Known Vulnerabilities for products from Plane
Listed below are 6 of the newest known vulnerabilities associated with the vendor "Plane".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-46414 json | Not Provided | 2026-05-27 | 2026-05-27 | |
| CVE-2026-46209 json | Not Provided | 2026-05-28 | 2026-05-28 | |
| CVE-2026-46101 json | Not Provided | 2026-05-27 | 2026-05-27 | |
| CVE-2026-45845 json | Not Provided | 2026-05-27 | 2026-05-27 | |
| CVE-2026-44328 json | Not Provided | 2026-05-27 | 2026-05-27 | |
| CVE-2026-42296 json | Not Provided | 2026-05-09 | 2026-05-12 | |
| CVE-2026-40102 json | Plane is an open-source project management tool. In versions 1.3.0 and below, SavedAnalyticEndpoint passes the user-controlle... | Not Provided | 2026-05-20 | 2026-05-21 |
| CVE-2026-39843 json | Plane is an an open-source project management tool. From 0.28.0 to before 1.3.0, the remediation of GHSA-jcc6-f9v6-f7jw is in... | Not Provided | 2026-04-09 | 2026-04-17 |
| CVE-2026-39429 json | Not Provided | 2026-04-08 | 2026-04-10 | |
| CVE-2026-39374 json | Plane is an an open-source project management tool. Prior to 1.3.0, the IssueBulkUpdateDateEndpoint allows a project member (... | Not Provided | 2026-04-07 | 2026-04-15 |
| CVE-2026-27949 json | Plane is an an open-source project management tool. Prior to 1.3.0, a vulnerability was identified in Plane's authentication ... | Not Provided | 2026-04-07 | 2026-04-14 |
| CVE-2023-30791 json | Plane version 0.7.1-dev allows an attacker to change the avatar of his profile, which allows uploading files with HTML extens... | 4.6 - MEDIUM | 2023-07-15 | 2023-07-28 |
| CVE-2023-2268 json | Plane version 0.7.1 allows an unauthenticated attacker to view all stored server files of all users. | 7.5 - HIGH | 2023-07-15 | 2023-07-26 |