Vulnerabilities (CVE)

Filtered by vendor Plane Subscribe
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-30791 1 Plane 1 Plane 2023-07-28 N/A 4.6 MEDIUM
Plane version 0.7.1-dev allows an attacker to change the avatar of his profile, which allows uploading files with HTML extension that interprets both HTML and JavaScript.
CVE-2023-2268 1 Plane 1 Plane 2023-07-26 N/A 7.5 HIGH
Plane version 0.7.1 allows an unauthenticated attacker to view all stored server files of all users.