Description
Plane CE 1.3.1 allows a low-privileged project member to submit arbitrary HTML/JS in the description_html field when creating an intake work item through the API v1 intake endpoint.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Thu, 18 Jun 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Plane CE 1.3.1 allows a low-privileged project member to submit arbitrary HTML/JS in the description_html field when creating an intake work item through the API v1 intake endpoint. | |
| Title | Plane 1.3.1 - Stored XSS in intake issue description_html | |
| First Time appeared |
Plane
Plane plane |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:plane:plane:1.3.1:*:linux:*:*:*:*:* cpe:2.3:a:plane:plane:1.3.1:*:macos:*:*:*:*:* cpe:2.3:a:plane:plane:1.3.1:*:windows:*:*:*:*:* |
|
| Vendors & Products |
Plane
Plane plane |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Fluid Attacks
Published:
Updated: 2026-06-17T15:39:40.388Z
Reserved: 2026-06-04T12:27:47.258Z
Link: CVE-2026-10850
Updated: 2026-06-17T15:39:32.385Z
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')