Combodo
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Combodo product.
RSS Feeds for Combodo security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Combodo products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Combodo Sorted by Most Security Vulnerabilities since 2018
By the Year
In 2026 there have been 0 vulnerabilities in Combodo. Last year, in 2025 Combodo had 16 security vulnerabilities published. Right now, Combodo is on track to have less security vulnerabilities in 2026 than it did last year.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 0 | 0.00 |
| 2025 | 16 | 7.67 |
| 2024 | 25 | 6.51 |
| 2023 | 6 | 7.12 |
| 2022 | 8 | 6.51 |
| 2021 | 11 | 6.65 |
| 2020 | 12 | 7.17 |
| 2019 | 1 | 7.20 |
| 2018 | 1 | 0.00 |
It may take a day or so for new Combodo vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Combodo Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2025-64167 | Nov 10, 2025 |
Combodo iTop XSS via export.php (pre-2.7.13 & pre-3.2.2)Combodo iTop is a web based IT service management tool. Versions prior to 2.7.13 and 3.2.2 are vulnerable to a cross-site scripting attack (leading to JS execution) when editing the URL parameter. Versions 2.7.13 and 3.2.2 don't use export.php, which was deprecated. They use export-v2.php instead. |
|
| CVE-2025-49145 | Nov 10, 2025 |
Combodo iTop <2.7.13/3.2.2: Webhook Enables DB DropCombodo iTop is a web based IT service management tool. In versions prior to 2.7.13 and 3.2.2, a user that has enough rights to create webhooks (mostly administrators) can drop the database. This is fixed in iTop 2.7.13 and 3.2.2 by verifying callback signature. |
|
| CVE-2025-48878 | Nov 10, 2025 |
iTop 3.x IDOR: ModuleInstallation creation allowed fixed in 3.2.2Combodo iTop is a web based IT service management tool. In versions on the 3.x branch prior to 3.2.2, an insecure direct object reference allows a user (e.g. with Service desk agent profile) to create a ModuleInstallation object when they shouldn't be able to do so. Version 3.2.2 fixes the issue. |
|
| CVE-2025-48065 | Nov 10, 2025 |
CVE-2025-48065 Combodo iTop 2.x/3.x XSS in error msg before 2.7.13/3.2.2Combodo iTop is a web based IT service management tool. Versions prior to 2.7.13 and 3.2.2 are vulnerable to cross-site scripting when a field with an error contains malicious content. Versions 2.7.13 and 3.2.2 protect rendered HTML content. |
|
| CVE-2025-48055 | Nov 10, 2025 |
Combodo iTop 3.2.x XSS in User Portal Browse BrickCombodo iTop is a web based IT service management tool. In versions prior to 3.2.2, when displaying content in a browse brick in the user portal, a cross-site scripting attack can occur. This is fixed in versions 3.2.2 and 3.3.0. |
|
| CVE-2025-47932 | Nov 10, 2025 |
XSS in Combodo iTop <2.7.13, <3.2.2 via AJAX DashboardCombodo iTop is a web based IT service management tool. Versions prior to 2.7.13 and 3.2.2 are vulnerable to cross-site scripting when a dashboard is rendered via an AJAX call. Versions 2.7.13 and 3.2.2 sanitize the var responsible for the attack. |
|
| CVE-2025-47773 | Nov 10, 2025 |
Combodo iTop XSS via AJAX Dashboard Edit (<2.7.13, <3.2.2)Combodo iTop is a web based IT service management tool. Versions prior to 2.7.13 and 3.2.2 are vulnerable to cross-site scripting when a dashboard is edited via an AJAX call. Versions 2.7.13 and 3.2.2 protect rendered HTML content. |
|
| CVE-2025-47286 | Nov 10, 2025 |
Code Exec via Config in Combodo iTop <2.7.13/3.2.2Combodo iTop is a web based IT service management tool. In versions prior to 2.7.13 and 3.2.2, an administrator can, by editing the configuration of the iTop instance, execute code on the server. Versions 2.7.13 and 3.2.2 escape and check the config parameter before executing a command based on it. |
|
| CVE-2025-24969 | May 14, 2025 |
iTop <3.2.1: URL Picture ID DisclosureiTop is an web based IT Service Management tool. Prior to version 3.2.1, a portal user can see any other contacts picture by changing the picture ID in the URL. Version 3.2.1 contains a patch for the issue. |
|
| CVE-2025-24785 | May 14, 2025 |
iTop 3.2.0 Dashboard PHP Error Crash via Malformed layout_classiTop is an web based IT Service Management tool. In version 3.2.0, an attacker may send a URL to the server to trigger a PHP error. The next user trying to load this dashboard would encounter a crashed start page. Version 3.2.1 fixes the issue by checking the provided layout_class before saving the dashboard. |
|