VendorsCombodoitopall versions
Vulnerabilities

Combodo iTop (aka IT Operations Portal)

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

81CVEs
CVE-2021-32775
Any user can see any fields (including mailbox password) with GroupBy Dashlet
Published 2021-07-21 · Modified
7.7EPSS 0.008
CVE-2019-13967
iTop 2.2.0 through 2.6.0 allows remote attackers to cause a denial of service (application outage) via many requests to launch a compile operation. The requests use the pages/exec.php?exec_env=production&exec_module=itop-hub-connector&exec_page=ajax.php&operation=compile URI. This only affects the community version.
Published 2020-02-14 · Modified
7.5EPSS 0.013
CVE-2020-12777
Combodo iTop - Broken Access Control
Published 2020-08-10 · Modified
7.5EPSS 0.013
CVE-2024-51739
Users enumeration allowed through Rest API in Combodo iTop
Published 2024-11-05 · Analyzed
7.5EPSS 0.012
CVE-2020-12780
Combodo iTop - Security Misconfiguration
Published 2020-08-10 · Modified
7.5EPSS 0.012
CVE-2020-12778
Combodo iTop - Reflected XSS
Published 2020-08-10 · Modified
7.4EPSS 0.008
CVE-2018-10642
Command injection vulnerability in Combodo iTop 2.4.1 allows remote authenticated administrators to execute arbitrary commands by changing the platform configuration, because web/env-production/itop-config/config.php contains a function called TestConfig() that calls the vulnerable function eval().
Published 2018-05-02 · Modified
7.2EPSS 0.074
CVE-2024-51995
Logic bug in ajax.render.php allows for bypass of 'backOffice' access control in Combodo iTop
Published 2024-11-07 · Analyzed
7.1EPSS 0.004
CVE-2024-51994
Cross-site Scripting in portal picture upload in Combodo iTop
Published 2024-11-07 · Analyzed
7.1EPSS 0.003
CVE-2025-64167
Combodo iTop vulnerable to reflected XSS in webservices/export.php
Published 2025-11-10 · Analyzed
7.1EPSS 0.002
CVE-2020-15218
Admin pages are cached and can be embedded
Published 2021-01-13 · Modified
6.8EPSS 0.008
CVE-2020-12779
Combodo iTop - Stored XSS
Published 2020-08-10 · Modified
6.8EPSS 0.006
CVE-2020-15221
XSS in the breadcrumbs
Published 2021-01-13 · Modified
6.8EPSS 0.006
CVE-2023-44396
iTop vulnerable to XSS in dashlet modifications ajax endpoints
Published 2024-04-15 · Analyzed
6.8EPSS 0.004
CVE-2025-27139
Combodo iTop vulnerable to stored self Cross-site Scripting in preferences
Published 2025-02-25 · Analyzed
6.8EPSS 0.002
CVE-2024-52601
iTop portal Insecure Direct Object Reference vulnerability
Published 2025-05-14 · Analyzed
6.5EPSS 0.003
CVE-2024-56157
iTop vulnerable to Self XSS in CSV Import
Published 2025-05-14 · Analyzed
6.3EPSS 0.003
CVE-2015-6544
Cross-site scripting (XSS) vulnerability in application/dashboard.class.inc.php in Combodo iTop before 2.2.0-2459 allows remote attackers to inject arbitrary web script or HTML via a dashboard title.
Published 2018-02-20 · Modified
6.1EPSS 0.054
CVE-2022-31402
ITOP v3.0.1 was discovered to contain a cross-site scripting (XSS) vulnerability via /itop/webservices/export-v2.php.
Published 2022-06-10 · Modified
6.1EPSS 0.023
CVE-2022-31403
ITOP v3.0.1 was discovered to contain a cross-site scripting (XSS) vulnerability via /itop/pages/ajax.render.php.
Published 2022-06-14 · Modified
6.1EPSS 0.018
CVE-2019-13965
Because of a lack of sanitization around error messages, multiple Reflective XSS issues exist in iTop through 2.6.0 via the param_file parameter to webservices/export.php, webservices/cron.php, or env-production/itop-backup/backup.php. By default, any XSS sent to the administrator can be transformed to remote command execution because of CVE-2018-10642 (still working through 2.6.0) The Reflective XSS can also become a stored XSS within the same account because of another vulnerability.
Published 2020-02-14 · Modified
