Bas S
3 exploits
Active since May 2018
Pluck < 4.7.6 - Authenticated Stored Cross-Site Scripting via Filename
CVSS 4.8
Pluck < 4.7.6 - Remote Code Execution via Unrestricted File Upload
CVSS 9.8
PluckCMS <4.7.4 - Unrestricted Upload of File with Dangerous Type
CVSS 9.8