Prasklatechnology's vulnerability profile centers on Placipy, a narrowly scoped product that punches above its typical representation in the vulnerability landscape. The vendor's disclosures skew strongly toward critical-severity outcomes and cluster around authorization and access-control weaknesses—missing authorization, incorrect authorization, improper authorization, and CSRF flaws—alongside injection-class issues in output handling that are characteristic of web-facing or API-driven applications. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Prasklatechnology over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-25753CRITICAL PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the application uses a hard-coded, static default password for all newly created s | Feb 6, 2026 | 9.8 | 31 | NO | NO |
CVE-2026-25875CRITICAL PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, The admin authorization middleware trusts client-controlled JWT claims (role and s | Feb 9, 2026 | 9.8 | 30 | NO | NO |
CVE-2026-25814CRITICAL PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, User-controlled query parameters are passed directly into DynamoDB query/filter co | Feb 9, 2026 | 9.8 | 30 | NO | NO |
CVE-2026-25809CRITICAL PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the code evaluation endpoint does not validate the assessment lifecycle state befo | Feb 9, 2026 | 9.8 | 29 | NO | NO |
CVE-2026-25811CRITICAL PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the application derives the tenant identifier directly from the email domain provi | Feb 9, 2026 | 9.1 | 28 | NO | NO |
CVE-2026-25876CRITICAL PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the backend/src/routes/results.routes.ts verify authentication but fails to enforc | Feb 9, 2026 | 9.1 | 27 | NO | NO |
CVE-2026-25810CRITICAL PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the backend/src/routes/student.submission.routes.ts verify authentication but fail | Feb 9, 2026 | 9.1 | 27 | NO | NO |
CVE-2026-25812HIGH PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the application enables credentialed CORS requests but does not implement any CSRF | Feb 9, 2026 | 8.8 | 26 | NO | NO |
CVE-2026-25813HIGH PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, The application logs highly sensitive data directly to console output without mask | Feb 9, 2026 | 7.5 | 24 | NO | NO |
CVE-2026-25806MEDIUM PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the GET /api/students/:email
PUT /api/students/:email/status, and DELETE /api/stud | Feb 9, 2026 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Prasklatechnology.
Media articles that mention a CVE ID that affects a product developed by Prasklatechnology — matched by CVE ID, not by vendor name.