Vulnerability index

Browse CVEs

9 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Opinio MEDIUM 5.4
CVE-2025-13873

Stored Cross-Site Scripting (XSS) in the survey-import feature of ObjectPlanet Opinio 7.26 rev12562 on web application allows an attacker to inject a…

Mitigation only
Fix from $1,600 2025-12-02
Opinio CRITICAL 9.1
CVE-2025-13872

Blind Server-Side Request Forgery (SSRF) in the survey-import feature of ObjectPlanet Opinio 7.26 rev12562 on Web-based platforms allows an atta…

Mitigation only
Fix from $2,300 2025-12-02
Opinio HIGH 8.8
CVE-2025-13871

Cross-Site Request Forgery (CSRF) in the resource-management feature of ObjectPlanet Opinio 7.26 rev12562 allows to upload files on behalf of th…

Mitigation only
Fix from $1,950 2025-12-02
Opinio CRITICAL 9.8
CVE-2023-4472

Objectplanet Opinio version 7.22 and prior uses a cryptographically weak pseudo-random number generator (PRNG) coupled to a predictable seed, which c…

Fix: 7.23+
Fix from $2,300 2024-02-01
Opinio HIGH 8.8
CVE-2020-26806EPSS 6%

admin/file.do in ObjectPlanet Opinio before 7.15 allows Unrestricted File Upload of executable JSP files, resulting in remote code execution, because…

Fix: 7.15+
Fix from $1,950 2021-07-31
Opinio HIGH 7.5
CVE-2020-26565

ObjectPlanet Opinio before 7.14 allows Expression Language Injection via the admin/permissionList.do from parameter. This can be used to retrieve pos…

Fix: 7.14+
Fix from $1,950 2021-07-31
Opinio MEDIUM 6.5
CVE-2020-26564

ObjectPlanet Opinio before 7.15 allows XXE attacks via three steps: modify a .css file to have <!ENTITY content, create a .xml file for a generic sur…

Fix: 7.15+
Fix from $1,600 2021-07-31
Opinio MEDIUM 6.1
CVE-2020-26563

ObjectPlanet Opinio before 7.14 allows reflected XSS via the survey/admin/surveyAdmin.do?action=viewSurveyAdmin query string. (There is also stored X…

Fix: 7.13+
Fix from $1,600 2021-07-30
Opinio MEDIUM 6.1
CVE-2017-10798

In ObjectPlanet Opinio before 7.6.4, there is XSS.

Fix: after 7.6.3
Fix from $1,600 2017-07-03