Plane CE 1.3.1 allows a low-privileged project member to submit arbitrary HTML/JS in the description_html field when creating an intake work item through the API v1 intake endpoint.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 18 Jun 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Plane CE 1.3.1 allows a low-privileged project member to submit arbitrary HTML/JS in the description_html field when creating an intake work item through the API v1 intake endpoint. | |
| Title | Plane 1.3.1 - Stored XSS in intake issue description_html | |
| First Time appeared |
Plane
Plane plane |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:plane:plane:1.3.1:*:linux:*:*:*:*:* cpe:2.3:a:plane:plane:1.3.1:*:macos:*:*:*:*:* cpe:2.3:a:plane:plane:1.3.1:*:windows:*:*:*:*:* |
|
| Vendors & Products |
Plane
Plane plane |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Fluid Attacks
Published:
Updated: 2026-06-17T15:39:40.388Z
Reserved: 2026-06-04T12:27:47.258Z
Link: CVE-2026-10850
Updated: 2026-06-17T15:39:32.385Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-18T19:00:11Z
Weaknesses