---
id: CVE-2025-13873
title: "Stored Cross-Site Scripting (XSS) in the survey-import feature of ObjectPlanet\_Opinio\_7.26 rev12562 on web application allows an attacker to inject arbitrary JavaScript code, which executes in the browsing context of any visitor accessin…"
summary: "Stored Cross-Site Scripting (XSS) in the survey-import feature of ObjectPlanet\_Opinio\_7.26 rev12562 on web application allows an attacker to inject arbitrary JavaScript code, which executes in the browsing context of any visitor accessin…"
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: objectplanet
product: opinio
affected:
  - opinio = 7.26
published: '2025-12-02'
updated: '2026-09-03'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-13873'
references:
  - url: 'https://www.objectplanet.com/opinio/changelog.html'
    label: 64c5ae8f-7972-4697-86a0-7ada793ac795
tags:
  - nvd
epss: 0.002
epssPercentile: 0.08766
ingestedAt: '2026-09-03T03:55:23.905Z'
---

## Overview

Stored Cross-Site Scripting (XSS) in the survey-import feature of ObjectPlanet Opinio 7.26 rev12562 on web application allows an attacker to inject arbitrary JavaScript code, which executes in the browsing context of any visitor accessing the compromised survey.

## Affected

- `opinio = 7.26`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
