Placipy
Vendor:
First CVE: Feb 6, 2026 · Active for under a year
10
Total CVEs
More Total CVEs than 89% of tracked products
10.0
Avg CVEs / Year
Higher CVE frequency than 96% of tracked products
8.9
Avg CVSS
Higher Avg CVSS than 83% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Placipy over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 6, 2026
5 months ago
Most Recent CVE
Feb 9, 2026
168 days ago
CVE Severity & Scoring
Placipy10 CVEs
10%
20%
70%
All CVEs352,785 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network10 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None9 (90.0%)
Unknown0 (0.0%)
Required1 (10.0%)
Privileges Required
Low1 (10.0%)
High0 (0.0%)
None9 (90.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-25753CRITICAL PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the application uses a hard-coded, static default password for all newly created s | Feb 6, 2026 | 9.8 | 31 | NO | NO |
CVE-2026-25875CRITICAL PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, The admin authorization middleware trusts client-controlled JWT claims (role and s | Feb 9, 2026 | 9.8 | 30 | NO | NO |
CVE-2026-25814CRITICAL PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, User-controlled query parameters are passed directly into DynamoDB query/filter co | Feb 9, 2026 | 9.8 | 30 | NO | NO |
CVE-2026-25809CRITICAL PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the code evaluation endpoint does not validate the assessment lifecycle state befo | Feb 9, 2026 | 9.8 | 29 | NO | NO |
CVE-2026-25811CRITICAL PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the application derives the tenant identifier directly from the email domain provi | Feb 9, 2026 | 9.1 | 28 | NO | NO |
CVE-2026-25876CRITICAL PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the backend/src/routes/results.routes.ts verify authentication but fails to enforc | Feb 9, 2026 | 9.1 | 27 | NO | NO |
CVE-2026-25810CRITICAL PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the backend/src/routes/student.submission.routes.ts verify authentication but fail | Feb 9, 2026 | 9.1 | 27 | NO | NO |
CVE-2026-25812HIGH PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the application enables credentialed CORS requests but does not implement any CSRF | Feb 9, 2026 | 8.8 | 26 | NO | NO |
CVE-2026-25813HIGH PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, The application logs highly sensitive data directly to console output without mask | Feb 9, 2026 | 7.5 | 24 | NO | NO |
CVE-2026-25806MEDIUM PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the GET /api/students/:email
PUT /api/students/:email/status, and DELETE /api/stud | Feb 9, 2026 | 6.5 | 22 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (10 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (10 CVEs).
Media Mentions
Signals from CVEs in this product scope (10 CVEs).
Top CNAs Publishing CVEs For Placipy
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.0.0 | 10 | 8.9 | 0.3% | 0 | 0 |