CVE-2026-25812

Severity CVSS v4.0:
CRITICAL
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
09/02/2026
Last modified:
18/02/2026

Description

PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the application enables credentialed CORS requests but does not implement any CSRF protection mechanism.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:prasklatechnology:placipy:1.0.0:*:*:*:*:*:*:*