CVE-2026-10850
Vulnerability Description
Plane CE 1.3.1 allows a low-privileged project member to submit arbitrary HTML/JS in the description_html field when creating an intake work item through the API v1 intake endpoint.
Vulnerability Details
Published Date
Last Modified
CWE ID
CWE-79
Source
NVD
Vendor
Plane
Product
Plane
Discussion (0)
Add Comment
No comments yet. Be the first!