makeplane plane

39 known vulnerabilities in makeplane plane, 6 critical, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-105641 CVSS 9.8 critical Plane is an open-source project management tool. Prior to 1.4.0, the deployments/aio/community/ and deployments/cli/community/ manifests…
  • CVE-2026-105640 CVSS 9.1 critical Plane is an open-source project management tool. Prior to 1.4.0, Plane trusts email addresses returned by Gitea OAuth and by self-managed…
  • CVE-2026-105639 CVSS 9.8 critical Plane is an open-source project management tool. Prior to 1.4.0, Plane's signup flow creates a logged-in User row for any submitted email…
  • CVE-2026-105638 CVSS 9.1 critical Plane is an open-source project management tool. Prior to 1.4.0, Plane's magic-code email login uses a six-digit numeric OTP with…
  • CVE-2026-105637 CVSS 9.6 critical Plane is an open-source project management tool. Prior to 1.4.0, ProjectBulkAssetEndpoint.post in apps/api/plane/app/views/asset/v2.py…
  • CVE-2026-105636 CVSS 9.9 critical Plane is an open-source project management tool. Prior to 1.4.0, the webhook delivery task in apps/api/plane/bgtasks/webhook_task.py calls…
  • CVE-2026-105635 CVSS 7.4 high Plane is an open-source project management tool. Prior to 1.4.0, ProjectJoinEndpoint at GET…
  • CVE-2026-105634 CVSS 8.1 high Plane is an open-source project management tool. Prior to 1.3.0, the ProjectMemberViewSet.partial_update method allows any project member…
  • CVE-2026-105633 CVSS 7.1 high Plane is an open-source project management tool. Prior to 1.4.0, the V2 issue-attachment PATCH endpoint accepts issue_id in the URL but…
  • CVE-2026-105632 CVSS 8.7 high Plane is an open-source project management tool. Prior to 1.4.0, the GraphQL joinProject mutation lets any workspace member add themselves…
  • CVE-2026-105631 CVSS 7.5 high Plane is an open-source project management tool. Prior to 1.4.0, WorkspaceFileAssetEndpoint.get and WorkspaceAssetDownloadEndpoint.get…
  • CVE-2026-105630 CVSS 8.7 high Plane is an open-source project management tool. Prior to 1.4.0, an authenticated low-privilege workspace member, including a Guest, can…
  • CVE-2026-105629 CVSS 7.1 high Plane is an open-source project management tool. Prior to 1.4.0, BulkEstimatePointEndpoint.destroy resolves an estimate point through a…
  • CVE-2026-105628 CVSS 7.6 high Plane is an open-source project management tool. Prior to 1.4.0, Plane's OAuth avatar synchronization flow fetches avatar_url from…
  • CVE-2026-104979 CVSS 8.7 high Plane is an open-source project management tool. Prior to 1.4.0, IntakeIssuePublicViewSet.create in Plane v1.3.1 writes description_html…
  • CVE-2026-104978 CVSS 8.2 high Plane is an open-source project management tool. Prior to 1.4.0, Plane's project invitation list endpoint is accessible to any…
  • CVE-2026-104977 CVSS 7.7 high Plane is an open-source project management tool. Prior to 1.4.0, the fix for CVE-2026-27706 and GHSA-jcc6-f9v6-f7jw, an SSRF in work-item…
  • CVE-2026-104976 CVSS 8.7 high Plane is an open-source project management tool. Prior to 1.4.0, Plane validates GITEA_HOST only for its URL scheme and does not reject…
  • CVE-2026-104975 CVSS 7.1 high Plane is an open-source project management tool. Prior to 1.4.0, Plane's dashboard asset endpoints in plane/app/views/asset/v2.py were…
  • CVE-2026-104974 CVSS 8.1 high Plane is an open-source project management tool. Prior to 1.4.0, a user whose account has been deactivated by setting is_active=False can…
  • CVE-2026-104973 CVSS 7.6 high Plane is an open-source project management tool. Prior to 1.4.0, the fix for CVE-2026-30242 validates webhook IP addresses only when the…
  • CVE-2026-104971 CVSS 8.5 high Plane is an open-source project management tool. Prior to 1.4.0, DuplicateAssetEndpoint fetches a source FileAsset without limiting it to…
  • CVE-2026-104970 CVSS 8.1 high Plane is an open-source project management tool. From 0.13 until 1.4.0, InstanceAdminSignUpEndpoint in…
  • CVE-2026-104969 CVSS 6.5 medium Plane is an open-source project management tool. Prior to 1.4.0, the cycle-issues endpoint accepts issue UUIDs in the request body without…
  • CVE-2026-104968 CVSS 8.7 high Plane is an open-source project management tool. Prior to 1.4.0, GET /api/workspaces/{slug}/entity-search/?query_type=user_mention returns…
  • CVE-2026-104967 CVSS 5.4 medium Plane is an open-source project management tool. Prior to 1.4.0, BulkDeleteIssuesEndpoint and SubIssuesEndpoint in…
  • CVE-2026-104966 CVSS 8.7 high Plane is an open-source project management tool. Prior to 1.4.0, two endpoint families fail to verify that nested resource identifiers…
  • CVE-2026-104965 CVSS 5.4 medium Plane is an open-source project management tool. Prior to 1.4.0, the issue-relation endpoint accepts issue UUIDs in the request body…
  • CVE-2026-104964 CVSS 6.8 medium Plane is an open-source project management tool. Prior to 1.4.0, Plane's project update endpoint authorizes the caller against the…
  • CVE-2026-104963 CVSS 4.3 medium Plane is an open-source project management tool. Prior to 1.4.0, GET /api/workspaces/{slug}/cycles/ through WorkspaceCyclesEndpoint and…