CVE-2025-15578
critical · 9.8Maypole versions from 2.10 through 2.13 for Perl generates session ids insecurely. The session id is seeded with the system time (which is available from HTTP response headers), a call to the built-in rand() function, and the PID.
9.8
CVSS
0.3%
EPSS (exploit prob.)
22nd
EPSS percentile
2026-02-16
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-338
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| teejay | maypole | >= 2.10, <= 2.13 |
| teejay | maypole | 2.111 |
| teejay | maypole | 2.121 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2025-15578