Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-10850 |
|
Cross-Site Scripting (XSS) in plane (CVE-2026-10850)
cross-site scripting in plane (CVE-2026-10850). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-46558 |
|
Vulnerability in plane (CVE-2026-46558)
vulnerability in plane (CVE-2026-46558). Confidential information can be exposed externally.
|
| CVE-2026-40102 |
|
Vulnerability in django (CVE-2026-40102)
vulnerability in django (CVE-2026-40102). Confidential information can be exposed externally. Exploitable via `GET /api/workspaces/`.
|
| CVE-2026-39374 |
|
Vulnerability in plane (CVE-2026-39374)
vulnerability in plane (CVE-2026-39374). Data can be tampered with by attackers. Mitigation: upgrade to `1.3.0` or later.
|