VYPR

Vendor CVEs

Combodo

All CVEs

103 total · sorted by risk
  • CVE-2026-30819HigAug 21, 2026
    risk 0.40cvss 7.3epss 0.00

    Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop has a reflected Cross-Site Scripting (XSS) vulnerability in its dashboard revert functionality with the parameter dashboard_id in /pages/ajax.render.php. This issue has been fixed in version 3.2.3.

  • CVE-2024-52000MedNov 8, 2024
    risk 0.40cvss 6.1epss 0.00

    Combodo iTop is a simple, web based IT Service Management tool. Affected versions are subject to a reflected Cross-site Scripting (XSS) exploit by way of editing a request's payload which can lead to malicious javascript execution. This issue has been addressed in version 3.2.0…

  • CVE-2023-47488MedNov 9, 2023
    risk 0.40cvss 6.1epss 0.01

    Cross Site Scripting vulnerability in Combodo iTop v.3.1.0-2-11973 allows a local attacker to obtain sensitive information via a crafted script to the attrib_manager_id parameter in the General Information page and the id parameter in the contact page.

  • CVE-2022-31403MedJun 14, 2022
    risk 0.40cvss 6.1epss 0.02

    ITOP v3.0.1 was discovered to contain a cross-site scripting (XSS) vulnerability via /itop/pages/ajax.render.php.

  • CVE-2022-31402MedJun 10, 2022
    risk 0.40cvss 6.1epss 0.02

    ITOP v3.0.1 was discovered to contain a cross-site scripting (XSS) vulnerability via /itop/webservices/export-v2.php.

  • CVE-2020-15220MedJan 13, 2021
    risk 0.40cvss 6.1epss 0.01

    Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 3.0.0, two cookies are created for the same session, which leads to a possibility to steal user session. This is fixed in versions 2.7.2 and 3.0.0.

  • CVE-2020-11696MedJun 5, 2020
    risk 0.40cvss 6.1epss 0.01

    In Combodo iTop a menu shortcut name can be exploited with a stored XSS payload. This is fixed in all iTop packages (community, essential, professional) in version 2.7.0 and iTop essential and iTop professional in version 2.6.4.

  • CVE-2020-11697MedJun 5, 2020
    risk 0.40cvss 6.1epss 0.01

    In Combodo iTop, dashboard ids can be exploited with a reflective XSS payload. This is fixed in all iTop packages (community, essential, professional) for version 2.7.0 and in iTop essential and iTop professional packages for version 2.6.4.

  • CVE-2019-13966MedFeb 14, 2020
    risk 0.40cvss 6.1epss 0.01

    In iTop through 2.6.0, an XSS payload can be delivered in certain fields (such as icon) of the XML file used to build the dashboard. This is similar to CVE-2015-6544 (which is only about the dashboard title).

  • CVE-2019-13965MedFeb 14, 2020
    risk 0.40cvss 6.1epss 0.02

    Because of a lack of sanitization around error messages, multiple Reflective XSS issues exist in iTop through 2.6.0 via the param_file parameter to webservices/export.php, webservices/cron.php, or env-production/itop-backup/backup.php. By default, any XSS sent to the…

  • CVE-2026-30865HigAug 21, 2026
    risk 0.39cvss 7.1epss 0.00

    Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the dashboard save functionality. This issue has been fixed in version 3.2.3.

  • CVE-2024-32870MedNov 5, 2024
    risk 0.38cvss 5.8epss 0.01

    Combodo iTop is a simple, web based IT Service Management tool. Server, OS, DBMS, PHP, and iTop info (name, version and parameters) can be read by anyone having access to iTop URI. This issue has been patched in versions 2.7.11, 3.0.5, 3.1.2, and 3.2.0. Users are advised to…

  • CVE-2021-21406MedJul 21, 2021
    risk 0.38cvss 5.8epss 0.01

    Combodo iTop is an open source, web based IT Service Management tool. In versions prior to 2.7.4, there is a command injection vulnerability in the Setup Wizard when providing Graphviz executable path. The vulnerability is patched in version 2.7.4 and 3.0.0.