6.1EPSS 0.016
CVE-2023-47488
Cross Site Scripting vulnerability in Combodo iTop v.3.1.0-2-11973 allows a local attacker to obtain sensitive information via a crafted script to the attrib_manager_id parameter in the General Information page and the id parameter in the contact page.
Published 2023-11-09 · Modified
6.1EPSS 0.012
CVE-2019-13966
In iTop through 2.6.0, an XSS payload can be delivered in certain fields (such as icon) of the XML file used to build the dashboard. This is similar to CVE-2015-6544 (which is only about the dashboard title).
Published 2020-02-14 · Modified
6.1EPSS 0.008
CVE-2020-15220
Session fixation
Published 2021-01-13 · Modified
6.1EPSS 0.007
CVE-2020-11696
In Combodo iTop a menu shortcut name can be exploited with a stored XSS payload. This is fixed in all iTop packages (community, essential, professional) in version 2.7.0 and iTop essential and iTop professional in version 2.6.4.
Published 2020-06-05 · Modified
6.1EPSS 0.007
CVE-2020-11697
In Combodo iTop, dashboard ids can be exploited with a reflective XSS payload. This is fixed in all iTop packages (community, essential, professional) for version 2.7.0 and in iTop essential and iTop professional packages for version 2.6.4.
Published 2020-06-05 · Modified
6.1EPSS 0.007
CVE-2024-32870
iTop hub connector Information disclosure
Published 2024-11-04 · Analyzed
5.8EPSS 0.008
CVE-2023-43790
iTop vulnerable to XSS in friendlyname in object details
Published 2024-04-15 · Analyzed
5.7EPSS 0.004
CVE-2022-24811
Cross-site Scripting in Combodo iTop
Published 2022-04-05 · Modified
5.4EPSS 0.007
CVE-2023-45808
iTop missing silo check on extkey in console and portal
Published 2024-04-15 · Analyzed
5.4EPSS 0.003
CVE-2025-24026
iTop Inefficient Regular Expression Complexity vulnerability
Published 2025-05-14 · Analyzed
5.3EPSS 0.003
CVE-2023-38511
iTop Dashboard editor vulnerable dashboard config file parameter
Published 2024-04-15 · Analyzed
5.0EPSS 0.007
CVE-2025-24969
iTop portal user can see any other contact's picture
Published 2025-05-14 · Analyzed
5.0EPSS 0.003
CVE-2025-24021
iTop doesn't have mass assignment of fields in the portal form
Published 2025-05-14 · Modified
5.0EPSS 0.003
CVE-2013-0805
Multiple cross-site scripting (XSS) vulnerabilities in the search feature in iTop (aka IT Operations Portal) 2.0, 1.2.1, 1.2, and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) text parameter to pages/UI.php or (2) expression parameter to pages/run_query.php. NOTE: some of these details are obtained from third party information.
Published 2014-03-20 · Modified
4.3EPSS 0.017
CVE-2011-4275
Multiple cross-site scripting (XSS) vulnerabilities in iTop (aka IT Operations Portal) 1.1.181 and 1.2.0-RC-282 allow remote attackers to inject arbitrary web script or HTML via (1) a crafted company name, (2) a crafted database server name, (3) a crafted CSV file, (4) a crafted copy-and-paste action, (5) the auth_user parameter in a suggest_pwd action to UI.php, (6) the c[menu] parameter to UniversalSearch.php, (7) the description parameter in a SearchFormToAdd_document_list action to UI.php, (8) the category parameter in an errors action to audit.php, or (9) the suggest_pwd parameter to UI.php.
Published 2011-11-26 · Modified
4.36 PoCEPSS 0.015
CVE-2020-15219
SQL query displayed on portal error
Published 2021-01-13 · Modified
4.3EPSS 0.007
CVE-2024-52001
Portal user is able to access forbidden services information in Combodo iTop
Published 2024-11-08 · Analyzed
4.3EPSS 0.003
CVE-2025-24785
iTop dashboard vulnerable to denial of service
Published 2025-05-14 · Analyzed
4.3EPSS 0.003
CVE-2025-48878
Combodo iTop vulnerable to IDOR with ModuleInstallation object
Published 2025-11-10 · Analyzed
4.3EPSS 0.002
← Prev2 / 3Next →