CVE-2026-10850
EUVD-2026-3773217.06.2026, 15:16
Plane CE 1.3.1 allows a low-privileged project member to submit arbitrary HTML/JS in the description_html field when creating an intake work item through the API v1 intake endpoint.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| plane | plane | 1.3.1 |
𝑥
= Vulnerable software versions