📦 Placipy

by Prasklatechnology

🔍 What is Placipy?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2026-25814

CRITICAL CVSS 9.8 Feb 9, 2026

PlaciPy version 1.0.0 passes user-controlled query parameters directly into DynamoDB query/filter construction without validation or sanitization. This allows attackers to inject malicious queries tha...

CVE-2026-25875

CRITICAL CVSS 9.8 Feb 9, 2026

This vulnerability allows attackers to bypass authorization in PlaciPy placement management systems by manipulating JWT claims. Attackers can escalate privileges to admin level without proper server-s...

CVE-2026-25811

CRITICAL CVSS 9.1 Feb 9, 2026

PlaciPy placement management system version 1.0.0 allows cross-tenant data access by deriving tenant identifiers from user-provided email domains without validating domain ownership. This vulnerabilit...

CVE-2026-25810

CRITICAL CVSS 9.1 Feb 9, 2026

PlaciPy placement management system version 1.0.0 has an authorization vulnerability where authenticated users can access other users' student submission data due to missing ownership checks. This aff...

CVE-2026-25876

CRITICAL CVSS 9.1 Feb 9, 2026

PlaciPy placement management system version 1.0.0 has a missing object-level authorization vulnerability that allows authenticated users to access assessment results they shouldn't have permission to ...

CVE-2026-25809

CRITICAL CVSS 9.8 Feb 9, 2026

This vulnerability in PlaciPy version 1.0.0 allows attackers to execute code evaluation outside of intended assessment windows due to missing lifecycle state validation. Educational institutions using...

CVE-2026-25753

CRITICAL CVSS 9.8 Feb 6, 2026

PlaciPy placement management system version 1.0.0 uses a hard-coded default password for all newly created student accounts, enabling attackers to log in as any student once this password is discovere...

CVE-2026-25812

HIGH CVSS 8.8 Feb 9, 2026

PlaciPy placement management system lacks CSRF protection while allowing credentialed CORS requests, enabling attackers to perform unauthorized actions on behalf of authenticated users. Educational in...

CVE-2026-25813

HIGH CVSS 7.5 Feb 9, 2026

PlaciPy placement management system logs sensitive data to console output without redaction in version 1.0.0. This allows attackers with access to console logs to view confidential information. Educat...

CVE-2026-25806

MEDIUM CVSS 6.5 Feb 9, 2026

This CVE describes a missing authorization vulnerability in PlaciPy placement management system. Authenticated users can access, modify, or delete any student record regardless of permissions, affecti...