Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Combodo — Vulnerabilities & Security Advisories 87

Browse all 87 CVE security advisories affecting Combodo. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Combodo is a software development firm best known for creating iTop, an open-source IT Service Management platform used for incident, problem, and change management. Historically, its applications have been targeted due to a significant volume of recorded vulnerabilities, including Remote Code Execution, Cross-Site Scripting, and SQL Injection. These flaws often stem from insufficient input validation and improper access controls within the web interface. While the company maintains an active security response process, the sheer number of disclosed Common Vulnerabilities and Exposures highlights persistent challenges in securing legacy codebases. Major incidents have primarily involved exploitation of these injection flaws by attackers seeking unauthorized administrative access or data exfiltration. Users are advised to maintain strict patch management protocols and implement robust network segmentation to mitigate risks associated with these historically common vulnerability classes.

Found 87 results / 87 Clear Filters
Top products by Combodo: iTop
CVE ID Title CVSS Severity Published
CVE-2023-38511 iTop Dashboard editor vulnerable dashboard config file parameter — iTop CWE-22 5.0 Medium 2024-04-15
CVE-2023-34447 iTop XSS vulnerability on pages/UI.php — iTop CWE-79 8.8 High 2023-10-25
CVE-2023-34446 iTop XSS vulnerability on pages/preferences.php — iTop CWE-79 8.8 High 2023-10-25
CVE-2022-39216 Combodo iTop's weak password reset token leads to account takeover — iTop CWE-330 7.4 High 2023-03-14
CVE-2022-39214 Authenticated users of Combodo iTop can take over any account — iTop CWE-863 9.6 Critical 2023-03-14
CVE-2021-41162 Cross-site Scripting in Combodo iTop — iTop CWE-79 9.3 Critical 2022-04-21
CVE-2022-24870 Stored Cross-site Scripting in Combodo iTop — iTop CWE-79 8.7 High 2022-04-21
CVE-2021-41161 XSS in csvimport in 3.0.0-beta versions — iTop CWE-79 9.3 Critical 2022-04-21
CVE-2022-24811 Cross-site Scripting in Combodo iTop — iTop CWE-79 5.4 Medium 2022-04-05
CVE-2022-24780 Code Injection in Combodo iTop — iTop CWE-94 8.8 High 2022-04-05
CVE-2021-41245 Possible Cross-Site Request Forgery in Combodo iTop — iTop CWE-352 6.5 Medium 2022-04-05
CVE-2021-32664 Reflected XSS in Combodo/iTop — iTop CWE-79 8.1 High 2021-10-19
CVE-2021-32663 Unauthorized setup leads to SSRF in Combodo/iTop — iTop CWE-918 8.7 High 2021-10-19
CVE-2021-32776 No CSRF form token cleanup on Windows servers — iTop CWE-352 6.8 Medium 2021-07-21
CVE-2021-32775 Any user can see any fields (including mailbox password) with GroupBy Dashlet — iTop CWE-209 7.7 High 2021-07-21
CVE-2021-21407 Portal : the CSRF token isn't validated — iTop CWE-352 8.0 High 2021-07-21
CVE-2021-21406 Command Injection vulnerability in the Setup Wizard — iTop CWE-77 5.8 Medium 2021-07-21
CVE-2020-15221 XSS in the breadcrumbs — iTop CWE-79 6.8 Medium 2021-01-13
CVE-2020-15220 Session fixation — iTop CWE-613 6.1 Medium 2021-01-13
CVE-2020-15219 SQL query displayed on portal error — iTop CWE-209 4.3 Medium 2021-01-13
CVE-2020-15218 Admin pages are cached and can be embedded — iTop CWE-613 6.8 Medium 2021-01-13
CVE-2020-4079 Information disclosure vulnerability in iTop — iTop CWE-200 7.7 High 2021-01-12
CVE-2020-12781 Combodo iTop - CSRF — iTop CWE-352 5.7 Medium 2020-08-10
CVE-2020-12780 Combodo iTop - Security Misconfiguration — iTop 7.5 High 2020-08-10
CVE-2020-12779 Combodo iTop - Stored XSS — iTop 6.8 Medium 2020-08-10
CVE-2020-12777 Combodo iTop - Broken Access Control — iTop 7.5 High 2020-08-10
CVE-2020-12778 Combodo iTop - Reflected XSS — iTop 7.4 High 2020-08-10

This page lists every published CVE security advisory associated with Combodo. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.