Critical severity9.8NVD Advisory· Published Feb 9, 2026· Updated Jun 17, 2026
CVE-2026-25809
CVE-2026-25809
Description
PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the code evaluation endpoint does not validate the assessment lifecycle state before allowing execution. There is no check to ensure that the assessment has started, is not expired, or the submission window is currently open.
Affected products
3- cpe:2.3:a:prasklatechnology:placipy:1.0.0:*:*:*:*:*:*:*
- Range: <1.0.0
- Praskla-Technology/assessment-placipyv5Range: = 1.0.0
Patches
Vulnerability mechanics
References
1- github.com/Praskla-Technology/assessment-placipy/security/advisories/GHSA-cc32-rp29-w9x7nvdMitigationVendor Advisory
News mentions
0No linked articles in our index yet.