Itop
Vendor:
First CVE: Nov 26, 2011 · Active for 14 years
81
Total CVEs
More Total CVEs than 99% of tracked products
9.0
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 28% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Itop over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 26, 2011
14 years ago
Most Recent CVE
Nov 10, 2025
256 days ago
CVE Severity & Scoring
Itop81 CVEs
68%
27%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local2 (2.5%)
Network77 (95.1%)
Unknown2 (2.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low74 (91.4%)
High5 (6.2%)
Unknown2 (2.5%)
User Interaction
None31 (38.3%)
Unknown2 (2.5%)
Required48 (59.3%)
Privileges Required
Low32 (39.5%)
High5 (6.2%)
None42 (51.9%)
Unknown2 (2.5%)
Top CVEs
Signals from CVEs in this product scope (81 CVEs).
81 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-39214HIGH Combodo iTop is an open source, web-based IT service management platform. Prior to versions 2.7.8 and 3.0.2-1, a user who can log in on iTop is able to take over any account just b | Mar 14, 2023 | 7.5 | 37 | NO | NO |
CVE-2022-24780HIGH Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.6 and 3.0.0, users of the iTop user portal can send TWIG code to the server by forging specific htt | Apr 5, 2022 | 8.8 | 30 | NO | NO |
CVE-2015-6544MEDIUM Cross-site scripting (XSS) vulnerability in application/dashboard.class.inc.php in Combodo iTop before 2.2.0-2459 allows remote attackers to inject arbitrary web script or HTML via | Feb 20, 2018 | 6.1 | 30 | NO | YES |
CVE-2024-32870MEDIUM Combodo iTop is a simple, web based IT Service Management tool. Server, OS, DBMS, PHP, and iTop info (name, version and parameters) can be read by anyone having access to iTop URI. | Nov 5, 2024 | 5.8 | 28 | NO | YES |
CVE-2022-39216CRITICAL Combodo iTop is an open source, web-based IT service management platform. Prior to versions 2.7.8 and 3.0.2-1, the reset password token is generated without any randomness paramete | Mar 14, 2023 | 9.8 | 28 | NO | NO |
CVE-2020-12781HIGH Combodo iTop contains a cross-site request forgery (CSRF) vulnerability, attackers can execute specific commands via malicious site request forgery. | Aug 10, 2020 | 8.8 | 28 | NO | NO |
CVE-2021-32776HIGH Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.4, CSRF tokens can be reused by a malicious user, as on Windows servers no cleanup is done on CSRF | Jul 21, 2021 | 8.8 | 27 | NO | NO |
CVE-2024-54139CRITICAL Combodo iTop is an open source and web-based IT service management platform. Prior to versions 2.7.11, 3.1.2, and 3.2.0., iTop has a cross-site scripting vulnerability that can lea | Dec 13, 2024 | 9.6 | 26 | NO | NO |
CVE-2023-48710CRITICAL iTop is an IT service management platform. Files from the `env-production` folder can be retrieved even though they should have restricted access. Hopefully, there is no sensitiv | Apr 15, 2024 | 9.8 | 26 | NO | NO |
CVE-2021-41245HIGH Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.6 and 3.0.0, CSRF tokens generated by `privUITransactionFile` aren't properly checked. Versions 2.7 | Apr 5, 2022 | 8.1 | 26 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (81 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
3 CVEs
3.7% of CVEs· 97th percentile
ExploitDB
1 CVE
1.2% of CVEs· 87th percentile
Social Chatter
Signals from CVEs in this product scope (81 CVEs).
Media Mentions
Signals from CVEs in this product scope (81 CVEs).
Top CNAs Publishing CVEs For Itop
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.2.0 | 2 | 7.5 | 0.2% | 0 | 0 |
| 3.1.0-2-11973 | 2 | 7.0 | 0.9% | 0 | 0 |
| 3.0.3 | 1 | 6.1 | 0.5% | 0 | 0 |
| 3.0.1 | 2 | 6.1 | 1.9% | 0 | 0 |
| 3.0.0 | 13 | 7.3 | 1.5% | 0 | 0 |
| 2.7.5-1 | 1 | 8.8 | 1.0% | 0 | 0 |
| 2.7.5 | 1 | 8.8 | 1.0% | 0 | 0 |
| 2.7.3 | 1 | 7.7 | 0.9% | 0 | 0 |
| 2.7.0 | 1 | 5.4 | 0.6% | 0 | 0 |
| 2.0 | 1 | 4.3 | 1.7% | 0 | 0 |
| 1.2.1 | 1 | 4.3 | 1.7% | 0 | 0 |
| 1.2.0 | 2 | 4.3 | 1.6% | 0 | 1 |
| 1.2 | 1 | 4.3 | 1.7% | 0 | 0 |
| 1.1.181 | 2 | 4.3 | 1.6% | 0 | 1 |
| 1.1 | 1 | 4.3 | 1.7% | 0 | 0 |
| 1.0.2 | 1 | 4.3 | 1.7% | 0 | 0 |
| 1.0.1 | 1 | 4.3 | 1.7% | 0 | 0 |
| 1.0 | 1 | 4.3 | 1.7% | 0 | 0 |
| 0.9.1 | 1 | 4.3 | 1.7% | 0 | 0 |
| 0.9 | 1 | 4.3 | 1.7% | 0 | 0 |