Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

iTop — Vulnerabilities & Security Advisories 87

All 87 CVE vulnerabilities found in iTop, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities affecting iTop, a web-based project management system, with a primary focus on common weakness types such as cross-site scripting, SQL injection, and authentication bypass. It collects all publicly disclosed advisories for iTop across its entire release history, covering known defects and their associated Common Vulnerabilities and Exposures. Readers can use this section to track a vendor’s security posture, understand the prevalence of specific weakness classes, and review the complete vulnerability history for the iTop product line.

Vendor: Combodo

CVE ID Title CVSS Severity Published
CVE-2026-40877 Combodo iTop: PHP Object Injection Leading to Remote Code Execution on user preferences CWE-502 8.7 High 2026-08-24
CVE-2026-30864 Combodo iTop: Reflected XSS in dashboard revert CWE-79 8.9 High 2026-08-24
CVE-2026-39975 Combodo iTop: Remote code execution using external auth variable value CWE-94 9.4 Critical 2026-08-24
CVE-2026-34949 Combodo iTop: Unauthenticated user can delete .readonly file CWE-306 6.5 Medium 2026-08-21
CVE-2026-34948 Combodo iTop: Access control bypass via OQL joins CWE-200 7.7 High 2026-08-21
CVE-2026-34836 Combodo iTop: Improper access control in ajax.render.php and ajax.document.php CWE-862 6.5 Medium 2026-08-21
CVE-2026-34741 Combodo iTop: Authentication bypass in exec.php allows PHP file execution CWE-306 8.6 High 2026-08-21
CVE-2026-33333 Combodo iTop: Information disclosure in ajax.render.php CWE-209 3.5 Low 2026-08-21
CVE-2026-33240 Combodo iTop: Reflected XSS in foreign key search criteria CWE-79 8.8 High 2026-08-21
CVE-2026-33047 Combodo iTop: Object can be locked by a user without write permissions CWE-862 4.3 Medium 2026-08-21
CVE-2026-31936 Combodo iTop: Unauthorized access to object information via search operation CWE-862 8.8 High 2026-08-21
CVE-2026-31880 Combodo iTop: Reflected XSS in universal search CWE-79 8.0 High 2026-08-21
CVE-2026-31803 Combodo iTop: Reflected XSS in tag admin CWE-79 8.0 High 2026-08-21
CVE-2026-30890 Combodo iTop: Reflected XSS in synchro/synchro_import.php CWE-79 8.0 High 2026-08-21
CVE-2026-30865 Combodo iTop: Reflected XSS in dashboard save CWE-79 7.1 High 2026-08-21
CVE-2026-30826 Combodo iTop: Reflected XSS in run_query.php CWE-79 8.0 High 2026-08-21
CVE-2026-30819 Combodo iTop: Reflected XSS in /pages/ajax.render.php dashboard_id parameter CWE-79 7.3 High 2026-08-21
CVE-2026-27490 Combodo iTop: Weak secret generation for inline image CWE-331 7.5 High 2026-08-21
CVE-2026-27463 Combodo iTop: Version disclosure via login page logo CWE-200 5.3 Medium 2026-08-21
CVE-2026-27462 Combodo iTop: User enumeration via password reset CWE-204 7.5 High 2026-08-21
CVE-2026-30866 Combodo iTop: Insecured access to uploaded images via sniffed url CWE-306 7.5 High 2026-08-21
CVE-2025-64167 Combodo iTop vulnerable to reflected XSS in webservices/export.php CWE-79 7.1 High 2025-11-10
CVE-2025-49145 iTop admin can drop iTop database using webhooks CWE-863 8.7 High 2025-11-10
CVE-2025-48878 Combodo iTop vulnerable to IDOR with ModuleInstallation object CWE-862 4.3 Medium 2025-11-10
CVE-2025-48065 Combodo iTop vulnerable to reflected XSS via objection edition form error CWE-79 8.8 High 2025-11-10
CVE-2025-48055 Combodo iTop has stored XSS in user portal's browse brick CWE-79 8.5 High 2025-11-10
CVE-2025-47932 Combodo iTop vulnerable to reflected XSS in ajax.render.php render_dashboard CWE-79 8.8 High 2025-11-10
CVE-2025-47773 Combodo iTop has XSS vulnerability in /pages/ajax.render.php CWE-79 8.8 High 2025-11-10
CVE-2025-47286 Combodo iTop vulnerable to Remote Code Execution in the backup creation functionality CWE-74 9.1 - 2025-11-10
CVE-2025-24969 iTop portal user can see any other contact's picture CWE-639 5.0 Medium 2025-05-14

All 87 known CVE vulnerabilities affecting iTop with full Chinese analysis, references, and POCs where available.