objectplanet CVE Vulnerabilities & Metrics

Focus on objectplanet vulnerabilities and metrics.

Last updated: 16 Jan 2026, 23:25 UTC

About objectplanet Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with objectplanet. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total objectplanet CVEs: 9
Earliest CVE date: 03 Jul 2017, 03:29 UTC
Latest CVE date: 02 Dec 2025, 10:16 UTC

Latest CVE reference: CVE-2025-13873

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 3

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): -100.0%
Year Variation (Calendar): 200.0%

Month Growth Rate (30-day Rolling): -100.0%
Year Growth Rate (365-day Rolling): 200.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical objectplanet CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 2.68

Max CVSS: 6.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 4
4.0-6.9 5
7.0-8.9 0
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS objectplanet CVEs

These are the five CVEs with the highest CVSS scores for objectplanet, sorted by severity first and recency.

All CVEs for objectplanet

CVE-2025-13873 objectplanet vulnerability CVSS: 0 02 Dec 2025, 10:16 UTC

Stored Cross-Site Scripting (XSS) in the survey-import feature of ObjectPlanet Opinio 7.26 rev12562 on web application allows an attacker to inject arbitrary JavaScript code, which executes in the browsing context of any visitor accessing the compromised survey.

CVE-2025-13872 objectplanet vulnerability CVSS: 0 02 Dec 2025, 10:16 UTC

Blind Server-Side Request Forgery (SSRF) in the survey-import feature of ObjectPlanet Opinio 7.26 rev12562 on Web-based platforms allows an attacker to force the server to perform HTTP GET requests via crafted import requests to an arbitrary destination.

CVE-2025-13871 objectplanet vulnerability CVSS: 0 02 Dec 2025, 10:16 UTC

Cross-Site Request Forgery (CSRF) in the resource-management feature of ObjectPlanet Opinio 7.26 rev12562 allows to upload files on behalf of the connected users and then access such files without authentication.

CVE-2023-4472 objectplanet vulnerability CVSS: 0 01 Feb 2024, 22:15 UTC

Objectplanet Opinio version 7.22 and prior uses a cryptographically weak pseudo-random number generator (PRNG) coupled to a predictable seed, which could lead to an unauthenticated account takeover of any user on the application.

CVE-2020-26806 objectplanet vulnerability CVSS: 6.5 31 Jul 2021, 17:15 UTC

admin/file.do in ObjectPlanet Opinio before 7.15 allows Unrestricted File Upload of executable JSP files, resulting in remote code execution, because filePath can have directory traversal and fileContent can be valid JSP code.

CVE-2020-26565 objectplanet vulnerability CVSS: 5.0 31 Jul 2021, 17:15 UTC

ObjectPlanet Opinio before 7.14 allows Expression Language Injection via the admin/permissionList.do from parameter. This can be used to retrieve possibly sensitive serverInfo data.

CVE-2020-26564 objectplanet vulnerability CVSS: 4.0 31 Jul 2021, 17:15 UTC

ObjectPlanet Opinio before 7.15 allows XXE attacks via three steps: modify a .css file to have <!ENTITY content, create a .xml file for a generic survey template (containing a link to this .css file), and import this .xml file at the survey/admin/folderSurvey.do?action=viewImportSurvey['importFile'] URI. The XXE can then be triggered at a admin/preview.do?action=previewSurvey&surveyId= URI.

CVE-2020-26563 objectplanet vulnerability CVSS: 4.3 30 Jul 2021, 15:15 UTC

ObjectPlanet Opinio before 7.14 allows reflected XSS via the survey/admin/surveyAdmin.do?action=viewSurveyAdmin query string. (There is also stored XSS if input to survey/admin/*.do is accepted from untrusted users.)

CVE-2017-10798 objectplanet vulnerability CVSS: 4.3 03 Jul 2017, 03:29 UTC

In ObjectPlanet Opinio before 7.6.4, there is XSS.