  • CVE-2020-12781MedAug 10, 2020
    risk 0.37cvss 5.7epss 0.00

    Combodo iTop contains a cross-site request forgery (CSRF) vulnerability, attackers can execute specific commands via malicious site request forgery.

  • CVE-2026-34949MedAug 21, 2026
    risk 0.35cvss 6.5epss 0.00

    Combodo iTop is a web based IT service management tool.Prior to 3.2.3, an unauthenticated user could delete the .readonly file on iTop instances — a file created during the setup process that prevents users from performing write actions. This issue has been fixed in version…

  • CVE-2026-34836MedAug 21, 2026
    risk 0.35cvss 6.5epss 0.00

    Combodo iTop is a web based IT service management tool. Prior to 3.2.3, improper access control in ajax.render.php and ajax.document.php allows for document access without checking on user permissions. This issue has been fixed in version 3.2.3.

  • CVE-2024-51994MedNov 7, 2024
    risk 0.35cvss 5.4epss 0.00

    Combodo iTop is a web based IT Service Management tool. In affected versions uploading a text file containing some java script in the portal will trigger an Cross-site Scripting (XSS) vulnerability. This issue has been addressed in version 3.2.0 and all users are advised to…

  • CVE-2025-24026MedMay 14, 2025
    risk 0.34cvss 5.3epss 0.00

    iTop is an web based IT Service Management tool. Versions prior to 3.2.1 are vulnerable to regular expression denial of service (ReDoS) that may, under some circumstances, affect iTop server. Version 3.2.1 doesn't use the affected variable in the regular expression. As a…

  • CVE-2025-24969MedMay 14, 2025
    risk 0.33cvss 5.0epss 0.00

    iTop is an web based IT Service Management tool. Prior to version 3.2.1, a portal user can see any other contacts picture by changing the picture ID in the URL. Version 3.2.1 contains a patch for the issue.

  • CVE-2015-6544MedFeb 20, 2018
    risk 0.33cvss 6.1epss 0.05

    Cross-site scripting (XSS) vulnerability in application/dashboard.class.inc.php in Combodo iTop before 2.2.0-2459 allows remote attackers to inject arbitrary web script or HTML via a dashboard title.

  • CVE-2025-48878MedNov 10, 2025
    risk 0.28cvss 4.3epss 0.00

    Combodo iTop is a web based IT service management tool. In versions on the 3.x branch prior to 3.2.2, an insecure direct object reference allows a user (e.g. with Service desk agent profile) to create a ModuleInstallation object when they shouldn't be able to do so. Version…

  • CVE-2025-24785MedMay 14, 2025
    risk 0.28cvss 4.3epss 0.00

    iTop is an web based IT Service Management tool. In version 3.2.0, an attacker may send a URL to the server to trigger a PHP error. The next user trying to load this dashboard would encounter a crashed start page. Version 3.2.1 fixes the issue by checking the provided…

  • CVE-2024-52001MedNov 8, 2024
    risk 0.28cvss 4.3epss 0.00

    Combodo iTop is a simple, web based IT Service Management tool. In affected versions portal users are able to access forbidden services information. This issue has been addressed in version 3.2.0. All users are advised to upgrade. There are no known workarounds for this…

  • CVE-2024-51740MedNov 5, 2024
    risk 0.28cvss 4.3epss 0.01

    Combodo iTop is a simple, web based IT Service Management tool. This vulnerability can be used to create HTTP requests on behalf of the server, from a low privileged user. The user portal form manager has been fixed to only instantiate classes derived from it. This issue has…

  • CVE-2020-15219MedJan 13, 2021
    risk 0.28cvss 4.3epss 0.01

    Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 3.0.0, when a download error is triggered in the user portal, an SQL query is displayed to the user. This is fixed in versions 2.7.2 and 3.0.0.

