MEDIUM
CVE-2026-10850
CVSS
5.4
Description
Plane CE 1.3.1 allows a low-privileged project member to submit arbitrary HTML/JS in the description_html field when creating an intake work item through the API v1 intake endpoint.
Weakness (CWE)
CWE-79
Cross-site Scripting (XSS)
EPSS Score
0.17%
Probability of exploitation in next 30 days
6.2th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.