Plane
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 57 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from July 15, 2023 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →Plane: Hardcoded SECRET_KEY and LIVE_SERVER_SECRET_KEY shipped in aio/cli community deployment manifests — session forgery and live-server auth bypass
Plane: Account Takeover via Unverified OAuth Email Match (Gitea, self-managed GitLab)
Plane: Pre-auth workspace invitation hijack via email-squat and self-served invitation token leak in Plane
Plane: Magic-code verifier endpoint has no rate limit, enabling 6-digit OTP brute force
Plane: Cross-Project Asset Hijacking via 'ProjectBulkAssetEndpoint' (sibling of CVE-2026-46558)
Plane: SSRF via HTTP redirect in webhook delivery (allow_redirects not set)
Plane: Unauthenticated Project Invitation Email Disclosure Enables Unauthorized Project Join Without Token
Plane: Privilege Escalation: Project Guest Can Demote Admin/Member Roles
Plane: Issue Attachment Ownership Hijacking via Missing `issue_id` Scope
Plane: Broken Access Control - joinProject GraphQL mutation allows self-join into private (secret) projects
Monitor Plane in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.