Combodo Itop vulnerabilities
102 known vulnerabilities affecting combodo/itop.
Total CVEs
102
CISA KEV
0
Public exploits
4
Exploited in wild
2
Severity breakdown
CRITICAL4HIGH37MEDIUM59LOW2
Vulnerabilities
Page 2 of 6
CVE-2026-30866P3HIGHCVSS 7.5fixed in 3.2.32026-08-21
CVE-2026-30866 [HIGH] CWE-200 CVE-2026-30866: Combodo iTop is a web based IT service management tool. Prior to 3.2.3, unauthenticated users can ac
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, unauthenticated users can access uploaded sensitive via sniffed url. This issue has been fixed in version 3.2.3.
nvd
CVE-2026-27462P3HIGHCVSS 7.5fixed in 3.2.32026-08-21
CVE-2026-27462 [HIGH] CWE-204 CVE-2026-27462: Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop returns different respo
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop returns different responses for valid/invalid usernames depending on multiple factors in the reset password mechanism, leading to user enumeration. This issue has been fixed in version 3.2.3.
nvd
CVE-2026-33240P3HIGHCVSS 8.8fixed in 3.2.32026-08-21
CVE-2026-33240 [HIGH] CWE-79 CVE-2026-33240: Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there was a Reflected Cross-
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there was a Reflected Cross-Site Scripting (XSS) vulnerability in the foreign key search criteria API. This issue has been fixed in version 3.2.3.
nvd
CVE-2023-48709P3HIGHCVSS 8.0fixed in 2.7.9≥ 3.0.0, < 3.0.4+3 more2024-04-15
CVE-2023-48709 [HIGH] CWE-74 CVE-2023-48709: iTop is an IT service management platform. When exporting data from backoffice or portal in CSV or
iTop is an IT service management platform. When exporting data from backoffice or portal in CSV or Excel files, users' inputs may include malicious formulas that may be imported into Excel. As Excel 2016 does **not** prevent Remote Code Execution by default, uninformed users may become victims. This vulnerability is fixed in 2.7.9, 3.0.4, 3.1.1, and 3.2.
nvd
CVE-2020-4079P3HIGHCVSS 7.7fixed in 2.7.2v2.7.32021-01-12
CVE-2020-4079 [HIGH] CWE-200 CVE-2020-4079: Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 2.8.0, whe
Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 2.8.0, when the ajax endpoint for the "excel export" portal functionality is called directly it allows getting data without scope filtering. This allows a user to access data they which they should not have access to. This is fixed in versions 2.7.2 and 3.0.0.
nvd
CVE-2026-30864P3HIGHCVSS 8.9fixed in 3.2.32026-08-24
CVE-2026-30864 [HIGH] CWE-79 CVE-2026-30864: Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to Reflec
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to Reflected Cross-Site Scripting (XSS) in the dashboard revert functionality. This issue has been fixed in version 3.2.3.
nvd
CVE-2024-52002P3HIGHCVSS 8.8fixed in 3.2.02024-11-08
CVE-2024-52002 [HIGH] CWE-352 CVE-2024-52002: Combodo iTop is a simple, web based IT Service Management tool. Several url endpoints are subject to
Combodo iTop is a simple, web based IT Service Management tool. Several url endpoints are subject to a Cross-Site Request Forgery (CSRF) vulnerability. Please refer to the linked GHSA for the complete list. This issue has been addressed in version 3.2.0 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
nvd
CVE-2020-12777P3HIGHCVSS 7.5fixed in 2.7.1v3.0.0+1 more2020-08-10
CVE-2020-12777 [HIGH] CWE-200 CVE-2020-12777: A function in Combodo iTop contains a vulnerability of Broken Access Control, which allows unauthori
A function in Combodo iTop contains a vulnerability of Broken Access Control, which allows unauthorized attacker to inject command and disclose system information.
nvd
CVE-2026-27490P3HIGHCVSS 7.5fixed in 3.2.32026-08-21
CVE-2026-27490 [HIGH] CWE-330 CVE-2026-27490: Combodo iTop is a web based IT service management tool. Prior to 3.2.3, inline images that are acces
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, inline images that are accessible without being authenticated are protected by a weak 24-bit pseudo-random secret. This issue has been fixed in version 3.2.3.
nvd
CVE-2024-54139P3CRITICALCVSS 9.6fixed in 2.7.11≥ 3.0.0, < 3.1.2+3 more2024-12-13
CVE-2024-54139 [CRITICAL] CWE-79 CVE-2024-54139: Combodo iTop is an open source and web-based IT service management platform. Prior to versions 2.7.1
Combodo iTop is an open source and web-based IT service management platform. Prior to versions 2.7.11, 3.1.2, and 3.2.0., iTop has a cross-site scripting vulnerability that can lead to cross-site request forgery on the `_table_id` parameter. Versions 2.7.11, 3.1.2, and 3.2.0 contain a patch for the issue.
