Comparison Overview

Plumbase

VS

STARK

Plumbase

70 High Park Drive, Old Wolverton Mill East, Milton Keynes, Buckinghamshire, MK12 5TT, GB
Last Update: 2025-03-05 (UTC)
Between 800 and 900

Strong

Plumbase is a national Plumber's merchant supplying heating, plumbing, bathrooms, renewables and boiler spares to professional trade installers.

NAICS: 4233
NAICS Definition: Lumber and Other Construction Materials Merchant Wholesalers
Employees: 627
Subsidiaries: 0
12-month incidents
0
Known data breaches
0
Attack type number
0

STARK

Skanderborgvej 277 Viby J, Denmark 8260, DK
Last Update: 2025-05-06 (UTC)

Strong

Between 800 and 900

STARK is the largest provider of building materials, services and advice and the preferred local partner for professional builders in Denmark. The company was founded in 1896 as a timber yard in Aarhus, Denmark. Over the years, a single timber yard turned into a family of more than 80 locations across Denmark and Greenland. STARK serves both professional contractors and DIY builders. STARK is part of STARK Group that consists of 10,000 people working across more than 420 branches in Northern Europe. Together we are local builders merchants focusing on professional builders in thriving communities โ€šร„รฎ from Rheinfelden-Herten in southern Germany to Tromsโˆšโˆ in northern Norway, and everywhere in between.

NAICS: 4233
NAICS Definition: Lumber and Other Construction Materials Merchant Wholesalers
Employees: 10,001+
Subsidiaries: 0
12-month incidents
0
Known data breaches
0
Attack type number
0

Compliance Badges Comparison

Security & Compliance Standards Overview

https://images.rankiteo.com/companyimages/plumbase.jpeg
Plumbase
โ€”
ISO 27001
Not verified
โ€”
SOC 2
Not verified
โ€”
GDPR
No public badge
โ€”
PCI DSS
No public badge
https://images.rankiteo.com/companyimages/stark.jpeg
STARK
โ€”
ISO 27001
Not verified
โ€”
SOC 2
Not verified
โ€”
GDPR
No public badge
โ€”
PCI DSS
No public badge
Compliance Summary
Plumbase
100%
Compliance Rate
0/4 Standards Verified
STARK
0%
Compliance Rate
0/4 Standards Verified

Benchmark & Cyber Underwriting Signals

Incidents vs Wholesale Building Materials Industry Average (This Year)

No incidents recorded for Plumbase in 2025.

Incidents vs Wholesale Building Materials Industry Average (This Year)

No incidents recorded for STARK in 2025.

Incident History โ€” Plumbase (X = Date, Y = Severity)

Plumbase cyber incidents detection timeline including parent company and subsidiaries

Incident History โ€” STARK (X = Date, Y = Severity)

STARK cyber incidents detection timeline including parent company and subsidiaries

Notable Incidents

Last 3 Security & Risk Events by Company

https://images.rankiteo.com/companyimages/plumbase.jpeg
Plumbase
Incidents

No Incident

https://images.rankiteo.com/companyimages/stark.jpeg
STARK
Incidents

No Incident

FAQ

Both Plumbase company and STARK company demonstrate a comparable AI risk posture, with strong governance and monitoring frameworks in place.

Historically, STARK company has disclosed a higher number of cyber incidents compared to Plumbase company.

In the current year, STARK company and Plumbase company have not reported any cyber incidents.

Neither STARK company nor Plumbase company has reported experiencing a ransomware attack publicly.

Neither STARK company nor Plumbase company has reported experiencing a data breach publicly.

Neither STARK company nor Plumbase company has reported experiencing targeted cyberattacks publicly.

Neither Plumbase company nor STARK company has reported experiencing or disclosing vulnerabilities publicly.

Neither Plumbase company nor STARK company has publicly disclosed detailed information about the number of their subsidiaries.

Plumbase company employs more people globally than STARK company, reflecting its scale as a Wholesale Building Materials.

Latest Global CVEs (Not Company-Specific)

Description

Formbricks is an open source qualtrics alternative. Prior to version 4.0.1, Formbricks is missing JWT signature verification. This vulnerability stems from a token validation routine that only decodes JWTs (jwt.decode) without verifying their signatures. Both the email verification token login path and the password reset server action use the same validator, which does not check the tokenโ€™s signature, expiration, issuer, or audience. If an attacker learns the victimโ€™s actual user.id, they can craft an arbitrary JWT with an alg: "none" header and use it to authenticate and reset the victimโ€™s password. This issue has been patched in version 4.0.1.

Risk Information
cvss3
Base: 9.4
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Description

Apollo Studio Embeddable Explorer & Embeddable Sandbox are website embeddable software solutions from Apollo GraphQL. Prior to Apollo Sandbox version 2.7.2 and Apollo Explorer version 3.7.3, a cross-site request forgery (CSRF) vulnerability was identified. The vulnerability arises from missing origin validation in the client-side code that handles window.postMessage events. A malicious website can send forged messages to the embedding page, causing the victimโ€™s browser to execute arbitrary GraphQL queries or mutations against their GraphQL server while authenticated with the victimโ€™s cookies. This issue has been patched in Apollo Sandbox version 2.7.2 and Apollo Explorer version 3.7.3.

Risk Information
cvss3
Base: 8.2
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:N
Description

A security vulnerability has been detected in Portabilis i-Educar up to 2.10. Affected by this vulnerability is an unknown functionality of the file /consulta-dispensas. Such manipulation leads to improper authorization. The attack may be launched remotely. The exploit has been disclosed publicly and may be used.

Risk Information
cvss2
Base: 6.5
Severity: LOW
AV:N/AC:L/Au:S/C:P/I:P/A:P
cvss3
Base: 6.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
cvss4
Base: 5.3
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

A weakness has been identified in Portabilis i-Educar up to 2.10. Affected is an unknown function of the file /module/Api/aluno. This manipulation of the argument aluno_id causes improper authorization. The attack may be initiated remotely. The exploit has been made available to the public and could be exploited.

Risk Information
cvss2
Base: 6.5
Severity: LOW
AV:N/AC:L/Au:S/C:P/I:P/A:P
cvss3
Base: 6.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
cvss4
Base: 5.3
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

A security flaw has been discovered in Tencent WeKnora 0.1.0. This impacts the function testEmbeddingModel of the file /api/v1/initialization/embedding/test. The manipulation of the argument baseUrl results in server-side request forgery. The attack can be launched remotely. The exploit has been released to the public and may be exploited. It is advisable to upgrade the affected component. The vendor responds: "We have confirmed that the issue mentioned in the report does not exist in the latest releases".

Risk Information
cvss2
Base: 7.5
Severity: LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
cvss3
Base: 7.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
cvss4
Base: 6.9
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X