Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Plane

First CVE: Jul 15, 2023Active for: 3 yearsTotal CVEs: 17
28.9
VTI Score
Low

Plane is a project-management and collaboration platform that, despite a focused product portfolio, ranks among the more prominent vendors in the vulnerability landscape for its class. The platform's disclosed vulnerabilities center on authorization and data-access weaknesses—including server-side request forgery, authorization bypass through user-controlled keys, improper access control, and exposure of sensitive information—that reflect the authentication and API-design complexity inherent to web-based collaboration tools. Defenders should monitor this vendor's releases for authentication and API boundary issues, particularly in multi-tenant and integration contexts; current severity and exploitation activity are shown alongside this summary.

FAUCET AI Generated
17
Total CVEs
More Total CVEs than 95% of tracked vendors
4.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 97% of tracked vendors
6.4
Avg CVSS Score
Higher Avg CVSS Score than 38% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Plane over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 15, 2023
3 years ago
Most Recent CVE
Jul 21, 2026
3 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (17 CVEs).

17 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-15342MEDIUM
Plane contains a multi‑tenant authorization flaw in its asset‑management API that allows authenticated users from one workspace to access, delete, or duplicate assets belonging to
Jul 21, 20266.530NONO
CVE-2026-39374HIGH
Plane is an an open-source project management tool. Prior to 1.3.0, the IssueBulkUpdateDateEndpoint allows a project member (ADMIN or MEMBER) to modify the start_date and target_da
Apr 7, 20267.730NONO
CVE-2026-46558HIGH
Plane is an open-source project management tool. Prior to version 1.3.1, there is a cross-workspace asset authorization bypass lets any authenticated user read, copy, delete, and o
Jun 10, 20268.329NONO
CVE-2026-30242HIGH
Plane is an an open-source project management tool. Prior to version 1.2.3, the webhook URL validation in plane/app/serializers/webhook.py only checks ip.is_loopback, allowing atta
Mar 6, 20268.529NONO
CVE-2026-40102MEDIUM
Plane is an open-source project management tool. In versions 1.3.0 and below, SavedAnalyticEndpoint passes the user-controlled segment query parameter directly to a Django F() expr
May 20, 20266.527NONO
CVE-2026-39843HIGH
Plane is an an open-source project management tool. From 0.28.0 to before 1.3.0, the remediation of GHSA-jcc6-f9v6-f7jw is incomplete which could lead to the same full read Server-
Apr 9, 20267.726NONO
CVE-2026-27706HIGH
Plane is an an open-source project management tool. Prior to version 1.2.2, a Full Read Server-Side Request Forgery (SSRF) vulnerability has been identified in the "Add Link" featu
Feb 25, 20267.726NONO
CVE-2026-30244HIGH
Plane is an an open-source project management tool. Prior to version 1.2.2, unauthenticated attackers can enumerate workspace members and extract sensitive information including em
Mar 6, 20267.524NONO
CVE-2026-10850MEDIUM
Plane CE 1.3.1 allows a low-privileged project member to submit arbitrary HTML/JS in the description_html field when creating an intake work item through the API v1 intake endpoint
Jun 17, 20265.423NONO
CVE-2026-27705MEDIUM
Plane is an an open-source project management tool. Prior to version 1.2.2, the `ProjectAssetEndpoint.patch()` method in `apps/api/plane/app/views/asset/v2.py` (lines 579–593) perf
Feb 25, 20266.523NONO
View all 17 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products17 CVEs
59%
41%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network17 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low17 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None13 (76.5%)
Unknown0 (0.0%)
Required4 (23.5%)
Privileges Required
Low13 (76.5%)
High0 (0.0%)
None4 (23.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (17 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Plane.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Plane — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Plane's Products

View all 3 CNAs →

Top CWEs