combodo CVE Vulnerabilities & Metrics

Focus on combodo vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About combodo Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with combodo. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total combodo CVEs: 60
Earliest CVE date: 26 Nov 2011, 03:57 UTC
Latest CVE date: 25 Feb 2025, 20:15 UTC

Latest CVE reference: CVE-2025-27139

Rolling Stats

30-day Count (Rolling): 1
365-day Count (Rolling): 21

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 250.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 250.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical combodo CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 2.68

Max CVSS: 6.8

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 33
4.0-6.9 29
7.0-8.9 0
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS combodo CVEs

These are the five CVEs with the highest CVSS scores for combodo, sorted by severity first and recency.

All CVEs for combodo

CVE-2025-27139 combodo vulnerability CVSS: 0 25 Feb 2025, 20:15 UTC

Combodo iTop is a web based IT service management tool. Versions prior to 2.7.12, 3.1.2, and 3.2.0 are vulnerable to cross-site scripting when the preferences page is opened. Versions 2.7.12, 3.1.2, and 3.2.0 fix the issue.

CVE-2024-52002 combodo vulnerability CVSS: 0 08 Nov 2024, 23:15 UTC

Combodo iTop is a simple, web based IT Service Management tool. Several url endpoints are subject to a Cross-Site Request Forgery (CSRF) vulnerability. Please refer to the linked GHSA for the complete list. This issue has been addressed in version 3.2.0 and all users are advised to upgrade. There are no known workarounds for this vulnerability.

CVE-2024-52001 combodo vulnerability CVSS: 0 08 Nov 2024, 23:15 UTC

Combodo iTop is a simple, web based IT Service Management tool. In affected versions portal users are able to access forbidden services information. This issue has been addressed in version 3.2.0. All users are advised to upgrade. There are no known workarounds for this vulnerability.

CVE-2024-52000 combodo vulnerability CVSS: 0 08 Nov 2024, 23:15 UTC

Combodo iTop is a simple, web based IT Service Management tool. Affected versions are subject to a reflected Cross-site Scripting (XSS) exploit by way of editing a request's payload which can lead to malicious javascript execution. This issue has been addressed in version 3.2.0 via systematic escaping of error messages when rendering on the page. All users are advised to upgrade. There are no known workarounds for this vulnerability.

CVE-2024-51740 combodo vulnerability CVSS: 0 05 Nov 2024, 19:15 UTC

Combodo iTop is a simple, web based IT Service Management tool. This vulnerability can be used to create HTTP requests on behalf of the server, from a low privileged user. The user portal form manager has been fixed to only instantiate classes derived from it. This issue has been addressed in versions 2.7.11, 3.0.5, 3.1.2, and 3.2.0. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVE-2024-51739 combodo vulnerability CVSS: 0 05 Nov 2024, 18:15 UTC

Combodo iTop is a simple, web based IT Service Management tool. Unauthenticated user can perform users enumeration, which can make it easier to bruteforce a valid account. As a fix the sentence displayed after resetting password no longer shows if the user exists or not. This fix is included in versions 2.7.11, 3.0.5, 3.1.2, and 3.2.0. Users are advised to upgrade. Users unable to upgrade may overload the dictionary entry `"UI:ResetPwd-Error-WrongLogin"` through an extension and replace it with a generic message.

CVE-2024-32870 combodo vulnerability CVSS: 0 05 Nov 2024, 00:15 UTC

Combodo iTop is a simple, web based IT Service Management tool. Server, OS, DBMS, PHP, and iTop info (name, version and parameters) can be read by anyone having access to iTop URI. This issue has been patched in versions 2.7.11, 3.0.5, 3.1.2, and 3.2.0. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVE-2024-31998 combodo vulnerability CVSS: 0 05 Nov 2024, 00:15 UTC

Combodo iTop is a simple, web based IT Service Management tool. A CSRF can be performed on CSV import simulation. This issue has been fixed in versions 3.1.2 and 3.2.0. All users are advised to upgrade. There are no known workarounds for this vulnerability.

CVE-2024-31448 combodo vulnerability CVSS: 0 05 Nov 2024, 00:15 UTC

Combodo iTop is a simple, web based IT Service Management tool. By filling malicious code in a CSV content, an Cross-site Scripting (XSS) attack can be performed when importing this content. This issue has been fixed in versions 3.1.2 and 3.2.0. All users are advised to upgrade. Users unable to upgrade should validate CSV content before importing it.

