CVE-2026-25753

Severity CVSS v4.0:
CRITICAL
Type:
CWE-259 Use of Hard-coded Password
Publication date:
06/02/2026
Last modified:
11/02/2026

Description

PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the application uses a hard-coded, static default password for all newly created student accounts. This results in mass account takeover, allowing any attacker to log in as any student once the password is known.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:prasklatechnology:placipy:1.0.0:*:*:*:*:*:*:*