Threats Tagged 'cve-2026-25812'
View all threats tagged with 'cve-2026-25812'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-25812'
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2026-25812 is a critical Cross-Site Request Forgery (CSRF) vulnerability affecting version 1.0.0 of Praskla-Technology's placement management system, PlaciPy. The application allows credentialed CORS requests but lacks any CSRF protection, enabling attackers to perform unauthorized actions on behalf of authenticated users without their consent. The vulnerability has a CVSS 4.0 score of 9.3, indicating high impact and ease of exploitation without requiring authentication or user interaction. This flaw could lead to unauthorized data manipulation or disruption of placement management processes in educational institutions. European organizations using PlaciPy are at risk, especially those in countries with significant educational technology adoption. Mitigation requires implementing anti-CSRF tokens, restricting CORS policies, and updating to patched versions once available. Join the discussion | CVE Database V5 | 02/09/2026, 21:03:36 UTC Added: 02/09/2026, 21:31:17 UTC |
Showing 1 to 1 of 1 result