CVE-2023-34445 combodo vulnerability CVSS: 0 05 Nov 2024, 00:15 UTC

Combodo iTop is a simple, web based IT Service Management tool. When displaying pages/ajax.render.php XSS are possible for scripts outside of script tags. This issue has been fixed in versions 2.7.9, 3.0.4, 3.1.0. All users are advised to upgrade. There are no known workarounds for this vulnerability.

CVE-2023-34444 combodo vulnerability CVSS: 0 05 Nov 2024, 00:15 UTC

Combodo iTop is a simple, web based IT Service Management tool. When displaying pages/ajax.searchform.php XSS are possible for scripts outside of script tags. This issue has been fixed in versions 2.7.9, 3.0.4, 3.1.0. All users are advised to upgrade. There are no known workarounds for this vulnerability.

CVE-2023-34443 combodo vulnerability CVSS: 0 05 Nov 2024, 00:15 UTC

Combodo iTop is a simple, web based IT Service Management tool. When displaying page Run queries Cross-site Scripting (XSS) are possible for scripts outside of script tags. This has been fixed in versions 2.7.9, 3.0.4, 3.1.0. All users are advised to upgrade. There are no known workarounds for this vulnerability.

CVE-2023-48710 combodo vulnerability CVSS: 0 15 Apr 2024, 18:15 UTC

iTop is an IT service management platform. Files from the `env-production` folder can be retrieved even though they should have restricted access. Hopefully, there is no sensitive files stored in that folder natively, but there could be from a third-party module. The `pages/exec.php` script as been fixed to limit execution of PHP files only. Other file types won't be retrieved and exposed. The vulnerability is fixed in 2.7.10, 3.0.4, 3.1.1, and 3.2.0.

CVE-2023-48709 combodo vulnerability CVSS: 0 15 Apr 2024, 18:15 UTC

iTop is an IT service management platform. When exporting data from backoffice or portal in CSV or Excel files, users' inputs may include malicious formulas that may be imported into Excel. As Excel 2016 does **not** prevent Remote Code Execution by default, uninformed users may become victims. This vulnerability is fixed in 2.7.9, 3.0.4, 3.1.1, and 3.2.0.

CVE-2023-47626 combodo vulnerability CVSS: 0 15 Apr 2024, 18:15 UTC

iTop is an IT service management platform. When displaying/editing the user's personal tokens, XSS attacks are possible. This vulnerability is fixed in 3.1.1.

CVE-2023-47622 combodo vulnerability CVSS: 0 15 Apr 2024, 18:15 UTC

iTop is an IT service management platform. When dashlet are refreshed, XSS attacks are possible. This vulnerability is fixed in 3.0.4 and 3.1.1.

CVE-2023-47123 combodo vulnerability CVSS: 0 15 Apr 2024, 18:15 UTC

iTop is an IT service management platform. By filling malicious code in an object friendlyname / complementary name, an XSS attack can be performed when this object will displayed as an n:n relation item in another object. This vulnerability is fixed in 3.1.1 and 3.2.0.

CVE-2023-45808 combodo vulnerability CVSS: 0 15 Apr 2024, 18:15 UTC

iTop is an IT service management platform. When creating or updating an object, extkey values aren't checked to be in the current user silo. In other words, by forging an http request, the user can create objects pointing to out of silo objects (for example a UserRequest in an out of scope Organization). Fixed in iTop 2.7.10, 3.0.4, 3.1.1, and 3.2.0.

CVE-2023-44396 combodo vulnerability CVSS: 0 15 Apr 2024, 18:15 UTC

iTop is an IT service management platform. Dashlet edits ajax endpoints can be used to produce XSS. Fixed in iTop 2.7.10, 3.0.4, and 3.1.1.

CVE-2023-43790 combodo vulnerability CVSS: 0 15 Apr 2024, 17:15 UTC

iTop is an IT service management platform. By manipulating HTTP queries, a user can inject malicious content in the fields used for the object friendlyname value. This vulnerability is fixed in 3.1.1 and 3.2.0.

CVE-2023-38511 combodo vulnerability CVSS: 0 15 Apr 2024, 17:15 UTC

iTop is an IT service management platform. Dashboard editor : can load multiple files and URL, and full path disclosure on dashboard config file. This vulnerability is fixed in 3.0.4 and 3.1.1.

CVE-2023-47489 combodo vulnerability CVSS: 0 09 Nov 2023, 06:15 UTC

CSV injection in export as csv in Combodo iTop v.3.1.0-2-11973 allows a local attacker to execute arbitrary code via a crafted script to the export-v2.php and ajax.render.php components.

