Plane is an open-source project management tool. A cross-site scripting (XSS) vulnerability has been identified in Plane versions prior to 0.23. The vulnerability allows authenticated users to upload SVG files containing malicious JavaScript code as profile images, which gets executed in victims' browsers when viewing the profile image.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
EUVD-2025-2573 | Plane is an open-source project management tool. A cross-site scripting (XSS) vulnerability has been identified in Plane versions prior to 0.23. The vulnerability allows authenticated users to upload SVG files containing malicious JavaScript code as profile images, which gets executed in victims' browsers when viewing the profile image. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 20 Jun 2025 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Plane
Plane plane |
|
CPEs | cpe:2.3:a:plane:plane:*:*:*:*:*:*:*:* | |
Vendors & Products |
Plane
Plane plane |
Tue, 07 Jan 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 06 Jan 2025 21:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Plane is an open-source project management tool. A cross-site scripting (XSS) vulnerability has been identified in Plane versions prior to 0.23. The vulnerability allows authenticated users to upload SVG files containing malicious JavaScript code as profile images, which gets executed in victims' browsers when viewing the profile image. | |
Title | Plane has a Cross-site scripting (XSS) via SVG image upload | |
Weaknesses | CWE-79 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-01-07T15:46:31.863Z
Reserved: 2024-12-29T03:00:24.713Z
Link: CVE-2025-21616

Updated: 2025-01-07T15:46:12.588Z

Status : Analyzed
Published: 2025-01-06T22:15:11.023
Modified: 2025-06-20T18:08:44.170
Link: CVE-2025-21616

No data.

No data.