VendorsCombodoitopall versions
Vulnerabilities

Combodo iTop (aka IT Operations Portal)

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

81CVEs
CVE-2022-39216
Combodo iTop's weak password reset token leads to account takeover
Published 2023-03-14 · Modified
9.8EPSS 0.009
CVE-2023-48710
iTop limit pages/exec.php script to PHP files
Published 2024-04-15 · Analyzed
9.8EPSS 0.007
CVE-2022-39214
Authenticated users of Combodo iTop can take over any account
Published 2023-03-14 · Modified
9.6EPSS 0.256
CVE-2024-54139
Combodo iTop vulnerable to XSS leading to CSRF breach on _table_id parameter
Published 2024-12-13 · Analyzed
9.6EPSS 0.002
CVE-2021-41162
Cross-site Scripting in Combodo iTop
Published 2022-04-21 · Modified
9.3EPSS 0.007
CVE-2021-41161
XSS in csvimport in 3.0.0-beta versions
Published 2022-04-21 · Modified
9.3EPSS 0.007
CVE-2022-24780
Code Injection in Combodo iTop
Published 2022-04-05 · Modified
8.8EPSS 0.057
CVE-2021-21406
Command Injection vulnerability in the Setup Wizard
Published 2021-07-21 · Modified
8.8EPSS 0.010
CVE-2023-34447
iTop XSS vulnerability on pages/UI.php
Published 2023-10-25 · Modified
8.8EPSS 0.007
CVE-2024-52002
Cross-Site Request Forgery (CSRF) in several iTop pages
Published 2024-11-08 · Analyzed
8.8EPSS 0.007
CVE-2024-51740
SSRF through arbitrary PHP class instantiation in the user portal in Combodo iTop
Published 2024-11-05 · Analyzed
8.8EPSS 0.005
CVE-2023-34446
iTop XSS vulnerability on pages/preferences.php
Published 2023-10-25 · Modified
8.8EPSS 0.005
CVE-2020-12781
Combodo iTop - CSRF
Published 2020-08-10 · Modified
8.8EPSS 0.005
CVE-2023-47622
iTop vulnerable to XSS vulnerability in dashlet refresh
Published 2024-04-15 · Analyzed
8.8EPSS 0.004
CVE-2023-47626
iTop vulnerable to XSS vulnerability in authent-token
Published 2024-04-15 · Analyzed
8.8EPSS 0.004
CVE-2021-32776
No CSRF form token cleanup on Windows servers
Published 2021-07-21 · Modified
8.8EPSS 0.004
CVE-2024-31448
Cross-site Scripting vulnerability in link CSV import in Combodo iTop
Published 2024-11-04 · Analyzed
8.8EPSS 0.003
CVE-2023-34443
Cross-site Scripting vulnerability in the run_query.php page in Combodo iTop
Published 2024-11-04 · Analyzed
8.8EPSS 0.003
CVE-2023-34444
Cross-site Scripting vulnerability on pages/ajax.searchform.php in Combodo iTop
Published 2024-11-04 · Analyzed
8.8EPSS 0.003
CVE-2023-34445
Cross-site Scripting vulnerability on pages/ajax.render.php in Combodo iTop
Published 2024-11-04 · Analyzed
8.8EPSS 0.003
CVE-2024-31998
CSRF security issue on CSV import in Combodo iTop
Published 2024-11-04 · Analyzed
8.8EPSS 0.002
CVE-2025-48065
Combodo iTop vulnerable to reflected XSS via objection edition form error
Published 2025-11-10 · Analyzed
8.8EPSS 0.002
CVE-2025-47932
Combodo iTop vulnerable to reflected XSS in ajax.render.php render_dashboard
Published 2025-11-10 · Analyzed
8.8EPSS 0.002
CVE-2025-47773
Combodo iTop has XSS vulnerability in /pages/ajax.render.php
Published 2025-11-10 · Analyzed
8.8EPSS 0.002
CVE-2021-32663
Unauthorized setup leads to SSRF in Combodo/iTop
Published 2021-10-19 · Modified
8.7EPSS 0.015
CVE-2022-24870
Stored Cross-site Scripting in Combodo iTop
Published 2022-04-21 · Modified
8.7EPSS 0.009
CVE-2023-47123
iTop vulnerable to XSS vulnerability in n:n relations "tagset" widget
Published 2024-04-15 · Analyzed
8.7EPSS 0.003
CVE-2025-49145
iTop admin can drop iTop database using webhooks
Published 2025-11-10 · Analyzed
8.7EPSS 0.003
CVE-2025-47286
Combodo iTop vulnerable to Remote Code Execution in the backup creation functionality
Published 2025-11-10 · Analyzed
8.6EPSS 0.005
CVE-2025-24022
iTop server vulnerable to portal code injection
Published 2025-05-14 · Modified
8.5EPSS 0.006
CVE-2025-48055
Combodo iTop has stored XSS in user portal's browse brick
Published 2025-11-10 · Analyzed
8.5EPSS 0.002
CVE-2019-19821
A post-authentication privilege escalation in the web application of Combodo iTop allows regular authenticated users to access information and modify information with administrative privileges by not following the HTTP Location header in server responses. This is fixed in all iTop packages (community, essential, professional) in versions : 2.5.4, 2.6.3, 2.7.0
Published 2020-03-16 · Modified
8.1EPSS 0.014
CVE-2019-11215
In Combodo iTop 2.2.0 through 2.6.0, if the configuration file is writable, then execution of arbitrary code can be accomplished by calling ajax.dataloader with a maliciously crafted payload. Many conditions can place the configuration file into a writable state: during installation; during upgrade; in certain cases, an error during modification of the file from the web interface leaves the file writable (can be triggered with XSS); a race condition can be triggered by the hub-connector module (community version only from 2.4.1 to 2.6.0); or editing the file in a CLI.
Published 2020-02-14 · Modified
8.1EPSS 0.012
CVE-2021-32664
Reflected XSS in Combodo/iTop
Published 2021-10-19 · Modified
8.1EPSS 0.008
CVE-2021-41245
Possible Cross-Site Request Forgery in Combodo iTop
Published 2022-04-05 · Modified
8.1EPSS 0.007
CVE-2024-52000
Reflected Cross-site Scripting exploit in Combodo iTop
Published 2024-11-08 · Analyzed
8.1EPSS 0.004
CVE-2023-48709
iTop vulnerable to potential formula injection in Excel/CSV export file
Published 2024-04-15 · Analyzed
8.0EPSS 0.010
CVE-2021-21407
Portal : the CSRF token isn't validated
Published 2021-07-21 · Modified
8.0EPSS 0.005
CVE-2023-47489
CSV injection in export as csv in Combodo iTop v.3.1.0-2-11973 allows a local attacker to execute arbitrary code via a crafted script to the export-v2.php and ajax.render.php components.
Published 2023-11-09 · Modified
7.8EPSS 0.004
CVE-2020-4079
Information disclosure vulnerability in iTop
Published 2021-01-12 · Modified
7.7EPSS 0.009
1 / 3Next →