Itop
This hub aggregates every CVE we track for Itop, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.
101
CVEs tracked
4
Critical
54
High
0
In CISA KEV
Severity distribution
HIGH54MEDIUM41CRITICAL4LOW2
Monthly trend
0
0
14
1
0
1
0
0
7
0
0
0
0
0
8
0
0
0
0
0
0
0
0
20
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Itop.
- CVE-2026-40877Combodo iTop: PHP Object Injection Leading to Remote Code Execution on user preferences8.7
- CVE-2026-30864Combodo iTop: Reflected XSS in dashboard revert8.9
- CVE-2026-34949Combodo iTop: Unauthenticated user can delete .readonly file6.5
- CVE-2026-34948Combodo iTop: Access control bypass via OQL joins7.7
- CVE-2026-34836Combodo iTop: Improper access control in ajax.render.php and ajax.document.php6.5
- CVE-2026-34741Combodo iTop: Authentication bypass in exec.php allows PHP file execution8.6
- CVE-2026-33333Combodo iTop: Information disclosure in ajax.render.php3.5
- CVE-2026-33240Combodo iTop: Reflected XSS in foreign key search criteria8.8
- CVE-2026-33047Combodo iTop: Object can be locked by a user without write permissions4.3
- CVE-2026-31936Combodo iTop: Unauthorized access to object information via search operation8.8
- CVE-2026-31880Combodo iTop: Reflected XSS in universal search8.0
- CVE-2026-31803Combodo iTop: Reflected XSS in tag admin8.0
- CVE-2026-30890Combodo iTop: Reflected XSS in synchro/synchro_import.php8.0
- CVE-2026-30865Combodo iTop: Reflected XSS in dashboard save7.1
- CVE-2026-30826Combodo iTop: Reflected XSS in run_query.php8.0
Product normalization is registry-driven with AI assist and human review. How it works