Combodo records
82 published records for vendor combodo.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 18.3%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')41
- CWE-352 Cross-Site Request Forgery (CSRF)6
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor5
- CWE-863 Incorrect Authorization3
- CWE-639 Authorization Bypass Through User-Controlled Key3
- CWE-94 Improper Control of Generation of Code ('Code Injection')3
The weakness classes this vendor ships most often: where to look.
CWEAll records
82 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2022-39216No exploit | Combodo iTop's weak password reset token leads to account takeovercombodo · itop · CWE-330 | Critical9.8 | — | 0.9% | Mar 14, 2023 |
39Monitor | CVE-2023-48710No exploit | iTop limit pages/exec.php script to PHP filescombodo · itop · CWE-552 | Critical9.8 | — | 0.7% | Apr 15, 2024 |
38Monitor | CVE-2022-39214No exploit | Authenticated users of Combodo iTop can take over any accountcombodo · itop · CWE-863 | High7.5 | — | 25.6% | Mar 14, 2023 |
38Monitor | CVE-2024-54139No exploit | Combodo iTop vulnerable to XSS leading to CSRF breach on _table_id parametercombodo · itop · CWE-79 | Critical9.6 | — | 0.2% | Dec 13, 2024 |
37Monitor | CVE-2022-24780Proof of concept | Code Injection in Combodo iTopcombodo · itop · CWE-94 | High8.8 | — | 5.7% | Apr 5, 2022 |
35Monitor | CVE-2021-21406No exploit | Command Injection vulnerability in the Setup Wizardcombodo · itop · CWE-77 | High8.8 | — | 1.0% | Jul 21, 2021 |
35Monitor | CVE-2024-52002Proof of concept | Cross-Site Request Forgery (CSRF) in several iTop pagescombodo · itop · CWE-352 | High8.8 | — | 0.7% | Nov 8, 2024 |
35Monitor | CVE-2024-51740No exploit | SSRF through arbitrary PHP class instantiation in the user portal in Combodo iTopcombodo · itop · CWE-918 | High8.8 | — | 0.5% | Nov 5, 2024 |
35Monitor | CVE-2020-12781No exploit | Combodo iTop contains a cross-site request forgery (CSRF) vulnerability, attackers can execute specific commands via malicious site request combodo · itop · CWE-352 | High8.8 | — | 0.5% | Aug 9, 2020 |
35Monitor | CVE-2021-32776No exploit | No CSRF form token cleanup on Windows serverscombodo · itop · CWE-352 | High8.8 | — | 0.4% | Jul 21, 2021 |
35Monitor | CVE-2024-31998No exploit | CSRF security issue on CSV import in Combodo iTopcombodo · itop · CWE-352 | High8.8 | — | 0.2% | Nov 4, 2024 |
34Monitor | CVE-2025-24022No exploit | iTop server vulnerable to portal code injectioncombodo · itop · CWE-78 | High8.5 | — | 0.6% | May 14, 2025 |
34Monitor | CVE-2025-47286No exploit | Combodo iTop vulnerable to Remote Code Execution in the backup creation functionalitycombodo · itop · CWE-74 | High8.6 | — | 0.5% | Nov 10, 2025 |
32Monitor | CVE-2019-10863Proof of concept | A command injection vulnerability exists in TeemIp versions before 2.4.0.combodo · teemip · CWE-94 | High7.2 | — | 13.4% | Apr 4, 2019 |
32Monitor | CVE-2019-19821No exploit | A post-authentication privilege escalation in the web application of Combodo iTop allows regular authenticated users to access information acombodo · itop · CWE-79 | High8.1 | — | 1.4% | Mar 16, 2020 |
32Monitor | CVE-2019-11215No exploit | In Combodo iTop 2.2.0 through 2.6.0, if the configuration file is writable, then execution of arbitrary code can be accomplished by calling combodo · itop · CWE-79 | High8.1 | — | 1.2% | Feb 14, 2020 |
32Monitor | CVE-2023-48709No exploit | iTop vulnerable to potential formula injection in Excel/CSV export filecombodo · itop · CWE-74 | High8.0 | — | 1.0% | Apr 15, 2024 |
32Monitor | CVE-2021-41245No exploit | Possible Cross-Site Request Forgery in Combodo iTopcombodo · itop · CWE-352 | High8.1 | — | 0.7% | Apr 5, 2022 |
31Monitor | CVE-2023-47489No exploit | CSV injection in export as csv in Combodo iTop v.3.1.0-2-11973 allows a local attacker to execute arbitrary code via a crafted script to thecombodo · itop | High7.8 | — | 0.4% | Nov 9, 2023 |
30Monitor | CVE-2018-10642No exploit | Command injection vulnerability in Combodo iTop 2.4.1 allows remote authenticated administrators to execute arbitrary commands by changing tcombodo · itop · CWE-94 | High7.2 | — | 7.4% | May 2, 2018 |
30Monitor | CVE-2021-32663No exploit | Unauthorized setup leads to SSRF in Combodo/iTopcombodo · itop · CWE-918 | High7.5 | — | 1.5% | Oct 19, 2021 |
30Monitor | CVE-2019-13967No exploit | iTop 2.2.0 through 2.6.0 allows remote attackers to cause a denial of service (application outage) via many requests to launch a compile opecombodo · itop | High7.5 | — | 1.3% | Feb 14, 2020 |
