Product
Planka versions 2.2.0 through 2.2.1 contain a vulnerability in the TOTP verification endpoint that lacks rate-limiting, allowing attackers with known user passwords to brute-force two-factor authentication tokens.