CVE-2023-47488 combodo vulnerability CVSS: 0 09 Nov 2023, 06:15 UTC

Cross Site Scripting vulnerability in Combodo iTop v.3.1.0-2-11973 allows a local attacker to obtain sensitive information via a crafted script to the attrib_manager_id parameter in the General Information page and the id parameter in the contact page.

CVE-2023-34447 combodo vulnerability CVSS: 0 25 Oct 2023, 18:17 UTC

iTop is an open source, web-based IT service management platform. Prior to versions 3.0.4 and 3.1.0, on `pages/UI.php`, cross site scripting is possible. This issue is fixed in versions 3.0.4 and 3.1.0.

CVE-2023-34446 combodo vulnerability CVSS: 0 25 Oct 2023, 18:17 UTC

iTop is an open source, web-based IT service management platform. Prior to versions 3.0.4 and 3.1.0, when displaying `pages/preferences.php`, cross site scripting is possible. This issue is fixed in versions 3.0.4 and 3.1.0.

CVE-2022-39216 combodo vulnerability CVSS: 0 14 Mar 2023, 16:15 UTC

Combodo iTop is an open source, web-based IT service management platform. Prior to versions 2.7.8 and 3.0.2-1, the reset password token is generated without any randomness parameter. This may lead to account takeover. The issue is fixed in versions 2.7.8 and 3.0.2-1.

CVE-2022-39214 combodo vulnerability CVSS: 0 14 Mar 2023, 16:15 UTC

Combodo iTop is an open source, web-based IT service management platform. Prior to versions 2.7.8 and 3.0.2-1, a user who can log in on iTop is able to take over any account just by knowing the account's username. This issue is fixed in versions 2.7.8 and 3.0.2-1.

CVE-2022-31403 combodo vulnerability CVSS: 4.3 14 Jun 2022, 17:15 UTC

ITOP v3.0.1 was discovered to contain a cross-site scripting (XSS) vulnerability via /itop/pages/ajax.render.php.

CVE-2022-31402 combodo vulnerability CVSS: 4.3 10 Jun 2022, 17:15 UTC

ITOP v3.0.1 was discovered to contain a cross-site scripting (XSS) vulnerability via /itop/webservices/export-v2.php.

CVE-2022-24870 combodo vulnerability CVSS: 3.5 21 Apr 2022, 17:15 UTC

Combodo iTop is a web based IT Service Management tool. In 3.0.0 beta releases prior to 3.0.0 beta3 a malicious script can be injected in tooltips using iTop customization mechanism. This provides a stored cross site scripting attack vector to authorized users of the system. Users are advised to upgrade. There are no known workarounds for this issue.

CVE-2021-41162 combodo vulnerability CVSS: 4.3 21 Apr 2022, 17:15 UTC

Combodo iTop is a web based IT Service Management tool. In 3.0.0 beta releases prior to beta6 the `ajax.render.php?operation=wizard_helper` page did not properly escape the user supplied parameters, allowing for a cross site scripting attack vector. Users are advised to upgrade. There are no known workarounds for this issue.

CVE-2021-41161 combodo vulnerability CVSS: 4.3 21 Apr 2022, 17:15 UTC

Combodo iTop is a web based IT Service Management tool. In versions prior to 3.0.0-beta6 the export CSV page don't properly escape the user supplied parameters, allowing for javascript injection into rendered csv files. Users are advised to upgrade. There are no known workarounds for this issue.

CVE-2022-24811 combodo vulnerability CVSS: 3.5 05 Apr 2022, 19:15 UTC

Combodi iTop is a web based IT Service Management tool. Prior to versions 2.7.6 and 3.0.0, cross-site scripting is possible for scripts outside of script tags when displaying HTML attachments. This issue is fixed in versions 2.7.6 and 3.0.0. There are currently no known workarounds.

CVE-2022-24780 combodo vulnerability CVSS: 6.5 05 Apr 2022, 19:15 UTC

Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.6 and 3.0.0, users of the iTop user portal can send TWIG code to the server by forging specific http queries, and execute arbitrary code on the server using http server user privileges. This issue is fixed in versions 2.7.6 and 3.0.0. There are currently no known workarounds.

CVE-2021-41245 combodo vulnerability CVSS: 5.8 05 Apr 2022, 15:15 UTC

Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.6 and 3.0.0, CSRF tokens generated by `privUITransactionFile` aren't properly checked. Versions 2.7.6 and 3.0.0 contain a patch for this issue. As a workaround, use the session implementation by adding in the iTop config file.

