CVE-2025-13872: Objectplanet Opinio
Critical severity, CVSS 9.1. EPSS: 0.3% chance of exploitation in the next 30 days.
Blind Server-Side Request Forgery (SSRF) in the survey-import feature of ObjectPlanet Opinio 7.26 rev12562 on Web-based platforms allows an attacker to force the server to perform HTTP GET requests via crafted import requests to an arbitrary destination.
Affected products
- Objectplanet Opinio: version 7.26 only
Published 2025-12-02. Last modified 2026-09-26.