VYPR

Itop

by Combodo

Source repositories

CVEs (102)

  • CVE-2026-33240HigAug 21, 2026
    risk 0.50cvss 8.8epss 0.00

    Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there was a Reflected Cross-Site Scripting (XSS) vulnerability in the foreign key search criteria API. This issue has been fixed in version 3.2.3.

  • CVE-2026-31936HigAug 21, 2026
    risk 0.50cvss 8.8epss 0.00

    Combodo iTop is a web based IT service management tool. Prior to 3.2.3, users can access to unauthorized object information through the search operation. This issue has been fixed in version 3.2.3.

  • CVE-2021-32775HigJul 21, 2021
    risk 0.50cvss 7.7epss 0.01

    Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.4, a non admin user can get access to many class/field values through GroupBy Dashlet error message. This issue is fixed in versions 2.7.4 and 3.0.0.

  • CVE-2026-34741HigAug 21, 2026
    risk 0.49cvss 8.6epss 0.00

    Combodo iTop is a web based IT service management tool. Prior to 3.2.3, authentication bypass allows unauthenticated remote attackers to execute arbitrary PHP files from the env-production directory on a new iTop instance in the production environment. This issue has been fixed…

  • CVE-2024-51739HigNov 5, 2024
    risk 0.49cvss 7.5epss 0.01

    Combodo iTop is a simple, web based IT Service Management tool. Unauthenticated user can perform users enumeration, which can make it easier to bruteforce a valid account. As a fix the sentence displayed after resetting password no longer shows if the user exists or not. This…

  • CVE-2020-12780HigAug 10, 2020
    risk 0.49cvss 7.5epss 0.01

    A security misconfiguration exists in Combodo iTop, which can expose sensitive information.

  • CVE-2020-12777HigAug 10, 2020
    risk 0.49cvss 7.5epss 0.01

    A function in Combodo iTop contains a vulnerability of Broken Access Control, which allows unauthorized attacker to inject command and disclose system information.

  • CVE-2019-13967HigFeb 14, 2020
    risk 0.49cvss 7.5epss 0.01

    iTop 2.2.0 through 2.6.0 allows remote attackers to cause a denial of service (application outage) via many requests to launch a compile operation. The requests use the pages/exec.php?exec_env=production&exec_module=itop-hub-connector&exec_page=ajax.php&operation=compile URI.…

  • CVE-2020-12778HigAug 10, 2020
    risk 0.48cvss 7.4epss 0.01

    Combodo iTop does not validate inputted parameters, attackers can inject malicious commands and launch XSS attack.

  • CVE-2025-47286HigNov 10, 2025
    risk 0.47cvss 7.2epss 0.00

    Combodo iTop is a web based IT service management tool. In versions prior to 2.7.13 and 3.2.2, an administrator can, by editing the configuration of the iTop instance, execute code on the server. Versions 2.7.13 and 3.2.2 escape and check the config parameter before executing a…

  • CVE-2018-10642HigMay 2, 2018
    risk 0.47cvss 7.2epss 0.06

    Command injection vulnerability in Combodo iTop 2.4.1 allows remote authenticated administrators to execute arbitrary commands by changing the platform configuration, because web/env-production/itop-config/config.php contains a function called TestConfig() that calls the…

  • CVE-2025-64167HigNov 10, 2025
    risk 0.46cvss 7.1epss 0.00

    Combodo iTop is a web based IT service management tool. Versions prior to 2.7.13 and 3.2.2 are vulnerable to a cross-site scripting attack (leading to JS execution) when editing the URL parameter. Versions 2.7.13 and 3.2.2 don't use export.php, which was deprecated. They use…

  • CVE-2024-51995HigNov 7, 2024
    risk 0.46cvss 7.1epss 0.00

    Combodo iTop is a web based IT Service Management tool. An attacker can request any `route` we want as long as we specify an `operation` that is allowed. This issue has been addressed in version 3.2.0 by applying the same access control pattern as in `UI.php` to the…

  • CVE-2026-31880HigAug 21, 2026
    risk 0.45cvss 8.0epss 0.00

    Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the universal search. This issue has been fixed in version 3.2.3.

  • CVE-2026-31803HigAug 21, 2026
    risk 0.45cvss 8.0epss 0.00

    Combodo iTop is a web based IT service management tool. Prior to 3.2.3, 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in pages/tagadmin.php. This issue has been fixed in version 3.2.3.

  • CVE-2026-30890HigAug 21, 2026
    risk 0.45cvss 8.0epss 0.00

    Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the synchro import script. This issue has been fixed in version 3.2.3.

  • CVE-2026-30826HigAug 21, 2026
    risk 0.45cvss 8.0epss 0.00

    Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the testing OQL query functionality. This issue has been fixed in version 3.2.3.

  • CVE-2025-27139MedFeb 25, 2025
    risk 0.44cvss 6.8epss 0.00

    Combodo iTop is a web based IT service management tool. Versions prior to 2.7.12, 3.1.2, and 3.2.0 are vulnerable to cross-site scripting when the preferences page is opened. Versions 2.7.12, 3.1.2, and 3.2.0 fix the issue.

  • CVE-2021-32776MedJul 21, 2021
    risk 0.44cvss 6.8epss 0.00

    Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.4, CSRF tokens can be reused by a malicious user, as on Windows servers no cleanup is done on CSRF tokens. This issue is fixed in versions 2.7.4 and 3.0.0.

  • CVE-2020-15221MedJan 13, 2021
    risk 0.44cvss 6.8epss 0.01

    Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 3.0.0, by modifying target browser local storage, an XSS can be generated in the iTop console breadcrumb. This is fixed in versions 2.7.2 and 3.0.0.

Page 2 of 6