Itop

Vendor:

First CVE: Nov 26, 2011 · Active for 14 years

81
Total CVEs
More Total CVEs than 99% of tracked products
9.0
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 28% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Itop over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 26, 2011
14 years ago
Most Recent CVE
Nov 10, 2025
256 days ago

CVE Severity & Scoring

Itop81 CVEs
All CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local2 (2.5%)
Network77 (95.1%)
Unknown2 (2.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low74 (91.4%)
High5 (6.2%)
Unknown2 (2.5%)
User Interaction
None31 (38.3%)
Unknown2 (2.5%)
Required48 (59.3%)
Privileges Required
Low32 (39.5%)
High5 (6.2%)
None42 (51.9%)
Unknown2 (2.5%)

Top CVEs

Signals from CVEs in this product scope (81 CVEs).

81 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Combodo iTop is an open source, web-based IT service management platform. Prior to versions 2.7.8 and 3.0.2-1, a user who can log in on iTop is able to take over any account just b
Mar 14, 20237.537NONO
Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.6 and 3.0.0, users of the iTop user portal can send TWIG code to the server by forging specific htt
Apr 5, 20228.830NONO
Cross-site scripting (XSS) vulnerability in application/dashboard.class.inc.php in Combodo iTop before 2.2.0-2459 allows remote attackers to inject arbitrary web script or HTML via
Feb 20, 20186.130NOYES
Combodo iTop is a simple, web based IT Service Management tool. Server, OS, DBMS, PHP, and iTop info (name, version and parameters) can be read by anyone having access to iTop URI.
Nov 5, 20245.828NOYES
Combodo iTop is an open source, web-based IT service management platform. Prior to versions 2.7.8 and 3.0.2-1, the reset password token is generated without any randomness paramete
Mar 14, 20239.828NONO
Combodo iTop contains a cross-site request forgery (CSRF) vulnerability, attackers can execute specific commands via malicious site request forgery.
Aug 10, 20208.828NONO
Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.4, CSRF tokens can be reused by a malicious user, as on Windows servers no cleanup is done on CSRF
Jul 21, 20218.827NONO
Combodo iTop is an open source and web-based IT service management platform. Prior to versions 2.7.11, 3.1.2, and 3.2.0., iTop has a cross-site scripting vulnerability that can lea
Dec 13, 20249.626NONO
iTop is an IT service management platform. Files from the `env-production` folder can be retrieved even though they should have restricted access. Hopefully, there is no sensitiv
Apr 15, 20249.826NONO
Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.6 and 3.0.0, CSRF tokens generated by `privUITransactionFile` aren't properly checked. Versions 2.7
Apr 5, 20228.126NONO

Exploit Exposure

Signals from CVEs in this product scope (81 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
3 CVEs
3.7% of CVEs· 97th percentile
ExploitDB
1 CVE
1.2% of CVEs· 87th percentile

Social Chatter

Signals from CVEs in this product scope (81 CVEs).

Media Mentions

Signals from CVEs in this product scope (81 CVEs).

Top CNAs Publishing CVEs For Itop

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
3.2.027.50.2%00
3.1.0-2-1197327.00.9%00
3.0.316.10.5%00
3.0.126.11.9%00
3.0.0137.31.5%00
2.7.5-118.81.0%00
2.7.518.81.0%00
2.7.317.70.9%00
2.7.015.40.6%00
2.014.31.7%00
1.2.114.31.7%00
1.2.024.31.6%01
1.214.31.7%00
1.1.18124.31.6%01
1.114.31.7%00
1.0.214.31.7%00
1.0.114.31.7%00
1.014.31.7%00
0.9.114.31.7%00
0.914.31.7%00