Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.5 MEDIUM
CVE-2026-104969 — Plane: Cross-Tenant Cycle Issue Hijack via IDOR

Plane is an open-source project management tool. Prior to 1.4.0, the cycle-issues endpoint accepts issue UUIDs in the request body without validating that they belong to the caller's workspace. An au…

plane | Remote | Authorization
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
8.7 HIGH
CVE-2026-104968 — Plane: Cross-workspace member enumeration via /api/workspaces/{slug}/entity-search/

Plane is an open-source project management tool. Prior to 1.4.0, GET /api/workspaces/{slug}/entity-search/?query_type=user_mention returns workspace-member display names, UUIDs, and avatar URLs to an…

plane | Remote | Information Disclosure
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
5.4 MEDIUM
CVE-2026-104967 — Plane: Cross-workspace association destruction and issue mutation/read via unscoped queri…

Plane is an open-source project management tool. Prior to 1.4.0, BulkDeleteIssuesEndpoint and SubIssuesEndpoint in apps/api/plane/app/views/issue/ accept body- or URL-supplied issue IDs and operate o…

plane | Remote | Authorization
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
8.7 HIGH
CVE-2026-104966 — Plane: Cross-Workspace IDOR in Estimate and Comment Endpoints Allows Read, Modify, and In…

Plane is an open-source project management tool. Prior to 1.4.0, two endpoint families fail to verify that nested resource identifiers belong to the workspace and project named in the URL. An authent…

plane | Remote | Authorization
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
5.4 MEDIUM
CVE-2026-104965 — Plane: Cross-Tenant Issue Relation Creation via IDOR

Plane is an open-source project management tool. Prior to 1.4.0, the issue-relation endpoint accepts issue UUIDs in the request body without validating that they belong to the caller's workspace. An …

plane | Remote | Authorization
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
6.8 MEDIUM
CVE-2026-104964 — Plane: Cross-Workspace Project Modification via Unscoped Project Lookup

Plane is an open-source project management tool. Prior to 1.4.0, Plane's project update endpoint authorizes the caller against the workspace slug in the request URL but loads the target project globa…

plane | Remote | Authorization
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
4.3 MEDIUM
CVE-2026-104963 — Plane: Workspace cycle and module endpoints missing project-membership filter expose priv…

Plane is an open-source project management tool. Prior to 1.4.0, GET /api/workspaces/{slug}/cycles/ through WorkspaceCyclesEndpoint and GET /api/workspaces/{slug}/modules/ through WorkspaceModulesEnd…

plane | Remote | Authorization
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
6.5 MEDIUM
CVE-2026-104962 — Plane: Cross-project member roster IDOR in ProjectMemberListCreateAPIEndpoint (missing pr…

Plane is an open-source project management tool. Prior to 1.4.0, GET /api/v1/workspaces/{slug}/projects/{project_id}/members/ returns the complete project-member roster, including each member's email…

plane | Remote | Information Disclosure
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
5.4 MEDIUM
CVE-2026-104961 — Plane: WorkspaceOwnerPermission missing is_active check allows deactivated users to retai…

Plane is an open-source project management tool. Prior to 1.4.0, WorkspaceOwnerPermission does not require is_active=True when checking whether a user is a workspace owner. A deactivated user can the…

plane | Remote
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
6.5 MEDIUM
CVE-2026-104960 — Plane: Authorization bypass in workspace-scoped asset download endpoint exposes secret pr…

Plane is an open-source project management tool. Prior to 1.4.0, Plane exposes the workspace-scoped GET /api/assets/v2/workspaces/{workspace_slug}/download/{asset_id}/ endpoint for project-bound File…

plane | Remote | Authorization
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
5.3 MEDIUM
CVE-2026-104956 — Plane: Unauthenticated ORM field-name injection via `group_by`/`sub_group_by` on public d…

Plane is an open-source project management tool. Prior to 1.4.0, the unauthenticated public issues endpoint accepts group_by and sub_group_by query parameters and passes them without an allowlist to …

plane | Remote | Injection
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
5.4 MEDIUM
CVE-2026-104955 — Plane: Project Member can escalate Project Guest to Member via PATCH /project-members/{pk…

Plane is an open-source project management tool. Prior to 1.4.0, a Project Member with role 15 can send a PATCH request to the project-member update endpoint at /api/workspaces/{workspace_slug}/proje…

plane | Remote | Authorization
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
4.3 MEDIUM
CVE-2026-104894 — Plane: Cross-Tenant Module Issue Linking via IDOR

Plane is an open-source project management tool. Prior to 1.4.0, the modules endpoint accepts issue UUIDs in the URL path without validating that they belong to the caller's workspace. An authenticat…

plane | Remote | Authorization
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
5.4 MEDIUM
CVE-2026-104893 — Plane: Improper validation allows arbitrary modification of API token rate limits

Plane is an open-source project management tool. Prior to 1.4.0, GET /api/users/api-tokens/ allows an authenticated user to retrieve API-token records, while PATCH /api/users/api-tokens/{token_id}/ a…

plane | Remote | Denial of Service
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
6.9 MEDIUM
CVE-2026-102779 — Joomla Extension - joomlafry.com - Unauthenticated forced execution of published automati…

Joomla Extension - joomlafry.com - Unauthenticated forced execution of published automation tasks in TF Content 2.9.0 - 2.9.4 - The extension exposes the site task `records.custom_action` without aut…

Remote | Authorization
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
6.3 MEDIUM
CVE-2026-102777 — Joomla Extension - svenbluege.de - Server-side request forgery in the Google Photos picke…

Joomla Extension - svenbluege.de - Server-side request forgery in the Google Photos picker in Event Gallery extension < 6.6.0 - The Google Photos picker of the back-end upload page fetches the thumbn…

Remote | Server-Side Request Forgery
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
7.1 HIGH
CVE-2026-102282 — adm-zip extraction preserves SUID/SGID bits from untrusted ZIPs -> local privilege escala…

adm-zip is a JavaScript library for creating and extracting ZIP archives in Node.js. Prior to 0.6.1, adm-zip applies the Unix permission bits stored in a zip entry directly to the extracted file via …

adm-zip | Authorization
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
0.0 NA
CVE-2026-88397 — ApiAdmin SQL Injection

ApiAdmin v.5.0 and before is vulnerable to SQL Injection in the user-list endpoint GET /admin/User/getUsers via the gid parameter.

| Injection
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
0.0 NA
CVE-2026-88396 — ApiAdmin Arbitrary File Upload to Remote Code Execution

ApiAdmin v5.0 and before is vulnerable to Directory Traversal. The admin file-upload endpoint POST /admin/Index/upload in ApiAdmin takes the uploaded file's extension verbatim there is no whitelist, …

| Path Traversal
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
0.0 NA
CVE-2026-88395 — GouGuOA SQL Injection Vulnerability

GouGuOA v6.0.5 and before is vulnerable to SQL Injection in /home/message/rubbish via the keywords parameter.

| Injection
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
Showing 20 of 14411 Results