nvd
CVE-2024-31998P3HIGHCVSS 8.8fixed in 3.1.22024-11-05
CVE-2024-31998 [HIGH] CWE-352 CVE-2024-31998: Combodo iTop is a simple, web based IT Service Management tool. A CSRF can be performed on CSV impor
Combodo iTop is a simple, web based IT Service Management tool. A CSRF can be performed on CSV import simulation. This issue has been fixed in versions 3.1.2 and 3.2.0. All users are advised to upgrade. There are no known workarounds for this vulnerability.
nvd
CVE-2019-11215P3HIGHCVSS 8.1≥ 2.2.0, ≤ 2.4.0≥ 2.4.1, ≤ 2.6.02020-02-14
CVE-2019-11215 [HIGH] CWE-79 CVE-2019-11215: In Combodo iTop 2.2.0 through 2.6.0, if the configuration file is writable, then execution of arbitr
In Combodo iTop 2.2.0 through 2.6.0, if the configuration file is writable, then execution of arbitrary code can be accomplished by calling ajax.dataloader with a maliciously crafted payload. Many conditions can place the configuration file into a writable state: during installation; during upgrade; in certain cases, an error during modification of the
nvd
CVE-2024-51995P3HIGHCVSS 7.1fixed in 3.2.02024-11-07
CVE-2024-51995 [HIGH] CWE-284 CVE-2024-51995: Combodo iTop is a web based IT Service Management tool. An attacker can request any `route` we want
Combodo iTop is a web based IT Service Management tool. An attacker can request any `route` we want as long as we specify an `operation` that is allowed. This issue has been addressed in version 3.2.0 by applying the same access control pattern as in `UI.php` to the `ajax.render.php` page which does not allow arbitrary `routes` to be dispatched. All us
nvd
CVE-2021-32776P3HIGHCVSS 8.8fixed in 2.7.4v3.0.02021-07-21
CVE-2021-32776 [HIGH] CWE-352 CVE-2021-32776: Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.4, CSRF tokens can
Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.4, CSRF tokens can be reused by a malicious user, as on Windows servers no cleanup is done on CSRF tokens. This issue is fixed in versions 2.7.4 and 3.0.0.
nvd
CVE-2023-47489P3HIGHCVSS 7.8v3.1.0-2-119732023-11-09
CVE-2023-47489 [HIGH] CVE-2023-47489: CSV injection in export as csv in Combodo iTop v.3.1.0-2-11973 allows a local attacker to execute ar
CSV injection in export as csv in Combodo iTop v.3.1.0-2-11973 allows a local attacker to execute arbitrary code via a crafted script to the export-v2.php and ajax.render.php components.
nvd
CVE-2026-34836P3MEDIUMCVSS 6.5fixed in 3.2.32026-08-21
CVE-2026-34836 [MEDIUM] CWE-862 CVE-2026-34836: Combodo iTop is a web based IT service management tool. Prior to 3.2.3, improper access control in a
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, improper access control in ajax.render.php and ajax.document.php allows for document access without checking on user permissions. This issue has been fixed in version 3.2.3.
nvd
CVE-2026-30826P3HIGHCVSS 8.0fixed in 3.2.32026-08-21
CVE-2026-30826 [HIGH] CWE-79 CVE-2026-30826: Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-S
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the testing OQL query functionality. This issue has been fixed in version 3.2.3.
nvd
CVE-2026-30819P3HIGHCVSS 7.3fixed in 3.2.32026-08-21
CVE-2026-30819 [HIGH] CWE-79 CVE-2026-30819: Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop has a reflected Cross-S
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop has a reflected Cross-Site Scripting (XSS) vulnerability in its dashboard revert functionality with the parameter dashboard_id in /pages/ajax.render.php. This issue has been fixed in version 3.2.3.
nvd
CVE-2026-31880P3HIGHCVSS 8.0fixed in 3.2.32026-08-21
CVE-2026-31880 [HIGH] CWE-79 CVE-2026-31880: Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-S
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the universal search. This issue has been fixed in version 3.2.3.
nvd
CVE-2026-31803P3HIGHCVSS 8.0fixed in 3.2.32026-08-21
CVE-2026-31803 [HIGH] CWE-79 CVE-2026-31803: Combodo iTop is a web based IT service management tool. Prior to 3.2.3, 3.2.3, there is a Reflected
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in pages/tagadmin.php. This issue has been fixed in version 3.2.3.
nvd