CVE-2021-32664 combodo vulnerability CVSS: 3.5 19 Oct 2021, 18:15 UTC

Combodo iTop is an open source web based IT Service Management tool. In affected versions there is a XSS vulnerability on "run query" page when logged as administrator. This has been resolved in versions 2.6.5 and 2.7.5.

CVE-2021-32663 combodo vulnerability CVSS: 5.0 19 Oct 2021, 18:15 UTC

iTop is an open source web based IT Service Management tool. In affected versions an attacker can call the system setup without authentication. Given specific parameters this can lead to SSRF. This issue has been resolved in versions 2.6.5 and 2.7.5 and later

CVE-2021-32776 combodo vulnerability CVSS: 6.8 21 Jul 2021, 21:15 UTC

Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.4, CSRF tokens can be reused by a malicious user, as on Windows servers no cleanup is done on CSRF tokens. This issue is fixed in versions 2.7.4 and 3.0.0.

CVE-2021-32775 combodo vulnerability CVSS: 4.0 21 Jul 2021, 21:15 UTC

Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.4, a non admin user can get access to many class/field values through GroupBy Dashlet error message. This issue is fixed in versions 2.7.4 and 3.0.0.

CVE-2021-21407 combodo vulnerability CVSS: 4.3 21 Jul 2021, 16:15 UTC

Combodo iTop is an open source, web based IT Service Management tool. Prior to version 2.7.4, the CSRF token validation can be bypassed through iTop portal via a tricky browser procedure. The vulnerability is patched in version 2.7.4 and 3.0.0.

CVE-2021-21406 combodo vulnerability CVSS: 6.5 21 Jul 2021, 15:15 UTC

Combodo iTop is an open source, web based IT Service Management tool. In versions prior to 2.7.4, there is a command injection vulnerability in the Setup Wizard when providing Graphviz executable path. The vulnerability is patched in version 2.7.4 and 3.0.0.

CVE-2020-15221 combodo vulnerability CVSS: 3.5 13 Jan 2021, 17:15 UTC

Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 3.0.0, by modifying target browser local storage, an XSS can be generated in the iTop console breadcrumb. This is fixed in versions 2.7.2 and 3.0.0.

CVE-2020-15220 combodo vulnerability CVSS: 5.8 13 Jan 2021, 17:15 UTC

Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 3.0.0, two cookies are created for the same session, which leads to a possibility to steal user session. This is fixed in versions 2.7.2 and 3.0.0.

CVE-2020-15219 combodo vulnerability CVSS: 4.0 13 Jan 2021, 17:15 UTC

Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 3.0.0, when a download error is triggered in the user portal, an SQL query is displayed to the user. This is fixed in versions 2.7.2 and 3.0.0.

CVE-2020-15218 combodo vulnerability CVSS: 3.5 13 Jan 2021, 17:15 UTC

Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 3.0.0, admin pages are cached, so that their content is visible after deconnection by using the browser back button. This is fixed in versions 2.7.2 and 3.0.0.

CVE-2020-4079 combodo vulnerability CVSS: 4.0 12 Jan 2021, 20:15 UTC

Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 2.8.0, when the ajax endpoint for the "excel export" portal functionality is called directly it allows getting data without scope filtering. This allows a user to access data they which they should not have access to. This is fixed in versions 2.7.2 and 3.0.0.

CVE-2020-12781 combodo vulnerability CVSS: 6.8 10 Aug 2020, 03:15 UTC

Combodo iTop contains a cross-site request forgery (CSRF) vulnerability, attackers can execute specific commands via malicious site request forgery.

CVE-2020-12780 combodo vulnerability CVSS: 5.0 10 Aug 2020, 03:15 UTC

A security misconfiguration exists in Combodo iTop, which can expose sensitive information.

CVE-2020-12779 combodo vulnerability CVSS: 3.5 10 Aug 2020, 03:15 UTC

Combodo iTop contains a stored Cross-site Scripting vulnerability, which can be attacked by uploading file with malicious script.

CVE-2020-12778 combodo vulnerability CVSS: 4.3 10 Aug 2020, 03:15 UTC

Combodo iTop does not validate inputted parameters, attackers can inject malicious commands and launch XSS attack.

CVE-2020-12777 combodo vulnerability CVSS: 5.0 10 Aug 2020, 03:15 UTC

A function in Combodo iTop contains a vulnerability of Broken Access Control, which allows unauthorized attacker to inject command and disclose system information.

