Combodo
Combodo Itop: vulnerabilidades y CVE
Combodo Itop tiene 102 vulnerabilidades publicadas, 29 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE102
Últimos 12 meses29
Críticas4
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-40877 | Alta (8.7) | 0.53% | — | 24 ago 2026 | Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in the user preference functionality, which can lead to remote code execution. This issue has been fixed… |
| CVE-2026-39975 | Crítica (9.4) | 0.59% | — | 24 ago 2026 | Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, unauthenticated users could delete the .readonly file on iTop instances, leading to code execution. This file, created during the setup process,… |
| CVE-2026-30864 | Alta (8.9) | 0.35% | — | 24 ago 2026 | Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to Reflected Cross-Site Scripting (XSS) in the dashboard revert functionality. This issue has been fixed in version 3.2.3. |
| CVE-2026-34949 | Media (6.5) | 0.37% | — | 21 ago 2026 | Combodo iTop is a web based IT service management tool.Prior to 3.2.3, an unauthenticated user could delete the .readonly file on iTop instances — a file created during the setup process that prevents users from… |
| CVE-2026-34948 | Alta (7.7) | 0.39% | — | 21 ago 2026 | Combodo iTop is a web based IT service management tool. Prior to 3.2.3, only classes present in the SELECT clause are protected by the silos access check in OQL. This issue has been fixed in version 3.2.3. |
| CVE-2026-34836 | Media (6.5) | 0.39% | — | 21 ago 2026 | Combodo iTop is a web based IT service management tool. Prior to 3.2.3, improper access control in ajax.render.php and ajax.document.php allows for document access without checking on user permissions. This issue has… |
| CVE-2026-34741 | Alta (8.6) | 0.64% | — | 21 ago 2026 | Combodo iTop is a web based IT service management tool. Prior to 3.2.3, authentication bypass allows unauthenticated remote attackers to execute arbitrary PHP files from the env-production directory on a new iTop… |
| CVE-2026-33333 | Baja (3.5) | 0.28% | — | 21 ago 2026 | Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is sensitive information disclosure in the error messages. This issue has been fixed in version 3.2.3. |
| CVE-2026-33240 | Alta (8.8) | 0.47% | — | 21 ago 2026 | Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there was a Reflected Cross-Site Scripting (XSS) vulnerability in the foreign key search criteria API. This issue has been fixed in version 3.2.3. |
| CVE-2026-33047 | Media (4.3) | 0.37% | — | 21 ago 2026 | Combodo iTop is a web based IT service management tool. Prior to 3.2.3, an object can be locked by a user who is not assigned write permissions. This issue has been fixed in version 3.2.3. |
| CVE-2026-31936 | Alta (8.8) | 0.48% | — | 21 ago 2026 | Combodo iTop is a web based IT service management tool. Prior to 3.2.3, users can access to unauthorized object information through the search operation. This issue has been fixed in version 3.2.3. |
| CVE-2026-31880 | Alta (8) | 0.43% | — | 21 ago 2026 | Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the universal search. This issue has been fixed in version 3.2.3. |
| CVE-2026-31803 | Alta (8) | 0.43% | — | 21 ago 2026 | Combodo iTop is a web based IT service management tool. Prior to 3.2.3, 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in pages/tagadmin.php. This issue has been fixed in version 3.2.3. |
| CVE-2026-30890 | Alta (8) | 0.43% | — | 21 ago 2026 | Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the synchro import script. This issue has been fixed in version 3.2.3. |
| CVE-2026-30865 | Alta (7.1) | 0.26% | — | 21 ago 2026 | Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the dashboard save functionality. This issue has been fixed in version 3.2.3. |
| CVE-2026-30826 | Alta (8) | 0.43% | — | 21 ago 2026 | Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the testing OQL query functionality. This issue has been fixed in version 3.2.3. |
