CVE-2026-25812
Severity CVSS v4.0:
CRITICAL
Type:
CWE-352
Cross-Site Request Forgery (CSRF)
Publication date:
09/02/2026
Last modified:
09/02/2026
Description
PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the application enables credentialed CORS requests but does not implement any CSRF protection mechanism.
Impact
Base Score 4.0
9.30
Severity 4.0
CRITICAL



