Plane is a project-management and collaboration platform that, despite a focused product portfolio, ranks among the more prominent vendors in the vulnerability landscape for its class. The platform's disclosed vulnerabilities center on authorization and data-access weaknesses—including server-side request forgery, authorization bypass through user-controlled keys, improper access control, and exposure of sensitive information—that reflect the authentication and API-design complexity inherent to web-based collaboration tools. Defenders should monitor this vendor's releases for authentication and API boundary issues, particularly in multi-tenant and integration contexts; current severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Plane over time
Signals from CVEs in this vendor scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-15342MEDIUM Plane contains a multi‑tenant authorization flaw in its asset‑management API that allows authenticated users from one workspace to access, delete, or duplicate assets belonging to | Jul 21, 2026 | 6.5 | 30 | NO | NO |
CVE-2026-39374HIGH Plane is an an open-source project management tool. Prior to 1.3.0, the IssueBulkUpdateDateEndpoint allows a project member (ADMIN or MEMBER) to modify the start_date and target_da | Apr 7, 2026 | 7.7 | 30 | NO | NO |
CVE-2026-46558HIGH Plane is an open-source project management tool. Prior to version 1.3.1, there is a cross-workspace asset authorization bypass lets any authenticated user read, copy, delete, and o | Jun 10, 2026 | 8.3 | 29 | NO | NO |
CVE-2026-30242HIGH Plane is an an open-source project management tool. Prior to version 1.2.3, the webhook URL validation in plane/app/serializers/webhook.py only checks ip.is_loopback, allowing atta | Mar 6, 2026 | 8.5 | 29 | NO | NO |
CVE-2026-40102MEDIUM Plane is an open-source project management tool. In versions 1.3.0 and below, SavedAnalyticEndpoint passes the user-controlled segment query parameter directly to a Django F() expr | May 20, 2026 | 6.5 | 27 | NO | NO |
CVE-2026-39843HIGH Plane is an an open-source project management tool. From 0.28.0 to before 1.3.0, the remediation of GHSA-jcc6-f9v6-f7jw is incomplete which could lead to the same full read Server- | Apr 9, 2026 | 7.7 | 26 | NO | NO |
CVE-2026-27706HIGH Plane is an an open-source project management tool. Prior to version 1.2.2, a Full Read Server-Side Request Forgery (SSRF) vulnerability has been identified in the "Add Link" featu | Feb 25, 2026 | 7.7 | 26 | NO | NO |
CVE-2026-30244HIGH Plane is an an open-source project management tool. Prior to version 1.2.2, unauthenticated attackers can enumerate workspace members and extract sensitive information including em | Mar 6, 2026 | 7.5 | 24 | NO | NO |
CVE-2026-10850MEDIUM Plane CE 1.3.1 allows a low-privileged project member to submit arbitrary HTML/JS in the description_html field when creating an intake work item through the API v1 intake endpoint | Jun 17, 2026 | 5.4 | 23 | NO | NO |
CVE-2026-27705MEDIUM Plane is an an open-source project management tool. Prior to version 1.2.2, the `ProjectAssetEndpoint.patch()` method in `apps/api/plane/app/views/asset/v2.py` (lines 579–593) perf | Feb 25, 2026 | 6.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (17 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Plane.
Media articles that mention a CVE ID that affects a product developed by Plane — matched by CVE ID, not by vendor name.