Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Combodo — Vulnerabilities & Security Advisories 87

Browse all 87 CVE security advisories affecting Combodo. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Combodo is a software development firm best known for creating iTop, an open-source IT Service Management platform used for incident, problem, and change management. Historically, its applications have been targeted due to a significant volume of recorded vulnerabilities, including Remote Code Execution, Cross-Site Scripting, and SQL Injection. These flaws often stem from insufficient input validation and improper access controls within the web interface. While the company maintains an active security response process, the sheer number of disclosed Common Vulnerabilities and Exposures highlights persistent challenges in securing legacy codebases. Major incidents have primarily involved exploitation of these injection flaws by attackers seeking unauthorized administrative access or data exfiltration. Users are advised to maintain strict patch management protocols and implement robust network segmentation to mitigate risks associated with these historically common vulnerability classes.

Top products by Combodo: iTop
CVE ID Title CVSS Severity Published
CVE-2026-40877 Combodo iTop: PHP Object Injection Leading to Remote Code Execution on user preferences — iTop CWE-502 8.7 High 2026-08-24
CVE-2026-30864 Combodo iTop: Reflected XSS in dashboard revert — iTop CWE-79 8.9 High 2026-08-24
CVE-2026-39975 Combodo iTop: Remote code execution using external auth variable value — iTop CWE-94 9.4 Critical 2026-08-24
CVE-2026-34949 Combodo iTop: Unauthenticated user can delete .readonly file — iTop CWE-306 6.5 Medium 2026-08-21
CVE-2026-34948 Combodo iTop: Access control bypass via OQL joins — iTop CWE-200 7.7 High 2026-08-21
CVE-2026-34836 Combodo iTop: Improper access control in ajax.render.php and ajax.document.php — iTop CWE-862 6.5 Medium 2026-08-21
CVE-2026-34741 Combodo iTop: Authentication bypass in exec.php allows PHP file execution — iTop CWE-306 8.6 High 2026-08-21
CVE-2026-33333 Combodo iTop: Information disclosure in ajax.render.php — iTop CWE-209 3.5 Low 2026-08-21
CVE-2026-33240 Combodo iTop: Reflected XSS in foreign key search criteria — iTop CWE-79 8.8 High 2026-08-21
CVE-2026-33047 Combodo iTop: Object can be locked by a user without write permissions — iTop CWE-862 4.3 Medium 2026-08-21
CVE-2026-31936 Combodo iTop: Unauthorized access to object information via search operation — iTop CWE-862 8.8 High 2026-08-21
CVE-2026-31880 Combodo iTop: Reflected XSS in universal search — iTop CWE-79 8.0 High 2026-08-21
CVE-2026-31803 Combodo iTop: Reflected XSS in tag admin — iTop CWE-79 8.0 High 2026-08-21
CVE-2026-30890 Combodo iTop: Reflected XSS in synchro/synchro_import.php — iTop CWE-79 8.0 High 2026-08-21
CVE-2026-30865 Combodo iTop: Reflected XSS in dashboard save — iTop CWE-79 7.1 High 2026-08-21
CVE-2026-30826 Combodo iTop: Reflected XSS in run_query.php — iTop CWE-79 8.0 High 2026-08-21
CVE-2026-30819 Combodo iTop: Reflected XSS in /pages/ajax.render.php dashboard_id parameter — iTop CWE-79 7.3 High 2026-08-21
CVE-2026-27490 Combodo iTop: Weak secret generation for inline image — iTop CWE-331 7.5 High 2026-08-21
CVE-2026-27463 Combodo iTop: Version disclosure via login page logo — iTop CWE-200 5.3 Medium 2026-08-21
CVE-2026-27462 Combodo iTop: User enumeration via password reset — iTop CWE-204 7.5 High 2026-08-21
CVE-2026-30866 Combodo iTop: Insecured access to uploaded images via sniffed url — iTop CWE-306 7.5 High 2026-08-21
CVE-2025-64167 Combodo iTop vulnerable to reflected XSS in webservices/export.php — iTop CWE-79 7.1 High 2025-11-10
CVE-2025-49145 iTop admin can drop iTop database using webhooks — iTop CWE-863 8.7 High 2025-11-10
CVE-2025-48878 Combodo iTop vulnerable to IDOR with ModuleInstallation object — iTop CWE-862 4.3 Medium 2025-11-10
CVE-2025-48065 Combodo iTop vulnerable to reflected XSS via objection edition form error — iTop CWE-79 8.8 High 2025-11-10
CVE-2025-48055 Combodo iTop has stored XSS in user portal's browse brick — iTop CWE-79 8.5 High 2025-11-10
CVE-2025-47932 Combodo iTop vulnerable to reflected XSS in ajax.render.php render_dashboard — iTop CWE-79 8.8 High 2025-11-10
CVE-2025-47773 Combodo iTop has XSS vulnerability in /pages/ajax.render.php — iTop CWE-79 8.8 High 2025-11-10
CVE-2025-47286 Combodo iTop vulnerable to Remote Code Execution in the backup creation functionality — iTop CWE-74 9.1 - 2025-11-10
CVE-2025-24969 iTop portal user can see any other contact's picture — iTop CWE-639 5.0 Medium 2025-05-14

This page lists every published CVE security advisory associated with Combodo. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.