30Monitor | CVE-2020-12777No exploit | Combodo iTop - Broken Access Controlcombodo · itop · CWE-200 | High7.5 | — | 1.3% | Aug 9, 2020 |
30Monitor | CVE-2020-12780No exploit | Combodo iTop - Security Misconfigurationcombodo · itop · CWE-863 | High7.5 | — | 1.2% | Aug 9, 2020 |
30Monitor | CVE-2020-4079No exploit | Information disclosure vulnerability in iTopcombodo · itop · CWE-200 | High7.7 | — | 0.9% | Jan 12, 2021 |
- CVE-2022-3921639Monitor
Combodo iTop's weak password reset token leads to account takeover
CriticalCVSS 9.8No exploitEPSS 1%combodo · itopMar 14, 2023
- CVE-2023-4871039Monitor
iTop limit pages/exec.php script to PHP files
CriticalCVSS 9.8No exploitEPSS 1%combodo · itopApr 15, 2024
- CVE-2022-3921438Monitor
Authenticated users of Combodo iTop can take over any account
HighCVSS 7.5No exploitEPSS 26%combodo · itopMar 14, 2023
- CVE-2024-5413938Monitor
Combodo iTop vulnerable to XSS leading to CSRF breach on _table_id parameter
CriticalCVSS 9.6No exploitEPSS 0%combodo · itopDec 13, 2024
- CVE-2022-2478037Monitor
Code Injection in Combodo iTop
HighCVSS 8.8Proof of conceptEPSS 6%combodo · itopApr 5, 2022
- CVE-2021-2140635Monitor
Command Injection vulnerability in the Setup Wizard
HighCVSS 8.8No exploitEPSS 1%combodo · itopJul 21, 2021
- CVE-2024-5200235Monitor
Cross-Site Request Forgery (CSRF) in several iTop pages
HighCVSS 8.8Proof of conceptEPSS 1%combodo · itopNov 8, 2024
- CVE-2024-5174035Monitor
SSRF through arbitrary PHP class instantiation in the user portal in Combodo iTop
HighCVSS 8.8No exploitEPSS 1%combodo · itopNov 5, 2024
- CVE-2020-1278135Monitor
Combodo iTop contains a cross-site request forgery (CSRF) vulnerability, attackers can execute specific commands via malicious site request
HighCVSS 8.8No exploitEPSS 0%combodo · itopAug 9, 2020
- CVE-2021-3277635Monitor
No CSRF form token cleanup on Windows servers
HighCVSS 8.8No exploitEPSS 0%combodo · itopJul 21, 2021
- CVE-2024-3199835Monitor
CSRF security issue on CSV import in Combodo iTop
HighCVSS 8.8No exploitEPSS 0%combodo · itopNov 4, 2024
- CVE-2025-2402234Monitor
iTop server vulnerable to portal code injection
HighCVSS 8.5No exploitEPSS 1%combodo · itopMay 14, 2025
- CVE-2025-4728634Monitor
Combodo iTop vulnerable to Remote Code Execution in the backup creation functionality
HighCVSS 8.6No exploitEPSS 0%combodo · itopNov 10, 2025
- CVE-2019-1086332Monitor
A command injection vulnerability exists in TeemIp versions before 2.4.0.
HighCVSS 7.2Proof of conceptEPSS 13%combodo · teemipApr 4, 2019
- CVE-2019-1982132Monitor
A post-authentication privilege escalation in the web application of Combodo iTop allows regular authenticated users to access information a
HighCVSS 8.1No exploitEPSS 1%combodo · itopMar 16, 2020
- CVE-2019-1121532Monitor
In Combodo iTop 2.2.0 through 2.6.0, if the configuration file is writable, then execution of arbitrary code can be accomplished by calling
HighCVSS 8.1No exploitEPSS 1%combodo · itopFeb 14, 2020
- CVE-2023-4870932Monitor
iTop vulnerable to potential formula injection in Excel/CSV export file
HighCVSS 8.0No exploitEPSS 1%combodo · itopApr 15, 2024
- CVE-2021-4124532Monitor
Possible Cross-Site Request Forgery in Combodo iTop
HighCVSS 8.1No exploitEPSS 1%combodo · itopApr 5, 2022
- CVE-2023-4748931Monitor
CSV injection in export as csv in Combodo iTop v.3.1.0-2-11973 allows a local attacker to execute arbitrary code via a crafted script to the
HighCVSS 7.8No exploitEPSS 0%combodo · itopNov 9, 2023
- CVE-2018-1064230Monitor
Command injection vulnerability in Combodo iTop 2.4.1 allows remote authenticated administrators to execute arbitrary commands by changing t
HighCVSS 7.2No exploitEPSS 7%combodo · itopMay 2, 2018
- CVE-2021-3266330Monitor
Unauthorized setup leads to SSRF in Combodo/iTop
HighCVSS 7.5No exploitEPSS 1%combodo · itopOct 19, 2021
- CVE-2019-1396730Monitor
iTop 2.2.0 through 2.6.0 allows remote attackers to cause a denial of service (application outage) via many requests to launch a compile ope
HighCVSS 7.5No exploitEPSS 1%combodo · itopFeb 14, 2020
- CVE-2020-1277730Monitor
Combodo iTop - Broken Access Control
HighCVSS 7.5No exploitEPSS 1%combodo · itopAug 9, 2020
- CVE-2020-1278030Monitor
Combodo iTop - Security Misconfiguration
HighCVSS 7.5No exploitEPSS 1%combodo · itopAug 9, 2020
- CVE-2020-407930Monitor
Information disclosure vulnerability in iTop
HighCVSS 7.7No exploitEPSS 1%combodo · itopJan 12, 2021