Skip to main content

Vendor/product archive

combodo / itop CVEs

Beta · best-effort

81 CVEs tagged to combodo / itop4 Critical, 39 High, 37 Medium, 1 Low, 0 Unrated.

CVE-2025-64167

Published Nov 10, 2025

Combodo iTop is a web based IT service management tool. Versions prior to 2.7.13 and 3.2.2 are vulnerable to a cross-site scripting attack (leading to JS execution) when editing t…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-49145

Published Nov 10, 2025

Combodo iTop is a web based IT service management tool. In versions prior to 2.7.13 and 3.2.2, a user that has enough rights to create webhooks (mostly administrators) can drop th…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-48878

Published Nov 10, 2025

Combodo iTop is a web based IT service management tool. In versions on the 3.x branch prior to 3.2.2, an insecure direct object reference allows a user (e.g. with Service desk age…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-48065

Published Nov 10, 2025

Combodo iTop is a web based IT service management tool. Versions prior to 2.7.13 and 3.2.2 are vulnerable to cross-site scripting when a field with an error contains malicious con…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-48055

Published Nov 10, 2025

Combodo iTop is a web based IT service management tool. In versions prior to 3.2.2, when displaying content in a browse brick in the user portal, a cross-site scripting attack can…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-47932

Published Nov 10, 2025

Combodo iTop is a web based IT service management tool. Versions prior to 2.7.13 and 3.2.2 are vulnerable to cross-site scripting when a dashboard is rendered via an AJAX call. V…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-47773

Published Nov 10, 2025

Combodo iTop is a web based IT service management tool. Versions prior to 2.7.13 and 3.2.2 are vulnerable to cross-site scripting when a dashboard is edited via an AJAX call. Vers…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-47286

Published Nov 10, 2025

Combodo iTop is a web based IT service management tool. In versions prior to 2.7.13 and 3.2.2, an administrator can, by editing the configuration of the iTop instance, execute cod…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2025-24969

Published May 14, 2025

iTop is an web based IT Service Management tool. Prior to version 3.2.1, a portal user can see any other contacts picture by changing the picture ID in the URL. Version 3.2.1 cont…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-24785

Published May 14, 2025

iTop is an web based IT Service Management tool. In version 3.2.0, an attacker may send a URL to the server to trigger a PHP error. The next user trying to load this dashboard wou…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-24026

Published May 14, 2025

iTop is an web based IT Service Management tool. Versions prior to 3.2.1 are vulnerable to regular expression denial of service (ReDoS) that may, under some circumstances, affect…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-24022

Published May 14, 2025

iTop is an web based IT Service Management tool. Prior to versions 2.7.12, 3.1.3, and 3.2.1, server code execution is possible through the frontend of iTop's portal. This is fixed…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-24021

Published May 14, 2025

iTop is an web based IT Service Management tool. Prior to versions 2.7.12, 3.1.3, and 3.2.1, anyone with an account having portal access can set value to object fields when they'r…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-56157

Published May 14, 2025

iTop is an web based IT Service Management tool. Prior to versions 3.1.3 and 3.2.1, by filling malicious code in a CSV content, a cross-site scripting attack can be performed when…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-52601

Published May 14, 2025

iTop is an web based IT Service Management tool. Prior to versions 2.7.12, 3.1.3, and 3.2.1, anyone with an account having portal access can have read access to objects they're no…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-27139

Published Feb 25, 2025

Combodo iTop is a web based IT service management tool. Versions prior to 2.7.12, 3.1.2, and 3.2.0 are vulnerable to cross-site scripting when the preferences page is opened. Vers…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-54139

Published Dec 13, 2024

Combodo iTop is an open source and web-based IT service management platform. Prior to versions 2.7.11, 3.1.2, and 3.2.0., iTop has a cross-site scripting vulnerability that can le…

CVSS 7.9 · High
Vendor/product tagsBeta · best-effort

CVE-2024-52002

Published Nov 8, 2024

Combodo iTop is a simple, web based IT Service Management tool. Several url endpoints are subject to a Cross-Site Request Forgery (CSRF) vulnerability. Please refer to the linked…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-52001

Published Nov 8, 2024

Combodo iTop is a simple, web based IT Service Management tool. In affected versions portal users are able to access forbidden services information. This issue has been addressed…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-52000

Published Nov 8, 2024

Combodo iTop is a simple, web based IT Service Management tool. Affected versions are subject to a reflected Cross-site Scripting (XSS) exploit by way of editing a request's paylo…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-51995

Published Nov 7, 2024

Combodo iTop is a web based IT Service Management tool. An attacker can request any `route` we want as long as we specify an `operation` that is allowed. This issue has been addre…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-51994

Published Nov 7, 2024

Combodo iTop is a web based IT Service Management tool. In affected versions uploading a text file containing some java script in the portal will trigger an Cross-site Scripting (…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-51993

Published Nov 7, 2024

Combodo iTop is a web based IT Service Management tool. An attacker accessing a backup file or the database can read some passwords for misconfigured Users. This issue has been ad…

CVSS 3.4 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-51740

Published Nov 5, 2024

Combodo iTop is a simple, web based IT Service Management tool. This vulnerability can be used to create HTTP requests on behalf of the server, from a low privileged user. The use…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-51739

Published Nov 5, 2024

Combodo iTop is a simple, web based IT Service Management tool. Unauthenticated user can perform users enumeration, which can make it easier to bruteforce a valid account. As a fi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 81 CVEsPage 1 of 4