XSS in intake issue description_htmlplane · plane · CWE-79 | Orta6,9 | — | %0,2 | 17 Haz 2026 |
26İzleyin | CVE-2026-40102İstismar yok | Plane: ORM Field Reference Injection via `segment` Parameter in Saved Analyticsplane · plane · CWE-943 | Orta6,5 | — | %0,4 | 20 May 2026 |
23İzleyin | CVE-2024-47830İstismar yok | Plane allows server side request forgery via /_next/image endpointplane · plane · CWE-918 | Orta5,8 | — | %0,6 | 11 Eki 2024 |
21İzleyin | CVE-2025-21616İstismar yok | Plane has a Cross-site scripting (XSS) via SVG image uploadplane · plane · CWE-79 | Orta5,4 | — | %0,3 | 6 Oca 2025 |
19İzleyin | CVE-2026-27705İstismar yok | Plane Vulnerable to Cross-Workspace/Cross-Project Asset Modification via IDOR in ProjectAssetEndpoint.patchplane · plane · CWE-639 | Orta4,9 | — | %0,4 | 25 Şub 2026 |
18İzleyin | CVE-2023-30791İstismar yok | Plane 0.7.1 - Insecure file uploadplane · plane · CWE-434 | Orta4,6 | — | %0,5 | 15 Tem 2023 |
17İzleyin | CVE-2026-27949İstismar yok | Plane Exposes User Email (PII and part of credential) in GET Parameterplane · plane · CWE-200 | Orta4,3 | — | %0,3 | 7 Nis 2026 |
17İzleyin | CVE-2025-48070İstismar yok | Plane has insecure permissions in UserSerializerplane · plane · CWE-276 | Orta4,3 | — | %0,3 | 21 May 2025 |
17İzleyin | CVE-2025-69284İstismar yok | In plane.io, a Guest User to a Workspace can still be able to see list of membersplane · plane · CWE-284 | Orta4,3 | — | %0,2 | 2 Oca 2026 |
- CVE-2026-3024234İzleyin
Plane: SSRF via Incomplete IP Validation in Webhook URL Serializer
YüksekCVSS 8,5İstismar yokEPSS %0plane · plane6 Mar 2026
- CVE-2026-4655833İzleyin
Plane: Cross-workspace asset authorization bypass lets any authenticated user read, copy, delete, and overwrite assets in other Plane workspaces
YüksekCVSS 8,3Kavram kanıtıEPSS %0plane · plane10 Haz 2026
- CVE-2023-226830İzleyin
Plane v0.7.1 - Unauthorized access to files
YüksekCVSS 7,5İstismar yokEPSS %1plane · plane15 Tem 2023
- CVE-2026-3024430İzleyin
Plane: Unauthenticated Workspace Member Information Disclosure
YüksekCVSS 7,5İstismar yokEPSS %0plane · plane6 Mar 2026
- CVE-2026-2770630İzleyin
Plane Vulnerable to Full Read SSRF via Favicon Fetching in "Add Link" Feature
YüksekCVSS 7,7İstismar yokEPSS %0plane · plane25 Şub 2026
- CVE-2026-3984330İzleyin
Plane has a Server-Side Request Forgery (SSRF) in Favicon Fetching
YüksekCVSS 7,7İstismar yokEPSS %0plane · plane9 Nis 2026
- CVE-2026-3937430İzleyin
Plane IDOR: Cross-Project Issue Date Modification via Bulk Update Endpoint
YüksekCVSS 7,7İstismar yokEPSS %0plane · plane7 Nis 2026
- CVE-2026-1085027İzleyin
Plane 1.3.1 - Stored XSS in intake issue description_html
OrtaCVSS 6,9İstismar yokEPSS %0plane · plane17 Haz 2026
- CVE-2026-4010226İzleyin
Plane: ORM Field Reference Injection via `segment` Parameter in Saved Analytics
OrtaCVSS 6,5İstismar yokEPSS %0plane · plane20 May 2026
- CVE-2024-4783023İzleyin
Plane allows server side request forgery via /_next/image endpoint
OrtaCVSS 5,8İstismar yokEPSS %1plane · plane11 Eki 2024
- CVE-2025-2161621İzleyin
Plane has a Cross-site scripting (XSS) via SVG image upload
OrtaCVSS 5,4İstismar yokEPSS %0plane · plane6 Oca 2025
- CVE-2026-2770519İzleyin
Plane Vulnerable to Cross-Workspace/Cross-Project Asset Modification via IDOR in ProjectAssetEndpoint.patch
OrtaCVSS 4,9İstismar yokEPSS %0plane · plane25 Şub 2026
- CVE-2023-3079118İzleyin
Plane 0.7.1 - Insecure file upload
OrtaCVSS 4,6İstismar yokEPSS %1plane · plane15 Tem 2023
- CVE-2026-2794917İzleyin
Plane Exposes User Email (PII and part of credential) in GET Parameter
OrtaCVSS 4,3İstismar yokEPSS %0plane · plane7 Nis 2026
- CVE-2025-4807017İzleyin
Plane has insecure permissions in UserSerializer
OrtaCVSS 4,3İstismar yokEPSS %0plane · plane21 May 2025
- CVE-2025-6928417İzleyin
In plane.io, a Guest User to a Workspace can still be able to see list of members
OrtaCVSS 4,3İstismar yokEPSS %0plane · plane2 Oca 2026