CVE-2026-10850 - Plane 1.3.1 - Stored XSS in intake issue description_html
CVE ID :CVE-2026-10850
Published : June 17, 2026, 2:39 p.m. | 59 minutes ago
Description :Plane CE 1.3.1 allows a low-privileged project member to submit arbitrary HTML/JS in the description_html field when creating an intake work item through the API v1 intake endpoint.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : June 17, 2026, 2:39 p.m. | 59 minutes ago
Description :Plane CE 1.3.1 allows a low-privileged project member to submit arbitrary HTML/JS in the description_html field when creating an intake work item through the API v1 intake endpoint.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...