← Vulnerability feed

Vulnerability record · CVE-2025-21616 · published 6 January 2025

CVE-2025-21616: Plane cross-site scripting vulnerability

Plane · Plane

Plane is an open-source project management tool. A cross-site scripting (XSS) vulnerability has been identified in Plane versions prior to 0.23. The vulnerability allows authenticated users to upload SVG files containing malicious JavaScript code as profile images, which gets executed in victims' browsers when viewing the profile image.

5.4 CVSS 3.1 Medium EPSS 0.27% · top 82.7% CWE-79 · Cross-site scripting
5.4CVSS 3.1 base score
0.27%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Plane is an open-source project management tool. A cross-site scripting (XSS) vulnerability has been identified in Plane versions prior to 0.23. The vulnerability allows authenticated users to upload SVG files containing malicious JavaScript code as profile images, which gets executed in victims' browsers when viewing the profile image.

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-21616 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.5CVE-2026-30242Plane server-side request forgery (ssrf) vulnerabilityPlane is an an open-source project management tool. Prior to version 1.2.3, the webhook URL validation in plane/app/serializers/webhook.py only check…EPSS 0.33%8.3CVE-2026-46558Plane insecure direct object reference vulnerabilityPlane is an open-source project management tool. Prior to version 1.3.1, there is a cross-workspace asset authorization bypass lets any authenticated…EPSS 0.40%7.7CVE-2026-39843Plane server-side request forgery (ssrf) vulnerabilityPlane is an an open-source project management tool. From 0.28.0 to before 1.3.0, the remediation of GHSA-jcc6-f9v6-f7jw is incomplete which could lea…EPSS 0.35%7.7CVE-2026-39374Plane insecure direct object reference vulnerabilityPlane is an an open-source project management tool. Prior to 1.3.0, the IssueBulkUpdateDateEndpoint allows a project member (ADMIN or MEMBER) to modi…EPSS 0.31%7.7CVE-2026-27706Plane server-side request forgery (ssrf) vulnerabilityPlane is an an open-source project management tool. Prior to version 1.2.2, a Full Read Server-Side Request Forgery (SSRF) vulnerability has been ide…EPSS 0.37%7.5CVE-2026-30244Plane information exposure vulnerabilityPlane is an an open-source project management tool. Prior to version 1.2.2, unauthenticated attackers can enumerate workspace members and extract sen…EPSS 0.42%7.5CVE-2023-2268Plane missing authorization vulnerabilityPlane version 0.7.1 allows an unauthenticated attacker to view all stored server files of all users.EPSS 0.66%6.9CVE-2026-10850Plane cross-site scripting vulnerabilityPlane CE 1.3.1 allows a low-privileged project member to submit arbitrary HTML/JS in the description_html field when creating an intake work item thr…EPSS 0.17%

Source: NIST National Vulnerability Database (record CVE-2025-21616), CISA KEV, FIRST EPSS (scores of 2026-10-02). This page is refreshed as NVD updates the record.