VendorsCombodoitopany version
Vulnerabilities

Combodo iTop (aka IT Operations Portal) any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

74CVEs
CVE-2024-51739
Users enumeration allowed through Rest API in Combodo iTop
Published 2024-11-05 · Analyzed
7.5EPSS 0.012
CVE-2020-12780
Combodo iTop - Security Misconfiguration
Published 2020-08-10 · Modified
7.5EPSS 0.012
CVE-2020-12778
Combodo iTop - Reflected XSS
Published 2020-08-10 · Modified
7.4EPSS 0.008
CVE-2018-10642
Command injection vulnerability in Combodo iTop 2.4.1 allows remote authenticated administrators to execute arbitrary commands by changing the platform configuration, because web/env-production/itop-config/config.php contains a function called TestConfig() that calls the vulnerable function eval().
Published 2018-05-02 · Modified
7.2EPSS 0.074
CVE-2024-51995
Logic bug in ajax.render.php allows for bypass of 'backOffice' access control in Combodo iTop
Published 2024-11-07 · Analyzed
7.1EPSS 0.004
CVE-2024-51994
Cross-site Scripting in portal picture upload in Combodo iTop
Published 2024-11-07 · Analyzed
7.1EPSS 0.003
CVE-2025-64167
Combodo iTop vulnerable to reflected XSS in webservices/export.php
Published 2025-11-10 · Analyzed
7.1EPSS 0.002
CVE-2020-15218
Admin pages are cached and can be embedded
Published 2021-01-13 · Modified
6.8EPSS 0.008
CVE-2020-12779
Combodo iTop - Stored XSS
Published 2020-08-10 · Modified
6.8EPSS 0.006
CVE-2020-15221
XSS in the breadcrumbs
Published 2021-01-13 · Modified
6.8EPSS 0.006
CVE-2023-44396
iTop vulnerable to XSS in dashlet modifications ajax endpoints
Published 2024-04-15 · Analyzed
6.8EPSS 0.004
CVE-2025-27139
Combodo iTop vulnerable to stored self Cross-site Scripting in preferences
Published 2025-02-25 · Analyzed
6.8EPSS 0.002
CVE-2024-52601
iTop portal Insecure Direct Object Reference vulnerability
Published 2025-05-14 · Analyzed
6.5EPSS 0.003
CVE-2024-56157
iTop vulnerable to Self XSS in CSV Import
Published 2025-05-14 · Analyzed
6.3EPSS 0.003
CVE-2015-6544
Cross-site scripting (XSS) vulnerability in application/dashboard.class.inc.php in Combodo iTop before 2.2.0-2459 allows remote attackers to inject arbitrary web script or HTML via a dashboard title.
Published 2018-02-20 · Modified
6.1EPSS 0.054
CVE-2019-13965
Because of a lack of sanitization around error messages, multiple Reflective XSS issues exist in iTop through 2.6.0 via the param_file parameter to webservices/export.php, webservices/cron.php, or env-production/itop-backup/backup.php. By default, any XSS sent to the administrator can be transformed to remote command execution because of CVE-2018-10642 (still working through 2.6.0) The Reflective XSS can also become a stored XSS within the same account because of another vulnerability.
Published 2020-02-14 · Modified
6.1EPSS 0.016
CVE-2019-13966
In iTop through 2.6.0, an XSS payload can be delivered in certain fields (such as icon) of the XML file used to build the dashboard. This is similar to CVE-2015-6544 (which is only about the dashboard title).
Published 2020-02-14 · Modified
6.1EPSS 0.008
CVE-2020-15220
Session fixation
Published 2021-01-13 · Modified
6.1EPSS 0.007
CVE-2020-11696
In Combodo iTop a menu shortcut name can be exploited with a stored XSS payload. This is fixed in all iTop packages (community, essential, professional) in version 2.7.0 and iTop essential and iTop professional in version 2.6.4.
Published 2020-06-05 · Modified
6.1EPSS 0.007
CVE-2020-11697
In Combodo iTop, dashboard ids can be exploited with a reflective XSS payload. This is fixed in all iTop packages (community, essential, professional) for version 2.7.0 and in iTop essential and iTop professional packages for version 2.6.4.
Published 2020-06-05 · Modified
6.1EPSS 0.007
CVE-2024-32870
iTop hub connector Information disclosure
Published 2024-11-04 · Analyzed
5.8EPSS 0.008
CVE-2023-43790
iTop vulnerable to XSS in friendlyname in object details
Published 2024-04-15 · Analyzed
5.7EPSS 0.004
CVE-2022-24811
Cross-site Scripting in Combodo iTop
Published 2022-04-05 · Modified
5.4EPSS 0.007
CVE-2023-45808
iTop missing silo check on extkey in console and portal
Published 2024-04-15 · Analyzed
5.4EPSS 0.003
CVE-2025-24026
iTop Inefficient Regular Expression Complexity vulnerability
Published 2025-05-14 · Analyzed
5.3EPSS 0.003
CVE-2023-38511
iTop Dashboard editor vulnerable dashboard config file parameter
Published 2024-04-15 · Analyzed
5.0EPSS 0.007
CVE-2025-24969
iTop portal user can see any other contact's picture
Published 2025-05-14 · Analyzed
5.0EPSS 0.003
CVE-2025-24021
iTop doesn't have mass assignment of fields in the portal form
Published 2025-05-14 · Modified
5.0EPSS 0.003
CVE-2013-0805
Multiple cross-site scripting (XSS) vulnerabilities in the search feature in iTop (aka IT Operations Portal) 2.0, 1.2.1, 1.2, and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) text parameter to pages/UI.php or (2) expression parameter to pages/run_query.php. NOTE: some of these details are obtained from third party information.
Published 2014-03-20 · Modified
4.3EPSS 0.017
CVE-2020-15219
SQL query displayed on portal error
Published 2021-01-13 · Modified
4.3EPSS 0.007
CVE-2024-52001
Portal user is able to access forbidden services information in Combodo iTop
Published 2024-11-08 · Analyzed
4.3EPSS 0.003
CVE-2025-24785
iTop dashboard vulnerable to denial of service
Published 2025-05-14 · Analyzed
4.3EPSS 0.003
CVE-2025-48878
Combodo iTop vulnerable to IDOR with ModuleInstallation object
Published 2025-11-10 · Analyzed
4.3EPSS 0.002
CVE-2024-51993
Password is stored in clear in the database in Combodo iTop
Published 2024-11-07 · Analyzed
3.4EPSS 0.001
← Prev2 / 2