Combodo maintains a narrowly focused portfolio centered on IT operations management and IP address management platforms, notably iTop and TeeMIP, that serve as critical infrastructure for enterprise IT teams and network administration. Despite the small product count, these platforms are deeply embedded in large-scale IT environments and enjoy prominence among organizations managing complex IT service delivery and network governance. The vendor's vulnerability profile clusters around web-application input handling and access control, with recurring exposures in cross-site scripting, cross-site request forgery, sensitive information disclosure, and authorization bypass—patterns typical of complex, user-facing administrative interfaces that handle both privileged operations and sensitive configuration data. A moderate share of disclosures acquire public exploit availability, reflecting the appeal of these administrative platforms as targets. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Combodo over time
Signals from CVEs in this vendor scope (82 CVEs).
82 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-10863HIGH A command injection vulnerability exists in TeemIp versions before 2.4.0. The new_config parameter of exec.php allows one to create a new PHP file with the exception of config info | Apr 4, 2019 | 7.2 | 40 | NO | YES |
CVE-2022-39214HIGH Combodo iTop is an open source, web-based IT service management platform. Prior to versions 2.7.8 and 3.0.2-1, a user who can log in on iTop is able to take over any account just b | Mar 14, 2023 | 7.5 | 37 | NO | NO |
CVE-2022-24780HIGH Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.6 and 3.0.0, users of the iTop user portal can send TWIG code to the server by forging specific htt | Apr 5, 2022 | 8.8 | 30 | NO | NO |
CVE-2015-6544MEDIUM Cross-site scripting (XSS) vulnerability in application/dashboard.class.inc.php in Combodo iTop before 2.2.0-2459 allows remote attackers to inject arbitrary web script or HTML via | Feb 20, 2018 | 6.1 | 30 | NO | YES |
CVE-2024-32870MEDIUM Combodo iTop is a simple, web based IT Service Management tool. Server, OS, DBMS, PHP, and iTop info (name, version and parameters) can be read by anyone having access to iTop URI. | Nov 5, 2024 | 5.8 | 28 | NO | YES |
CVE-2022-39216CRITICAL Combodo iTop is an open source, web-based IT service management platform. Prior to versions 2.7.8 and 3.0.2-1, the reset password token is generated without any randomness paramete | Mar 14, 2023 | 9.8 | 28 | NO | NO |
CVE-2020-12781HIGH Combodo iTop contains a cross-site request forgery (CSRF) vulnerability, attackers can execute specific commands via malicious site request forgery. | Aug 10, 2020 | 8.8 | 28 | NO | NO |
CVE-2021-32776HIGH Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.4, CSRF tokens can be reused by a malicious user, as on Windows servers no cleanup is done on CSRF | Jul 21, 2021 | 8.8 | 27 | NO | NO |
CVE-2024-54139CRITICAL Combodo iTop is an open source and web-based IT service management platform. Prior to versions 2.7.11, 3.1.2, and 3.2.0., iTop has a cross-site scripting vulnerability that can lea | Dec 13, 2024 | 9.6 | 26 | NO | NO |
CVE-2023-48710CRITICAL iTop is an IT service management platform. Files from the `env-production` folder can be retrieved even though they should have restricted access. Hopefully, there is no sensitiv | Apr 15, 2024 | 9.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (82 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Combodo.
Media articles that mention a CVE ID that affects a product developed by Combodo — matched by CVE ID, not by vendor name.