Objectplanet
Objectplanet Opinio: vulnerabilidades y CVE
Objectplanet Opinio tiene 9 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE9
Últimos 12 meses3
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-13873 | Media (4.8) | 0.20% | — | 2 dic 2025 | Stored Cross-Site Scripting (XSS) in the survey-import feature of ObjectPlanet Opinio 7.26 rev12562 on web application allows an attacker to inject arbitrary JavaScript code, which executes in the browsing context of… |
| CVE-2025-13872 | Baja (2.1) | 0.31% | — | 2 dic 2025 | Blind Server-Side Request Forgery (SSRF) in the survey-import feature of ObjectPlanet Opinio 7.26 rev12562 on Web-based platforms allows an attacker to force the server to perform HTTP GET requests via crafted import… |
| CVE-2025-13871 | Baja (2.3) | 0.18% | — | 2 dic 2025 | Cross-Site Request Forgery (CSRF) in the resource-management feature of ObjectPlanet Opinio 7.26 rev12562 allows to upload files on behalf of the connected users and then access such files without authentication. |
| CVE-2023-4472 | Crítica (9.8) | 0.74% | — | 1 feb 2024 | Objectplanet Opinio version 7.22 and prior uses a cryptographically weak pseudo-random number generator (PRNG) coupled to a predictable seed, which could lead to an unauthenticated account takeover of any user on the… |
| CVE-2020-26806 | Alta (8.8) | 6.0% | — | 31 jul 2021 | admin/file.do in ObjectPlanet Opinio before 7.15 allows Unrestricted File Upload of executable JSP files, resulting in remote code execution, because filePath can have directory traversal and fileContent can be valid… |
| CVE-2020-26565 | Alta (7.5) | 1.7% | — | 31 jul 2021 | ObjectPlanet Opinio before 7.14 allows Expression Language Injection via the admin/permissionList.do from parameter. This can be used to retrieve possibly sensitive serverInfo data. |
| CVE-2020-26564 | Media (6.5) | 1.1% | — | 31 jul 2021 | ObjectPlanet Opinio before 7.15 allows XXE attacks via three steps: modify a .css file to have <!ENTITY content, create a .xml file for a generic survey template (containing a link to this .css file), and import this… |
| CVE-2020-26563 | Media (6.1) | 0.98% | — | 30 jul 2021 | ObjectPlanet Opinio before 7.14 allows reflected XSS via the survey/admin/surveyAdmin.do?action=viewSurveyAdmin query string. (There is also stored XSS if input to survey/admin/*.do is accepted from untrusted users.) |
| CVE-2017-10798 | Media (6.1) | 0.64% | — | 3 jul 2017 | In ObjectPlanet Opinio before 7.6.4, there is XSS. |