Plane
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 19 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from July 15, 2023 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →Plane through 1.4.2 Arbitrary Comment Write via Public Deploy Board
Plane 1.3.1 - Stored XSS in intake issue description_html
Plane: Cross-workspace asset authorization bypass lets any authenticated user read, copy, delete, and overwrite assets in other Plane workspaces
Plane: ORM Field Reference Injection via `segment` Parameter in Saved Analytics
Plane has a Server-Side Request Forgery (SSRF) in Favicon Fetching
Plane Exposes User Email (PII and part of credential) in GET Parameter
Plane IDOR: Cross-Project Issue Date Modification via Bulk Update Endpoint
Plane: Unauthenticated Workspace Member Information Disclosure
Plane: SSRF via Incomplete IP Validation in Webhook URL Serializer
Plane Vulnerable to Full Read SSRF via Favicon Fetching in "Add Link" Feature
Monitor Plane in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.