CVE-2025-21616: Plane has a Cross-site scripting (XSS) via SVG image upload
Published Jan 6, 2025
·Updated
Plane is an open-source project management tool. A cross-site scripting (XSS) vulnerability has been identified in Plane versions prior to 0.23. The vulnerability allows authenticated users to upload SVG files containing malicious JavaScript code as profile images, which gets executed in victims' browsers when viewing the profile image.
Affected Software
2 affected components
Plane Plane<0.23
Plane Plane<0.23.0
Event History
Jan 6, 2025
CVE Published
via MITRE·09:22 PM
Data Sourced
via MITRE·09:22 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-21616?
CVE-2025-21616 is classified as a high severity cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2025-21616?
To fix CVE-2025-21616, upgrade Plane to version 0.23 or later.
3
Who is affected by CVE-2025-21616?
CVE-2025-21616 affects all versions of Plane prior to 0.23.
4
What type of vulnerability is CVE-2025-21616?
CVE-2025-21616 is a cross-site scripting (XSS) vulnerability.
5
Can authenticated users exploit CVE-2025-21616?
Yes, authenticated users can exploit CVE-2025-21616 by uploading malicious SVG files.