ObjectPlanet records
9 published records for vendor objectplanet.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-335 Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG)1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-917 Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')1
- CWE-918 Server-Side Request Forgery (SSRF)1
The weakness classes this vendor ships most often: where to look.
CWEAll records
9 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2023-4472No exploit | Cryptographically weak PRNG in Opinio 7.22objectplanet · opinio · CWE-335 | Critical9.8 | — | 0.7% | Feb 1, 2024 |
37Monitor | CVE-2020-26806No exploit | admin/file.do in ObjectPlanet Opinio before 7.15 allows Unrestricted File Upload of executable JSP files, resulting in remote code executionobjectplanet · opinio · CWE-22 | High8.8 | — | 6.0% | Jul 31, 2021 |
31Monitor | CVE-2020-26565No exploit | ObjectPlanet Opinio before 7.14 allows Expression Language Injection via the admin/permissionList.do from parameter.objectplanet · opinio · CWE-917 | High7.5 | — | 1.7% | Jul 31, 2021 |
26Monitor | CVE-2020-26564No exploit | ObjectPlanet Opinio before 7.15 allows XXE attacks via three steps: modify a .css file to have <!ENTITY content, create a .xml file for a geobjectplanet · opinio · CWE-611 | Medium6.5 | — | 1.1% | Jul 31, 2021 |
24Monitor | CVE-2020-26563No exploit | ObjectPlanet Opinio before 7.14 allows reflected XSS via the survey/admin/surveyAdmin.do?action=viewSurveyAdmin query string.objectplanet · opinio · CWE-79 | Medium6.1 | — | 1.0% | Jul 30, 2021 |
24Monitor | CVE-2017-10798No exploit | In ObjectPlanet Opinio before 7.6.4, there is XSS.objectplanet · opinio · CWE-79 | Medium6.1 | — | 0.6% | Jul 2, 2017 |
19Monitor | CVE-2025-13873No exploit | The feature to import a survey is prone to stored Cross-Site Script attacksobjectplanet · opinio · CWE-79 | Medium4.8 | — | 0.2% | Dec 2, 2025 |
9Monitor | CVE-2025-13871No exploit | The feature to manage resources is prone to Cross-Site Request Forgery attacksobjectplanet · opinio · CWE-352 | Low2.3 | — | 0.2% | Dec 2, 2025 |
8Monitor | CVE-2025-13872No exploit | Blind Server-Side Request Forgery (SSRF) in the survey-import feature of ObjectPlanet Opinioobjectplanet · opinio · CWE-918 | Low2.1 | — | 0.3% | Dec 2, 2025 |
- CVE-2023-447239Monitor
Cryptographically weak PRNG in Opinio 7.22
CriticalCVSS 9.8No exploitEPSS 1%objectplanet · opinioFeb 1, 2024
- CVE-2020-2680637Monitor
admin/file.do in ObjectPlanet Opinio before 7.15 allows Unrestricted File Upload of executable JSP files, resulting in remote code execution
HighCVSS 8.8No exploitEPSS 6%objectplanet · opinioJul 31, 2021
- CVE-2020-2656531Monitor
ObjectPlanet Opinio before 7.14 allows Expression Language Injection via the admin/permissionList.do from parameter.
HighCVSS 7.5No exploitEPSS 2%objectplanet · opinioJul 31, 2021
- CVE-2020-2656426Monitor
ObjectPlanet Opinio before 7.15 allows XXE attacks via three steps: modify a .css file to have <!ENTITY content, create a .xml file for a ge
MediumCVSS 6.5No exploitEPSS 1%objectplanet · opinioJul 31, 2021
- CVE-2020-2656324Monitor
ObjectPlanet Opinio before 7.14 allows reflected XSS via the survey/admin/surveyAdmin.do?action=viewSurveyAdmin query string.
MediumCVSS 6.1No exploitEPSS 1%objectplanet · opinioJul 30, 2021
- CVE-2017-1079824Monitor
In ObjectPlanet Opinio before 7.6.4, there is XSS.
MediumCVSS 6.1No exploitEPSS 1%objectplanet · opinioJul 2, 2017
- CVE-2025-1387319Monitor
The feature to import a survey is prone to stored Cross-Site Script attacks
MediumCVSS 4.8No exploitEPSS 0%objectplanet · opinioDec 2, 2025
- CVE-2025-138719Monitor
The feature to manage resources is prone to Cross-Site Request Forgery attacks
LowCVSS 2.3No exploitEPSS 0%objectplanet · opinioDec 2, 2025
- CVE-2025-138728Monitor
Blind Server-Side Request Forgery (SSRF) in the survey-import feature of ObjectPlanet Opinio
LowCVSS 2.1No exploitEPSS 0%objectplanet · opinioDec 2, 2025