iTop vulnerabilities
CVEs whose affected-version data names the iTop package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-33333Low· 3.5Combodo iTop is a web based IT service management tool
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is sensitive information disclosure in the error messages. This issue has been fixed in version 3.2.3.
▾ SunlitCombodo · iTopEPSS 0.20%via NVD
CVE-2026-30866High· 7.5Combodo iTop is a web based IT service management tool
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, unauthenticated users can access uploaded sensitive via sniffed url. This issue has been fixed in version 3.2.3.
▾ TwilightCombodo · iTopEPSS 0.27%via NVD