X-Frame-Options and CSP Vulnerabilities in Planka by Planka
CVE-2025-65922

4.3MEDIUM

Key Information:

Vendor

Planka

Status
Vendor
CVE Published:
5 January 2026

What is CVE-2025-65922?

Planka 2.0.0 is susceptible to vulnerabilities due to the absence of X-Frame-Options and Content Security Policy (CSP) frame-ancestors headers. This oversight permits the application to be embedded within malicious iframes, facilitating potential phishing attacks. While the application safeguards against unintended modifications of projects or tasks, it still presents a risk. Attackers can exploit legitimate instances of the Planka application by embedding them in a fake context that can mislead users, thus refining the technique of UI Redressing to capture sensitive information. It is crucial to note that while challenges are acknowledged regarding the feasibility of these attacks, the situation emphasizes the importance of implementing robust security measures.

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.