Opinio
Objectplanet · 9 CVEs
The feature to import a survey is prone to stored Cross-Site Script attacks
Dec 2, 2025
Blind Server-Side Request Forgery (SSRF) in the survey-import feature of ObjectPlanet Opinio
Dec 2, 2025
The feature to manage resources is prone to Cross-Site Request Forgery attacks
Dec 2, 2025
Cryptographically weak PRNG in Opinio 7.22
Feb 1, 2024
ObjectPlanet Opinio before 7.14 allows Expression Language Injection via the admin/permissionList.do from parameter. Th…
Jul 31, 2021
ObjectPlanet Opinio before 7.15 allows XXE attacks via three steps: modify a .css file to have <!ENTITY content, create…
Jul 31, 2021
admin/file.do in ObjectPlanet Opinio before 7.15 allows Unrestricted File Upload of executable JSP files, resulting in…
Jul 31, 2021
ObjectPlanet Opinio before 7.14 allows reflected XSS via the survey/admin/surveyAdmin.do?action=viewSurveyAdmin query s…
Jul 30, 2021
In ObjectPlanet Opinio before 7.6.4, there is XSS.
Jul 3, 2017
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2025-13873 | The feature to import a survey is prone to stored Cross-Site Script attacks | MEDIUM | 0.20% | Dec 2, 2025 |
| CVE-2025-13872 | Blind Server-Side Request Forgery (SSRF) in the survey-import feature of ObjectPlanet Opinio | LOW | 0.31% | Dec 2, 2025 |
| CVE-2025-13871 | The feature to manage resources is prone to Cross-Site Request Forgery attacks | LOW | 0.18% | Dec 2, 2025 |
| CVE-2023-4472 | Cryptographically weak PRNG in Opinio 7.22 | CRITICAL | 0.74% | Feb 1, 2024 |
| CVE-2020-26565 | ObjectPlanet Opinio before 7.14 allows Expression Language Injection via the admin/permissionList.do from parameter. This can be used to retrieve possibly sens… | HIGH | 1.72% | Jul 31, 2021 |
| CVE-2020-26564 | ObjectPlanet Opinio before 7.15 allows XXE attacks via three steps: modify a .css file to have <!ENTITY content, create a .xml file for a generic survey templa… | MEDIUM | 1.12% | Jul 31, 2021 |
| CVE-2020-26806 | admin/file.do in ObjectPlanet Opinio before 7.15 allows Unrestricted File Upload of executable JSP files, resulting in remote code execution, because filePath… | HIGH | 5.97% | Jul 31, 2021 |
| CVE-2020-26563 | ObjectPlanet Opinio before 7.14 allows reflected XSS via the survey/admin/surveyAdmin.do?action=viewSurveyAdmin query string. (There is also stored XSS if inpu… | MEDIUM | 0.98% | Jul 30, 2021 |
| CVE-2017-10798 | In ObjectPlanet Opinio before 7.6.4, there is XSS. | MEDIUM | 0.64% | Jul 3, 2017 |
Showing 1 to 9 of 9 CVEs