CVE-2025-21616

Plane is an open-source project management tool. A cross-site scripting (XSS) vulnerability has been identified in Plane versions prior to 0.23. The vulnerability allows authenticated users to upload SVG files containing malicious JavaScript code as profile images, which gets executed in victims' browsers when viewing the profile image.
CVSS

No CVSS.

Configurations

Configuration 1 (hide)

cpe:2.3:a:plane:plane:*:*:*:*:*:*:*:*

History

20 Jun 2025, 18:08

Type Values Removed Values Added
References () https://github.com/makeplane/plane/security/advisories/GHSA-rcg8-g69v-x23j - () https://github.com/makeplane/plane/security/advisories/GHSA-rcg8-g69v-x23j - Exploit, Vendor Advisory
CPE cpe:2.3:a:plane:plane:*:*:*:*:*:*:*:*
First Time Plane plane
Plane

07 Jan 2025, 16:15

Type Values Removed Values Added
CWE CWE-79

06 Jan 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-06 22:15

Updated : 2025-06-20 18:08


NVD link : CVE-2025-21616

Mitre link : CVE-2025-21616


JSON object : View

Products Affected

plane

  • plane
CWE

No CWE.