prasklatechnology records
10 published records for vendor prasklatechnology.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-862 Missing Authorization3
- CWE-863 Incorrect Authorization2
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-259 Use of Hard-coded Password1
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')1
- CWE-532 Insertion of Sensitive Information into Log File1
The weakness classes this vendor ships most often: where to look.
CWEAll records
10 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
37Monitor | CVE-2026-25814No exploit | NoSQL Injection Risk via Unsanitized Query Parametersprasklatechnology · placipy · CWE-74 | Critical9.3 | — | 0.6% | Feb 9, 2026 |
37Monitor | CVE-2026-25753No exploit | PlaciPy has a Hard-Coded Default Password for All Student Accounts (Account Takeover)prasklatechnology · placipy · CWE-259 | Critical9.3 | — | 0.5% | Feb 6, 2026 |
37Monitor | CVE-2026-25875No exploit | PlaciPy Admin Privilege Escalation via Trusted JWT Claimsprasklatechnology · placipy · CWE-863 | Critical9.3 | — | 0.5% | Feb 9, 2026 |
37Monitor | CVE-2026-25812No exploit | PlaciPy is Missing CSRF Protection on State-Changing Endpointsprasklatechnology · placipy · CWE-352 | Critical9.3 | — | 0.2% | Feb 9, 2026 |
34Monitor | CVE-2026-25813No exploit | PlaciPy Exposes Sensitive Data via Application Logsprasklatechnology · placipy · CWE-532 | High8.7 | — | 0.4% | Feb 9, 2026 |
21Monitor | CVE-2026-25809No exploit | PlaciPy Code Execution Allowed Without Assessment Active State Validationprasklatechnology · placipy · CWE-285 | Medium5.3 | — | 0.6% | Feb 9, 2026 |
21Monitor | CVE-2026-25810No exploit | PlaciPy is Missing Object-Level Authorization in student.submission.routes.tsprasklatechnology · placipy · CWE-862 | Medium5.3 | — | 0.5% | Feb 9, 2026 |
21Monitor | CVE-2026-25876No exploit | PlaciPy is Missing Authorization on Assessment Results Endpointprasklatechnology · placipy · CWE-862 | Medium5.3 | — | 0.5% | Feb 9, 2026 |
21Monitor | CVE-2026-25806No exploit | PlaciPy has Missing Authorization Checks on Student Management Endpoints (IDOR)prasklatechnology · placipy · CWE-862 | Medium5.3 | — | 0.4% | Feb 9, 2026 |
21Monitor | CVE-2026-25811No exploit | PlaciPy Email Domain Trust Enables Cross-Tenant Data Access (Multi-Tenant Isolation Failure)prasklatechnology · placipy · CWE-863 | Medium5.3 | — | 0.4% | Feb 9, 2026 |
- CVE-2026-2581437Monitor
NoSQL Injection Risk via Unsanitized Query Parameters
CriticalCVSS 9.3No exploitEPSS 1%prasklatechnology · placipyFeb 9, 2026
- CVE-2026-2575337Monitor
PlaciPy has a Hard-Coded Default Password for All Student Accounts (Account Takeover)
CriticalCVSS 9.3No exploitEPSS 1%prasklatechnology · placipyFeb 6, 2026
- CVE-2026-2587537Monitor
PlaciPy Admin Privilege Escalation via Trusted JWT Claims
CriticalCVSS 9.3No exploitEPSS 1%prasklatechnology · placipyFeb 9, 2026
- CVE-2026-2581237Monitor
PlaciPy is Missing CSRF Protection on State-Changing Endpoints
CriticalCVSS 9.3No exploitEPSS 0%prasklatechnology · placipyFeb 9, 2026
- CVE-2026-2581334Monitor
PlaciPy Exposes Sensitive Data via Application Logs
HighCVSS 8.7No exploitEPSS 0%prasklatechnology · placipyFeb 9, 2026
- CVE-2026-2580921Monitor
PlaciPy Code Execution Allowed Without Assessment Active State Validation
MediumCVSS 5.3No exploitEPSS 1%prasklatechnology · placipyFeb 9, 2026
- CVE-2026-2581021Monitor
PlaciPy is Missing Object-Level Authorization in student.submission.routes.ts
MediumCVSS 5.3No exploitEPSS 0%prasklatechnology · placipyFeb 9, 2026
- CVE-2026-2587621Monitor
PlaciPy is Missing Authorization on Assessment Results Endpoint
MediumCVSS 5.3No exploitEPSS 0%prasklatechnology · placipyFeb 9, 2026
- CVE-2026-2580621Monitor
PlaciPy has Missing Authorization Checks on Student Management Endpoints (IDOR)
MediumCVSS 5.3No exploitEPSS 0%prasklatechnology · placipyFeb 9, 2026
- CVE-2026-2581121Monitor
PlaciPy Email Domain Trust Enables Cross-Tenant Data Access (Multi-Tenant Isolation Failure)
MediumCVSS 5.3No exploitEPSS 0%prasklatechnology · placipyFeb 9, 2026