Vulnerabilities > Plane

DATE CVE VULNERABILITY TITLE RISK
2024-10-11 CVE-2024-47830 Server-Side Request Forgery (SSRF) vulnerability in Plane
Plane is an open-source project management tool.
network
low complexity
plane CWE-918
5.8
2023-07-15 CVE-2023-2268 Missing Authorization vulnerability in Plane 0.7.1
Plane version 0.7.1 allows an unauthenticated attacker to view all stored server files of all users.
network
low complexity
plane CWE-862
7.5
2023-07-15 CVE-2023-30791 Unrestricted Upload of File with Dangerous Type vulnerability in Plane 0.7.1
Plane version 0.7.1-dev allows an attacker to change the avatar of his profile, which allows uploading files with HTML extension that interprets both HTML and JavaScript.
network
low complexity
plane CWE-434
4.6