Pierre du Plessis
2 exploits
Active since Jun 2026
SolidInvoice: Unrestricted file upload with no MIME validation allows stored XSS via malicious SVG logo
CVSS 8.1
SolidInvoice: API tokens stored as plaintext in the database allowing full credential compromise on database breach
CVSS 8.1