CVE-2026-47325
Description
ProjectsAndPrograms school-management-system uses predictable credentials by generating student's and teacher's passwords solely from the user’s date of birth (e.g., 12072000 for 12 July 2000). The application does not require or prompt users to change the password upon first login. This behavior allows attackers to easily guess or derive valid credentials, leading to unauthorized account access. The maintainers were notified early about this vulnerability but did not provide details regarding affected versions. The version corresponding to commit 6b6fae5 was tested and confirmed vulnerable; other versions were not tested and may also be affected.
Is your site exposed to CVE-2026-47325?
Run a free security scan — no signup, results in seconds.
EPSS — Exploit Prediction
EPSS estimates the probability that this vulnerability will be exploited in the wild within the next 30 days. A higher score means more likely to be exploited.
Weakness Type (CWE)
References
Frequently Asked Questions
What is CVE-2026-47325? +
How do I check if I'm vulnerable to CVE-2026-47325? +
Related Vulnerabilities
Longse model LBH30FE200W cameras, as well as products based on this device, make use of telnet passwords which follow a …
In Slican telephone exchanges secure key is generated in a predictable manner using properties of the telephone exchange which can …
Weak credentials in the CashDro 3 web administration panel, version 24.01.00.26, where the platform allows the use of numeric PINs …
Tokens in CTFd used for account activation and password resetting can be used interchangeably for these operations. When used, they …
Under certain circumstances the Software House C●CURE 9000 installer will utilize weak credentials.
Dlink DWR-X1820 router uses weak default password generated from its IMEI number and does not require users to change it. …