Makeplane

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 15
    Known Exploited: 0
    2
    Critical Level Threats
    6
    High Level Threats
    5
    Medium Level Threats
    2
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-46558

    Plane: Cross-workspace asset authorization bypass lets any authenticated user read, copy, delete, and overwrite assets in other Plane workspaces

    Last Modified: Jun 12, 2026
    Published: Jun 10, 2026

    CVE-2026-40102

    Plane: ORM Field Reference Injection via `segment` Parameter in Saved Analytics

    Last Modified: May 21, 2026
    Published: May 20, 2026

    CVE-2026-39843

    Plane has a Server-Side Request Forgery (SSRF) in Favicon Fetching

    Last Modified: Apr 17, 2026
    Published: Apr 09, 2026

    CVE-2026-27949

    Plane Exposes User Email (PII and part of credential) in GET Parameter

    Last Modified: Apr 15, 2026
    Published: Apr 07, 2026

    CVE-2026-39374

    Plane IDOR: Cross-Project Issue Date Modification via Bulk Update Endpoint

    Last Modified: Apr 15, 2026
    Published: Apr 07, 2026
    Items Per Page
    Makeplane Vulnerabilities & Security CVEs | CVE-DB