Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Combodo

First CVE: Nov 26, 2011Active for: 15 yearsTotal CVEs: 82
35.9
VTI Score
Medium

Combodo maintains a narrowly focused portfolio centered on IT operations management and IP address management platforms, notably iTop and TeeMIP, that serve as critical infrastructure for enterprise IT teams and network administration. Despite the small product count, these platforms are deeply embedded in large-scale IT environments and enjoy prominence among organizations managing complex IT service delivery and network governance. The vendor's vulnerability profile clusters around web-application input handling and access control, with recurring exposures in cross-site scripting, cross-site request forgery, sensitive information disclosure, and authorization bypass—patterns typical of complex, user-facing administrative interfaces that handle both privileged operations and sensitive configuration data. A moderate share of disclosures acquire public exploit availability, reflecting the appeal of these administrative platforms as targets. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
82
Total CVEs
More Total CVEs than 99% of tracked vendors
4.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 97% of tracked vendors
6.5
Avg CVSS Score
Higher Avg CVSS Score than 39% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Combodo over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 26, 2011
14 years ago
Most Recent CVE
Nov 10, 2025
256 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (82 CVEs).

82 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-10863HIGH
A command injection vulnerability exists in TeemIp versions before 2.4.0. The new_config parameter of exec.php allows one to create a new PHP file with the exception of config info
Apr 4, 20197.240NOYES
CVE-2022-39214HIGH
Combodo iTop is an open source, web-based IT service management platform. Prior to versions 2.7.8 and 3.0.2-1, a user who can log in on iTop is able to take over any account just b
Mar 14, 20237.537NONO
CVE-2022-24780HIGH
Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.6 and 3.0.0, users of the iTop user portal can send TWIG code to the server by forging specific htt
Apr 5, 20228.830NONO
CVE-2015-6544MEDIUM
Cross-site scripting (XSS) vulnerability in application/dashboard.class.inc.php in Combodo iTop before 2.2.0-2459 allows remote attackers to inject arbitrary web script or HTML via
Feb 20, 20186.130NOYES
CVE-2024-32870MEDIUM
Combodo iTop is a simple, web based IT Service Management tool. Server, OS, DBMS, PHP, and iTop info (name, version and parameters) can be read by anyone having access to iTop URI.
Nov 5, 20245.828NOYES
CVE-2022-39216CRITICAL
Combodo iTop is an open source, web-based IT service management platform. Prior to versions 2.7.8 and 3.0.2-1, the reset password token is generated without any randomness paramete
Mar 14, 20239.828NONO
CVE-2020-12781HIGH
Combodo iTop contains a cross-site request forgery (CSRF) vulnerability, attackers can execute specific commands via malicious site request forgery.
Aug 10, 20208.828NONO
CVE-2021-32776HIGH
Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.4, CSRF tokens can be reused by a malicious user, as on Windows servers no cleanup is done on CSRF
Jul 21, 20218.827NONO
CVE-2024-54139CRITICAL
Combodo iTop is an open source and web-based IT service management platform. Prior to versions 2.7.11, 3.1.2, and 3.2.0., iTop has a cross-site scripting vulnerability that can lea
Dec 13, 20249.626NONO
CVE-2023-48710CRITICAL
iTop is an IT service management platform. Files from the `env-production` folder can be retrieved even though they should have restricted access. Hopefully, there is no sensitiv
Apr 15, 20249.826NONO
View all 82 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products82 CVEs
67%
28%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local2 (2.4%)
Network78 (95.1%)
Unknown2 (2.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low75 (91.5%)
High5 (6.1%)
Unknown2 (2.4%)
User Interaction
None32 (39.0%)
Unknown2 (2.4%)
Required48 (58.5%)
Privileges Required
Low32 (39.0%)
High6 (7.3%)
None42 (51.2%)
Unknown2 (2.4%)

Exploit Exposure

Signals from CVEs in this vendor scope (82 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
3 CVEs
3.7% of CVEs· 95th percentile
ExploitDB
2 CVEs
2.4% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Combodo.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Combodo — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Combodo's Products

View all 3 CNAs →

Top CWEs