#combodo
Combodo iTop carries 39 CVEs, 22 high severity, max CVSS 8.8, and 100 percent remain unpatched. Trust score D. #cybersecurity #infosec #iTop https://www.valtersit.com/vendors/combodo/
Combodo
www.valtersit.com
September 30, 2026 at 3:30 AM
Combodo intègre l'IA dans iTop 3.3, apportant une nouvelle approche à l'ITSM et renforçant la sécurité des systèmes informatiques.
➡️ https://l.iatechauquotidien.com/IiC
September 26, 2026 at 11:23 AM
Conteneurs, flux et passerelles pour LLM : iTop 3.3 prépare l’ITSM libre aux futurs agents d’IA

Préparer la gestion de parc informatique aux modèles de langage : Combodo publie la version 3.3 de sa solution ITSM open source iTop...

https://goodtech.info/itop-3-3-combodo-itsm-open-source-cmdb-ia/
Conteneurs, flux et passerelles pour LLM : iTop 3.3 prépare l’ITSM libre aux futurs agents d’IA
Préparer la gestion de parc informatique aux modèles de langage : Combodo publie la version 3.3 de sa solution ITSM open source iTop sous licence AGPL-3.0 ! Au menu : cartographie des conteneurs et socle prêt pour l'IA.
goodtech.info
September 22, 2026 at 4:54 AM
CVE-2026-39975
The web‑based IT service tool Combodo iTop, versions before 3.2.3, let anyone on the internet delete a safety file and then run their own programs on the server. This could give an attacker full control of the…

Too many irrelevant or confusing CVEs? Use stackflag.com

#CVE #infosec
August 25, 2026 at 6:00 AM
🚨 CVE-2026-39975 — CVSS 9.4 CRITICAL

Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, unauthenticated users could delete ...

🔎 https://stemshop.top/cve/CVE-2026-39975

#CVE #CyberSecurity #InfoSec
August 24, 2026 at 8:08 PM
CVE-2026-39975 - itop
Versions of Combodo iTop before 3.2.3 let anyone on the internet delete a protection file and then execute their own code on the server. This could let an attacker take control of the…

Too many irrelevant or confusing CVEs? Use stackflag.com

#itop #combodo #CVE #infosec
CVE-2026-39975: Combodo iTop allows attackers to run code remotely
Versions of Combodo iTop before 3.2.3 let anyone on the internet delete a protection file and then execute their own code on the server.
stackflag.com
August 24, 2026 at 7:40 PM
🟠 CVE-2026-30826 - High (8)

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cros...

https://www.thehackerwire.com/vulnerability/CVE-2026-30826/

#infosec #cybersecurity #CVE #vulnerability #security #patchstack
August 22, 2026 at 7:03 AM
🟠 CVE-2026-31880 - High (8)

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cros...

https://www.thehackerwire.com/vulnerability/CVE-2026-31880/

#infosec #cybersecurity #CVE #vulnerability #security #patchstack
August 22, 2026 at 7:03 AM
🟠 CVE-2026-31803 - High (8)

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, 3.2.3, there is a Reflect...

https://www.thehackerwire.com/vulnerability/CVE-2026-31803/

#infosec #cybersecurity #CVE #vulnerability #security #patchstack
August 22, 2026 at 3:02 AM
🟠 CVE-2026-30890 - High (8)

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cros...

https://www.thehackerwire.com/vulnerability/CVE-2026-30890/

#infosec #cybersecurity #CVE #vulnerability #security #patchstack
August 22, 2026 at 3:02 AM
Combodo iTop 3.2.3未満の、検索APIにReflected XSS脆弱性。攻撃者は悪意あるコードを実行させる可能性がある。
CVE-2026-33240 CVSS 8.8 | HIGH
NVD - CVE-2026-33240
nvd.nist.gov
August 22, 2026 at 1:42 AM
Combodo iTop 3.2.3未満では、検索操作で権限のないオブジェクト情報にアクセスされる可能性がありました。この脆弱性は3.2.3で修正されています。
CVE-2026-31936 CVSS 8.8 | HIGH
NVD - CVE-2026-31936
nvd.nist.gov
August 22, 2026 at 1:42 AM
One Inline Image Bug, One More Ancient Ritual of Corporate Self-Destruction
PANIC 54% | Lag 0.0h | Combodo iTop versions before 3.2.3 contain a vulnerability in inline image handling that could allow
#AfterShockIndex
READ MORE
August 22, 2026 at 12:41 AM
🟠 CVE-2026-34948 - High (7.7)

