← All CVEs

CVE-2025-15578

critical · 9.8

Maypole versions from 2.10 through 2.13 for Perl generates session ids insecurely. The session id is seeded with the system time (which is available from HTTP response headers), a call to the built-in rand() function, and the PID.

9.8
CVSS
0.3%
EPSS (exploit prob.)
22nd
EPSS percentile
2026-02-16
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-338

Affected products

VendorProductAffected versions
teejaymaypole>= 2.10, <= 2.13
teejaymaypole2.111
teejaymaypole2.121

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2025-15578