CVE-2026-25812

HIGH

PlaciPy 1.0.0 - CSRF

Title source: llm
STIX 2.1

Description

PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the application enables credentialed CORS requests but does not implement any CSRF protection mechanism.

Scores

CVSS v3 8.8
EPSS 0.0003
EPSS Percentile 7.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-352
Status published
Products (1)
prasklatechnology/placipy 1.0.0
Published Feb 09, 2026
Tracked Since Feb 18, 2026