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, only classes present in t...

https://www.thehackerwire.com/vulnerability/CVE-2026-34948/

#infosec #cybersecurity #CVE #vulnerability #security #patchstack
August 22, 2026 at 12:00 AM
CVE-2026-34741 - Combodo iTop: Authentication bypass in exec.php allows PHP file execution
CVE ID : CVE-2026-34741

Published : Aug. 21, 2026, 10:16 p.m. | 17 minutes ago

Description : Combodo iTop is a web based IT service management tool. Prior to 3.2.3, authentication ...
CVE-2026-34741 - Combodo iTop: Authentication bypass in exec.php allows PHP file execution
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, authentication bypass allows unauthenticated remote attackers to execute arbitrary PHP files from the env-production directory on a new iTop instance in the production environment. This issue has been fixed in version 3.2.3.
cvefeed.io
August 21, 2026 at 11:56 PM
🟠 CVE-2026-33240 - High (8.8)

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there was a Reflected Cro...

https://www.thehackerwire.com/vulnerability/CVE-2026-33240/

#infosec #cybersecurity #CVE #vulnerability #security #patchstack
August 21, 2026 at 11:01 PM
🟠 CVE-2026-31936 - High (8.8)

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, users can access to unaut...

https://www.thehackerwire.com/vulnerability/CVE-2026-31936/

#infosec #cybersecurity #CVE #vulnerability #security #patchstack
August 21, 2026 at 11:01 PM
🟠 CVE-2026-34741 - High (8.6)

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, authentication bypass all...

https://www.thehackerwire.com/vulnerability/CVE-2026-34741/

#infosec #cybersecurity #CVE #vulnerability #security #patchstack
August 21, 2026 at 11:01 PM
🟠 CVE-2026-27462 - High (7.5)

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop returns different re...

https://www.thehackerwire.com/vulnerability/CVE-2026-27462/

#infosec #cybersecurity #CVE #vulnerability #security #patchstack
August 21, 2026 at 9:01 PM
🟠 CVE-2026-30866 - High (7.5)

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, unauthenticated users can...

https://www.thehackerwire.com/vulnerability/CVE-2026-30866/

#infosec #cybersecurity #CVE #vulnerability #security #patchstack
August 21, 2026 at 9:00 PM
🟠 CVE-2026-27490 - High (7.5)

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, inline images that are ac...

https://www.thehackerwire.com/vulnerability/CVE-2026-27490/

#infosec #cybersecurity #CVE #vulnerability #security #patchstack
August 21, 2026 at 9:00 PM
Combodo: 33 CVEs, 0 exploited in wild, but 100% unpatched. Avg CVSS 6.7, top weakness XSS (CWE-79). Trust Score: D. Open source ITSM needs urgent updates. #Combodo #iTop #cybersecurity

https://www.valtersit.com/vendors/combodo/
July 8, 2026 at 12:03 AM
📌 CVE-2023-34445 - Combodo iTop is a simple, web based IT Service Management tool. When displaying pages/ajax.render.php XSS are possible for scripts outside of script t... https://www.potatohub.blog/cves/CVE-2023-34445
July 5, 2026 at 2:37 AM
📌 CVE-2023-34445 - Combodo iTop is a simple, web based IT Service Management tool. When displaying pages/ajax.render.php XSS are possible for scripts outside of script t... https://www.cyberhub.blog/cves/CVE-2023-34445
CVE-2023-34445
Combodo iTop is a simple, web based IT Service Management tool. When displaying pages/ajax.render.php XSS are possible for scripts outside of script tags. This issue has been fixed in versions 2.7.9, 3.0.4, 3.1.0. All users are advised to upgrade. There are no known workarounds for this vulnerabilit
www.cyberhub.blog
July 5, 2026 at 2:37 AM
📌 CVE-2023-34444 - Combodo iTop is a simple, web based IT Service Management tool. When displaying pages/ajax.searchform.php XSS are possible for scripts outside of scri... https://www.cyberhub.blog/cves/CVE-2023-34444
CVE-2023-34444
Combodo iTop is a simple, web based IT Service Management tool. When displaying pages/ajax.searchform.php XSS are possible for scripts outside of script tags. This issue has been fixed in versions 2.7.9, 3.0.4, 3.1.0. All users are advised to upgrade. There are no known workarounds for this vulnerab
www.cyberhub.blog
July 5, 2026 at 2:07 AM