  • CVE-2026-27463MedAug 21, 2026
    risk 0.27cvss 5.3epss 0.00

    Combodo iTop is a web based IT service management tool. Prior to 3.2.3, the HTML title attribute of the logo in the login page contains the complete iTop version. This issue has been fixed in version 3.2.3.

  • CVE-2024-51993LowNov 7, 2024
    risk 0.22cvss 3.4epss 0.00

    Combodo iTop is a web based IT Service Management tool. An attacker accessing a backup file or the database can read some passwords for misconfigured Users. This issue has been addressed in version 3.2.0 and all users are advised to upgrade. Users unable to upgrade are advised…

  • CVE-2026-33047MedAug 21, 2026
    risk 0.21cvss 4.3epss 0.00

    Combodo iTop is a web based IT service management tool. Prior to 3.2.3, an object can be locked by a user who is not assigned write permissions. This issue has been fixed in version 3.2.3.

  • CVE-2026-33333LowAug 21, 2026
    risk 0.16cvss 3.5epss 0.00

    Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is sensitive information disclosure in the error messages. This issue has been fixed in version 3.2.3.

  • CVE-2011-4275Nov 26, 2011
    risk 0.03cvss —epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in iTop (aka IT Operations Portal) 1.1.181 and 1.2.0-RC-282 allow remote attackers to inject arbitrary web script or HTML via (1) a crafted company name, (2) a crafted database server name, (3) a crafted CSV file, (4) a crafted…

  • CVE-2022-39214CriMar 14, 2023
    risk 0.02cvss 9.6epss 0.26

    Combodo iTop is an open source, web-based IT service management platform. Prior to versions 2.7.8 and 3.0.2-1, a user who can log in on iTop is able to take over any account just by knowing the account's username. This issue is fixed in versions 2.7.8 and 3.0.2-1.

  • CVE-2025-24022HigMay 14, 2025
    risk 0.00cvss 8.5epss 0.01

    iTop is an web based IT Service Management tool. Prior to versions 2.7.12, 3.1.3, and 3.2.1, server code execution is possible through the frontend of iTop's portal. This is fixed in versions 2.7.12, 3.1.3 and 3.2.1.

  • CVE-2025-24021MedMay 14, 2025
    risk 0.00cvss 5.0epss 0.00

    iTop is an web based IT Service Management tool. Prior to versions 2.7.12, 3.1.3, and 3.2.1, anyone with an account having portal access can set value to object fields when they're not supposed to. Versions 2.7.12, 3.1.3, and 3.2.1 contain a fix for the issue.

  • CVE-2023-48710CriApr 15, 2024
    risk 0.00cvss 9.8epss 0.01

    iTop is an IT service management platform. Files from the `env-production` folder can be retrieved even though they should have restricted access. Hopefully, there is no sensitive files stored in that folder natively, but there could be from a third-party module. The…

  • CVE-2023-48709HigApr 15, 2024
    risk 0.00cvss 8.0epss 0.01

    iTop is an IT service management platform. When exporting data from backoffice or portal in CSV or Excel files, users' inputs may include malicious formulas that may be imported into Excel. As Excel 2016 does **not** prevent Remote Code Execution by default, uninformed users…

  • CVE-2023-47622HigApr 15, 2024
    risk 0.00cvss 8.8epss 0.00

    iTop is an IT service management platform. When dashlet are refreshed, XSS attacks are possible. This vulnerability is fixed in 3.0.4 and 3.1.1.

  • CVE-2023-47123HigApr 15, 2024
    risk 0.00cvss 8.7epss 0.00

    iTop is an IT service management platform. By filling malicious code in an object friendlyname / complementary name, an XSS attack can be performed when this object will displayed as an n:n relation item in another object. This vulnerability is fixed in 3.1.1 and 3.2.0.

