VulnSea

combodo has 9 CVEs on record between 2025 and 2026. 2 were published in the last 90 days. The busiest recent month was November 2025 with 7. The median CVSS is 8.5 (high). None have a confirmed exploitation report. The most common weakness class is CWE-79 (4).

CVEs per month

Last 12 months, by publish date

111201020304050607080910
Exploited share
0% vs 1% corpus
Median CVSS
8.5
Publish → KEV
—
Last 90 days
2 prev 0

Products

  • iTop 9
9
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

combodo vulnerabilities

CVEs affecting combodo, newest first. Open any entry for full detail, references, and exploit status.

9 CVEsRSS

CVE-2026-33333Low· 3.5
1mo ago

Combodo iTop is a web based IT service management tool

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is sensitive information disclosure in the error messages. This issue has been fixed in version 3.2.3.

▾ SunlitCombodo · iTopEPSS 0.28%via NVD
CVE-2026-30866High· 7.5
1mo ago

Combodo iTop is a web based IT service management tool

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, unauthenticated users can access uploaded sensitive via sniffed url. This issue has been fixed in version 3.2.3.

▾ TwilightCombodo · iTopEPSS 0.46%via NVD
CVE-2025-49145High· 8.7
11mo ago

Combodo iTop is a web based IT service management tool

Combodo iTop is a web based IT service management tool. In versions prior to 2.7.13 and 3.2.2, a user that has enough rights to create webhooks (mostly administrators) can drop the database. This is fixed in iTop 2.7.13 and 3.2.2 by veri…

▾ Twilightcombodo · itopEPSS 0.30%via NVD
CVE-2025-48878Medium· 4.3
11mo ago

Combodo iTop is a web based IT service management tool

Combodo iTop is a web based IT service management tool. In versions on the 3.x branch prior to 3.2.2, an insecure direct object reference allows a user (e.g. with Service desk agent profile) to create a ModuleInstallation object when the…

▾ Sunlitcombodo · itopEPSS 0.20%via NVD
CVE-2025-48065High· 8.8
11mo ago

Combodo iTop is a web based IT service management tool

Combodo iTop is a web based IT service management tool. Versions prior to 2.7.13 and 3.2.2 are vulnerable to cross-site scripting when a field with an error contains malicious content. Versions 2.7.13 and 3.2.2 protect rendered HTML cont…

▾ Twilightcombodo · itopEPSS 0.22%via NVD
CVE-2025-48055High· 8.5
11mo ago

Combodo iTop is a web based IT service management tool

Combodo iTop is a web based IT service management tool. In versions prior to 3.2.2, when displaying content in a browse brick in the user portal, a cross-site scripting attack can occur. This is fixed in versions 3.2.2 and 3.3.0.

▾ Twilightcombodo · itopEPSS 0.18%via NVD
CVE-2025-47932High· 8.8
11mo ago

Combodo iTop is a web based IT service management tool

Combodo iTop is a web based IT service management tool. Versions prior to 2.7.13 and 3.2.2 are vulnerable to cross-site scripting when a dashboard is rendered via an AJAX call. Versions 2.7.13 and 3.2.2 sanitize the var responsible for …

▾ Twilightcombodo · itopEPSS 0.22%via NVD
CVE-2025-47773High· 8.8
11mo ago

Combodo iTop is a web based IT service management tool

Combodo iTop is a web based IT service management tool. Versions prior to 2.7.13 and 3.2.2 are vulnerable to cross-site scripting when a dashboard is edited via an AJAX call. Versions 2.7.13 and 3.2.2 protect rendered HTML content.

▾ Twilightcombodo · itopEPSS 0.22%via NVD
CVE-2025-47286High· 7.2
11mo ago

Combodo iTop is a web based IT service management tool

Combodo iTop is a web based IT service management tool. In versions prior to 2.7.13 and 3.2.2, an administrator can, by editing the configuration of the iTop instance, execute code on the server. Versions 2.7.13 and 3.2.2 escape and chec…

▾ Twilightcombodo · itopEPSS 0.47%via NVD
combodo vulnerabilities (CVEs) · VulnSea