VendorsPrasklatechnologyplacipy1.0.0
Vulnerabilities

Prasklatechnology Placipy 1.0.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2026-25814
NoSQL Injection Risk via Unsanitized Query Parameters
Published 2026-02-09 · Analyzed
9.8EPSS 0.006
CVE-2026-25809
PlaciPy Code Execution Allowed Without Assessment Active State Validation
Published 2026-02-09 · Analyzed
9.8EPSS 0.005
CVE-2026-25753
PlaciPy has a Hard-Coded Default Password for All Student Accounts (Account Takeover)
Published 2026-02-06 · Analyzed
9.8EPSS 0.005
CVE-2026-25875
PlaciPy Admin Privilege Escalation via Trusted JWT Claims
Published 2026-02-09 · Analyzed
9.8EPSS 0.005
CVE-2026-25812
PlaciPy is Missing CSRF Protection on State-Changing Endpoints
Published 2026-02-09 · Analyzed
9.3EPSS 0.002
CVE-2026-25810
PlaciPy is Missing Object-Level Authorization in student.submission.routes.ts
Published 2026-02-09 · Analyzed
9.1EPSS 0.005
CVE-2026-25876
PlaciPy is Missing Authorization on Assessment Results Endpoint
Published 2026-02-09 · Analyzed
9.1EPSS 0.005
CVE-2026-25811
PlaciPy Email Domain Trust Enables Cross-Tenant Data Access (Multi-Tenant Isolation Failure)
Published 2026-02-09 · Analyzed
9.1EPSS 0.004
CVE-2026-25813
PlaciPy Exposes Sensitive Data via Application Logs
Published 2026-02-09 · Analyzed
8.7EPSS 0.004
CVE-2026-25806
PlaciPy has Missing Authorization Checks on Student Management Endpoints (IDOR)
Published 2026-02-09 · Analyzed
6.5EPSS 0.004