Critical severity9.8NVD Advisory· Published Feb 6, 2026· Updated Jun 17, 2026
CVE-2026-25753
CVE-2026-25753
Description
PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the application uses a hard-coded, static default password for all newly created student accounts. This results in mass account takeover, allowing any attacker to log in as any student once the password is known.
Affected products
3- cpe:2.3:a:prasklatechnology:placipy:1.0.0:*:*:*:*:*:*:*
- Range: <1.0.0
- Praskla-Technology/assessment-placipyv5Range: <= 1.0.0
Patches
Vulnerability mechanics
References
1- github.com/Praskla-Technology/assessment-placipy/security/advisories/GHSA-6537-cf56-j9w2nvdMitigationVendor Advisory
News mentions
0No linked articles in our index yet.