CVE-2026-105630 - Plane: Stored XSS via SVG attachment served inline on the application origin (account takeover)
CVE ID :CVE-2026-105630 Published : Oct. 5, 2026, 6:17 p.m. | 1 hour, 10 minutes ago Description :Plane is an open-source project management tool. Prior to 1.4.0, an authenticated low-privilege workspace member, including a Guest, can upload an image/svg+xml file as a generic or issue...