  • CVE-2023-45808MedApr 15, 2024
    risk 0.00cvss 4.1epss 0.00

    iTop is an IT service management platform. When creating or updating an object, extkey values aren't checked to be in the current user silo. In other words, by forging an http request, the user can create objects pointing to out of silo objects (for example a UserRequest in an…

  • CVE-2023-44396MedApr 15, 2024
    risk 0.00cvss 6.8epss 0.00

    iTop is an IT service management platform. Dashlet edits ajax endpoints can be used to produce XSS. Fixed in iTop 2.7.10, 3.0.4, and 3.1.1.

  • CVE-2023-43790MedApr 15, 2024
    risk 0.00cvss 5.7epss 0.00

    iTop is an IT service management platform. By manipulating HTTP queries, a user can inject malicious content in the fields used for the object friendlyname value. This vulnerability is fixed in 3.1.1 and 3.2.0.

  • CVE-2023-38511MedApr 15, 2024
    risk 0.00cvss 5.0epss 0.01

    iTop is an IT service management platform. Dashboard editor : can load multiple files and URL, and full path disclosure on dashboard config file. This vulnerability is fixed in 3.0.4 and 3.1.1.

  • CVE-2023-34447HigOct 25, 2023
    risk 0.00cvss 8.8epss 0.01

    iTop is an open source, web-based IT service management platform. Prior to versions 3.0.4 and 3.1.0, on `pages/UI.php`, cross site scripting is possible. This issue is fixed in versions 3.0.4 and 3.1.0.

  • CVE-2023-34446HigOct 25, 2023
    risk 0.00cvss 8.8epss 0.01

    iTop is an open source, web-based IT service management platform. Prior to versions 3.0.4 and 3.1.0, when displaying `pages/preferences.php`, cross site scripting is possible. This issue is fixed in versions 3.0.4 and 3.1.0.

  • CVE-2022-39216HigMar 14, 2023
    risk 0.00cvss 7.4epss 0.01

    Combodo iTop is an open source, web-based IT service management platform. Prior to versions 2.7.8 and 3.0.2-1, the reset password token is generated without any randomness parameter. This may lead to account takeover. The issue is fixed in versions 2.7.8 and 3.0.2-1.

  • CVE-2022-24870HigApr 21, 2022
    risk 0.00cvss 8.7epss 0.01

    Combodo iTop is a web based IT Service Management tool. In 3.0.0 beta releases prior to 3.0.0 beta3 a malicious script can be injected in tooltips using iTop customization mechanism. This provides a stored cross site scripting attack vector to authorized users of the system.…

  • CVE-2021-41162CriApr 21, 2022
    risk 0.00cvss 9.3epss 0.01

    Combodo iTop is a web based IT Service Management tool. In 3.0.0 beta releases prior to beta6 the `ajax.render.php?operation=wizard_helper` page did not properly escape the user supplied parameters, allowing for a cross site scripting attack vector. Users are advised to upgrade.…

  • CVE-2021-41161CriApr 21, 2022
    risk 0.00cvss 9.3epss 0.01

    Combodo iTop is a web based IT Service Management tool. In versions prior to 3.0.0-beta6 the export CSV page don't properly escape the user supplied parameters, allowing for javascript injection into rendered csv files. Users are advised to upgrade. There are no known…

  • CVE-2022-24811MedApr 5, 2022
    risk 0.00cvss 5.4epss 0.01

    Combodi iTop is a web based IT Service Management tool. Prior to versions 2.7.6 and 3.0.0, cross-site scripting is possible for scripts outside of script tags when displaying HTML attachments. This issue is fixed in versions 2.7.6 and 3.0.0. There are currently no known…

  • CVE-2022-24780HigApr 5, 2022
    risk 0.00cvss 8.8epss 0.06

    Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.6 and 3.0.0, users of the iTop user portal can send TWIG code to the server by forging specific http queries, and execute arbitrary code on the server using http server user privileges. This issue…

  • CVE-2021-41245MedApr 5, 2022
    risk 0.00cvss 6.5epss 0.01

    Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.6 and 3.0.0, CSRF tokens generated by `privUITransactionFile` aren't properly checked. Versions 2.7.6 and 3.0.0 contain a patch for this issue. As a workaround, use the session implementation by…