Objectplanet develops a narrow product line centered on its Opinio survey and feedback platform, which sits in a niche but security-sensitive role within organizations' web infrastructure. Vulnerabilities affecting this vendor skew toward serious outcomes and recur through web-application weakness classes including cross-site scripting, CSRF, path traversal, expression language injection, and improper XML entity handling—patterns characteristic of Java-based web applications that process and render user input. Defenders should treat updates to this platform as a patching priority given its typical deployment in customer-facing contexts; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Objectplanet over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-13872CRITICAL Blind Server-Side Request Forgery (SSRF) in the survey-import feature of
ObjectPlanet Opinio 7.26 rev12562 on
Web-based platforms allows an attacker to force the server to per | Dec 2, 2025 | 9.1 | 32 | NO | NO |
CVE-2023-4472CRITICAL Objectplanet Opinio version 7.22 and prior uses a cryptographically weak pseudo-random number generator (PRNG) coupled to a predictable seed, which could lead to an unauthenticated | Feb 1, 2024 | 9.8 | 29 | NO | NO |
CVE-2020-26806HIGH admin/file.do in ObjectPlanet Opinio before 7.15 allows Unrestricted File Upload of executable JSP files, resulting in remote code execution, because filePath can have directory tr | Jul 31, 2021 | 8.8 | 28 | NO | NO |
CVE-2025-13871HIGH Cross-Site Request Forgery (CSRF) in the resource-management feature of
ObjectPlanet Opinio 7.26 rev12562
allows to upload
files on behalf of the connected users and then acce | Dec 2, 2025 | 8.8 | 27 | NO | NO |
CVE-2020-26565HIGH ObjectPlanet Opinio before 7.14 allows Expression Language Injection via the admin/permissionList.do from parameter. This can be used to retrieve possibly sensitive serverInfo data | Jul 31, 2021 | 7.5 | 25 | NO | NO |
CVE-2017-10798MEDIUM In ObjectPlanet Opinio before 7.6.4, there is XSS. | Jul 3, 2017 | 6.1 | 22 | NO | NO |
CVE-2020-26564MEDIUM ObjectPlanet Opinio before 7.15 allows XXE attacks via three steps: modify a .css file to have <!ENTITY content, create a .xml file for a generic survey template (containing a link | Jul 31, 2021 | 6.5 | 21 | NO | NO |
CVE-2020-26563MEDIUM ObjectPlanet Opinio before 7.14 allows reflected XSS via the survey/admin/surveyAdmin.do?action=viewSurveyAdmin query string. (There is also stored XSS if input to survey/admin/*.d | Jul 30, 2021 | 6.1 | 21 | NO | NO |
CVE-2025-13873MEDIUM Stored Cross-Site Scripting (XSS) in the survey-import feature of ObjectPlanet Opinio 7.26 rev12562 on web application allows an attacker to inject arbitrary JavaScript code, which | Dec 2, 2025 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Objectplanet.
Media articles that mention a CVE ID that affects a product developed by Objectplanet — matched by CVE ID, not by vendor name.