| CVE-2026-30866 | Alta (7.5) | 0.46% | — | 21 ago 2026 | Combodo iTop is a web based IT service management tool. Prior to 3.2.3, unauthenticated users can access uploaded sensitive via sniffed url. This issue has been fixed in version 3.2.3. |
| CVE-2026-30819 | Alta (7.3) | 0.37% | — | 21 ago 2026 | Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop has a reflected Cross-Site Scripting (XSS) vulnerability in its dashboard revert functionality with the parameter dashboard_id in… |
| CVE-2026-27490 | Alta (7.5) | 0.43% | — | 21 ago 2026 | Combodo iTop is a web based IT service management tool. Prior to 3.2.3, inline images that are accessible without being authenticated are protected by a weak 24-bit pseudo-random secret. This issue has been fixed in… |
| CVE-2026-27463 | Media (5.3) | 0.34% | — | 21 ago 2026 | Combodo iTop is a web based IT service management tool. Prior to 3.2.3, the HTML title attribute of the logo in the login page contains the complete iTop version. This issue has been fixed in version 3.2.3. |
| CVE-2026-27462 | Alta (7.5) | 0.43% | — | 21 ago 2026 | Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop returns different responses for valid/invalid usernames depending on multiple factors in the reset password mechanism, leading to user… |
| CVE-2025-64167 | Media (6.1) | 0.23% | — | 10 nov 2025 | Combodo iTop is a web based IT service management tool. Versions prior to 2.7.13 and 3.2.2 are vulnerable to a cross-site scripting attack (leading to JS execution) when editing the URL parameter. Versions 2.7.13 and… |
| CVE-2025-49145 | Media (6.5) | 0.30% | — | 10 nov 2025 | Combodo iTop is a web based IT service management tool. In versions prior to 2.7.13 and 3.2.2, a user that has enough rights to create webhooks (mostly administrators) can drop the database. This is fixed in iTop 2.7.13… |
| CVE-2025-48878 | Media (4.3) | 0.20% | — | 10 nov 2025 | Combodo iTop is a web based IT service management tool. In versions on the 3.x branch prior to 3.2.2, an insecure direct object reference allows a user (e.g. with Service desk agent profile) to create a… |
| CVE-2025-48065 | Media (6.1) | 0.22% | — | 10 nov 2025 | Combodo iTop is a web based IT service management tool. Versions prior to 2.7.13 and 3.2.2 are vulnerable to cross-site scripting when a field with an error contains malicious content. Versions 2.7.13 and 3.2.2 protect… |
| CVE-2025-48055 | Media (5.4) | 0.18% | — | 10 nov 2025 | Combodo iTop is a web based IT service management tool. In versions prior to 3.2.2, when displaying content in a browse brick in the user portal, a cross-site scripting attack can occur. This is fixed in versions 3.2.2… |
| CVE-2025-47932 | Media (6.1) | 0.22% | — | 10 nov 2025 | Combodo iTop is a web based IT service management tool. Versions prior to 2.7.13 and 3.2.2 are vulnerable to cross-site scripting when a dashboard is rendered via an AJAX call. Versions 2.7.13 and 3.2.2 sanitize the var… |
| CVE-2025-47773 | Media (6.1) | 0.22% | — | 10 nov 2025 | Combodo iTop is a web based IT service management tool. Versions prior to 2.7.13 and 3.2.2 are vulnerable to cross-site scripting when a dashboard is edited via an AJAX call. Versions 2.7.13 and 3.2.2 protect rendered… |
| CVE-2025-47286 | Alta (8.6) | 0.47% | — | 10 nov 2025 | Combodo iTop is a web based IT service management tool. In versions prior to 2.7.13 and 3.2.2, an administrator can, by editing the configuration of the iTop instance, execute code on the server. Versions 2.7.13 and… |
| CVE-2025-24969 | Media (5) | 0.27% | — | 14 may 2025 | iTop is an web based IT Service Management tool. Prior to version 3.2.1, a portal user can see any other contacts picture by changing the picture ID in the URL. Version 3.2.1 contains a patch for the issue. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.