makeplane
- Total products in the ecosystem
- 1
- Total vulnerabilities (90 days)
- 1
en
Verify to analyze this security profile
As of 09/15/2026, makeplane recorded 1 security vulnerabilities in the last 90 days across 1 products, including 0 rated High or above and 0 known exploited vulnerabilities (KEV) that should be prioritized for immediate remediation.
Over the last 90 days, plane had the most security vulnerabilities in the makeplane ecosystem, with 1 vulnerabilities—approximately 100% of the provider's total vulnerabilities during this period.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan| Vulnerability | Exploitation status | Fix | Affected product | Published | Severity |
|---|---|---|---|---|---|
CVE-2026-86174Plane through 1.4.2 Arbitrary Comment Write via Public Deploy Board | Exploitation statusNot known exploited | FixYes | Affected productplane | Published09/05/2026 | SeverityMedium |
CVE-2026-46558Plane: Cross-workspace asset authorization bypass lets any authenticated user read, copy, delete, and overwrite assets in other Plane workspaces | Exploitation statusPublic exploit | FixYes | Affected productplane | Published06/10/2026 | SeverityHigh |
CVE-2026-40102Plane: ORM Field Reference Injection via `segment` Parameter in Saved Analytics | Exploitation statusPublic exploit | FixYes | Affected productplane | Published05/20/2026 | SeverityMedium |
CVE-2026-39843Plane has a Server-Side Request Forgery (SSRF) in Favicon Fetching | Exploitation statusPublic exploit | FixYes | Affected productplane | Published04/09/2026 | SeverityHigh |
CVE-2026-27949Plane Exposes User Email (PII and part of credential) in GET Parameter | Exploitation statusNot known exploited | FixYes | Affected productplane | Published04/07/2026 | SeverityLow |
CVE-2026-39374Plane IDOR: Cross-Project Issue Date Modification via Bulk Update Endpoint | Exploitation statusPublic exploit | FixYes | Affected productplane | Published04/07/2026 | SeverityMedium |
CVE-2026-30242Plane: SSRF via Incomplete IP Validation in Webhook URL Serializer | Exploitation statusNot known exploited | FixYes | Affected productplane | Published03/06/2026 | SeverityHigh |
CVE-2026-30244Plane: Unauthenticated Workspace Member Information Disclosure | Exploitation statusNot known exploited | FixYes | Affected productplane | Published03/06/2026 | SeverityHigh |
CVE-2026-27706Plane Vulnerable to Full Read SSRF via Favicon Fetching in "Add Link" Feature | Exploitation statusNot known exploited | FixNot confirmed | Affected productplane | Published02/25/2026 | SeverityHigh |
CVE-2026-27705Plane Vulnerable to Cross-Workspace/Cross-Project Asset Modification via IDOR in ProjectAssetEndpoint.patch | Exploitation statusNot known exploited | FixNot confirmed | Affected productplane | Published02/25/2026 | SeverityMedium |
CVE-2025-69284In plane.io, a Guest User to a Workspace can still be able to see list of members | Exploitation statusNot known exploited | FixNot confirmed | Affected productplane | Published01/02/2026 | SeverityMedium |
CVE-2025-62716Plane Vulnerable to Cross-Site Scripting via Open Redirect in ?next_path Parameter | Exploitation statusPublic exploit | FixYes | Affected productplane | Published10/24/2025 | SeverityHigh |
CVE-2025-55203Plane Stored XSS in Add Work Item Functionality | Exploitation statusNot known exploited | FixYes | Affected productplane | Published08/15/2025 | SeverityMedium |
CVE-2025-48070Plane has insecure permissions in UserSerializer | Exploitation statusPublic exploit | FixNot confirmed | Affected productplane | Published05/21/2025 | SeverityLow |
CVE-2025-21616Plane has a Cross-site scripting (XSS) via SVG image upload | Exploitation statusPublic exploit | FixNot confirmed | Affected productplane | Published01/06/2025 | SeverityMedium |
CVE-2024-47830Plane allows server side request forgery via /_next/image endpoint | Exploitation statusPublic exploit | FixYes | Affected productplane | Published10/11/2024 | SeverityCritical |
CVE-2024-31461Plane Server-Side Request Forgery (SSRF) Vulnerability | Exploitation statusNot known exploited | FixNot confirmed | Affected productplane | Published04/10/2024 | SeverityCritical |