VYPR
Unrated severityNVD Advisory· Published Feb 6, 2026· Updated Feb 9, 2026

PlaciPy has a Hard-Coded Default Password for All Student Accounts (Account Takeover)

CVE-2026-25753

Description

PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the application uses a hard-coded, static default password for all newly created student accounts. This results in mass account takeover, allowing any attacker to log in as any student once the password is known.

Affected products

2
  • PlaciPy/PlaciPyllm-fuzzy
    Range: = 1.0.0
  • Praskla-Technology/assessment-placipyv5
    Range: <= 1.0.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.