I-Doit is an IT asset and configuration management platform that maintains a focused product footprint centered on its core discovery and inventory software, which serves as a critical repository for infrastructure documentation across many organizations. The vendor's vulnerability disclosures, while modest in volume, span its widely deployed asset-management application; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by I Doit over time
Signals from CVEs in this vendor scope (19 CVEs).
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-20159HIGH i-doit open 1.11.2 allows Remote Code Execution because ZIP archives are mishandled. It has an upload feature that allows an authenticated user with the administrator role to uploa | Dec 15, 2018 | 7.2 | 38 | NO | YES |
CVE-2014-1597HIGH SQL injection vulnerability in the CMDB web application in synetics i-doit pro before 1.2.5 and i-doit open allows remote attackers to execute arbitrary SQL commands via the objID | Feb 27, 2014 | 7.5 | 34 | NO | YES |
CVE-2023-37756CRITICAL I-doit pro 25 and below and I-doit open 25 and below employ weak password requirements for Administrator account creation. Attackers are able to easily guess users' passwords via a | Sep 14, 2023 | 9.8 | 28 | NO | NO |
CVE-2019-1010248CRITICAL Synetics GmbH I-doit 1.12 and earlier is affected by: SQL Injection. The impact is: Unauthenticated mysql database access. The component is: Web login form. The attack vector is: A | Jul 18, 2019 | 9.8 | 28 | NO | NO |
CVE-2019-25581HIGH i-doit CMDB 1.12 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the objGroupID p | Mar 21, 2026 | 8.2 | 27 | NO | NO |
CVE-2023-37755CRITICAL i-doit pro 25 and below and I-doit open 25 and below are configured with insecure default administrator credentials, and there is no warning or prompt to ask users to change the de | Sep 14, 2023 | 9.8 | 26 | NO | NO |
CVE-2019-6965MEDIUM An XSS issue was discovered in i-doit Open 1.12 via the src/tools/php/qr/qr.php url parameter. | Jun 18, 2019 | 6.1 | 25 | NO | YES |
CVE-2024-8749HIGH SQL injection vulnerability in idoit pro version 28. This vulnerability could allow an attacker to send a specially crafted query to the ID parameter in /var/www/html/src/classes/m | Sep 12, 2024 | 7.5 | 23 | NO | NO |
CVE-2019-25582MEDIUM i-doit CMDB 1.12 contains an arbitrary file download vulnerability that allows authenticated attackers to download sensitive files by manipulating the file parameter in index.php. | Mar 21, 2026 | 6.5 | 22 | NO | NO |
CVE-2020-13826HIGH A CSV injection (aka Excel Macro Injection or Formula Injection) issue in i-doit 1.14.2 allows an attacker to execute arbitrary commands via a Title parameter that is mishandled in | Aug 20, 2020 | 8.8 | 22 | NO | NO |
Signals from CVEs in this vendor scope (19 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by I Doit.
Media articles that mention a CVE ID that affects a product developed by I Doit — matched by CVE ID, not by vendor name.