CVE-2020-11696 combodo vulnerability CVSS: 4.3 05 Jun 2020, 22:15 UTC

In Combodo iTop a menu shortcut name can be exploited with a stored XSS payload. This is fixed in all iTop packages (community, essential, professional) in version 2.7.0 and iTop essential and iTop professional in version 2.6.4.

CVE-2020-11697 combodo vulnerability CVSS: 4.3 05 Jun 2020, 21:15 UTC

In Combodo iTop, dashboard ids can be exploited with a reflective XSS payload. This is fixed in all iTop packages (community, essential, professional) for version 2.7.0 and in iTop essential and iTop professional packages for version 2.6.4.

CVE-2019-19821 combodo vulnerability CVSS: 5.5 16 Mar 2020, 18:15 UTC

A post-authentication privilege escalation in the web application of Combodo iTop allows regular authenticated users to access information and modify information with administrative privileges by not following the HTTP Location header in server responses. This is fixed in all iTop packages (community, essential, professional) in versions : 2.5.4, 2.6.3, 2.7.0

CVE-2019-13967 combodo vulnerability CVSS: 5.0 14 Feb 2020, 22:15 UTC

iTop 2.2.0 through 2.6.0 allows remote attackers to cause a denial of service (application outage) via many requests to launch a compile operation. The requests use the pages/exec.php?exec_env=production&exec_module=itop-hub-connector&exec_page=ajax.php&operation=compile URI. This only affects the community version.

CVE-2019-13966 combodo vulnerability CVSS: 4.3 14 Feb 2020, 22:15 UTC

In iTop through 2.6.0, an XSS payload can be delivered in certain fields (such as icon) of the XML file used to build the dashboard. This is similar to CVE-2015-6544 (which is only about the dashboard title).

CVE-2019-13965 combodo vulnerability CVSS: 4.3 14 Feb 2020, 22:15 UTC

Because of a lack of sanitization around error messages, multiple Reflective XSS issues exist in iTop through 2.6.0 via the param_file parameter to webservices/export.php, webservices/cron.php, or env-production/itop-backup/backup.php. By default, any XSS sent to the administrator can be transformed to remote command execution because of CVE-2018-10642 (still working through 2.6.0) The Reflective XSS can also become a stored XSS within the same account because of another vulnerability.

CVE-2019-11215 combodo vulnerability CVSS: 6.8 14 Feb 2020, 18:15 UTC

In Combodo iTop 2.2.0 through 2.6.0, if the configuration file is writable, then execution of arbitrary code can be accomplished by calling ajax.dataloader with a maliciously crafted payload. Many conditions can place the configuration file into a writable state: during installation; during upgrade; in certain cases, an error during modification of the file from the web interface leaves the file writable (can be triggered with XSS); a race condition can be triggered by the hub-connector module (community version only from 2.4.1 to 2.6.0); or editing the file in a CLI.

CVE-2018-10642 combodo vulnerability CVSS: 6.5 02 May 2018, 07:29 UTC

Command injection vulnerability in Combodo iTop 2.4.1 allows remote authenticated administrators to execute arbitrary commands by changing the platform configuration, because web/env-production/itop-config/config.php contains a function called TestConfig() that calls the vulnerable function eval().

CVE-2015-6544 combodo vulnerability CVSS: 4.3 20 Feb 2018, 20:29 UTC

Cross-site scripting (XSS) vulnerability in application/dashboard.class.inc.php in Combodo iTop before 2.2.0-2459 allows remote attackers to inject arbitrary web script or HTML via a dashboard title.

CVE-2013-0805 combodo vulnerability CVSS: 4.3 20 Mar 2014, 16:55 UTC

Multiple cross-site scripting (XSS) vulnerabilities in the search feature in iTop (aka IT Operations Portal) 2.0, 1.2.1, 1.2, and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) text parameter to pages/UI.php or (2) expression parameter to pages/run_query.php. NOTE: some of these details are obtained from third party information.

CVE-2011-4275 combodo vulnerability CVSS: 4.3 26 Nov 2011, 03:57 UTC

Multiple cross-site scripting (XSS) vulnerabilities in iTop (aka IT Operations Portal) 1.1.181 and 1.2.0-RC-282 allow remote attackers to inject arbitrary web script or HTML via (1) a crafted company name, (2) a crafted database server name, (3) a crafted CSV file, (4) a crafted copy-and-paste action, (5) the auth_user parameter in a suggest_pwd action to UI.php, (6) the c[menu] parameter to UniversalSearch.php, (7) the description parameter in a SearchFormToAdd_document_list action to UI.php, (8) the category parameter in an errors action to audit.php, or (9) the suggest_pwd parameter to UI.php.