CVE-2026-33240
- EPSS 0.27%
- Veröffentlicht 21.08.2026 22:16:36
- Zuletzt bearbeitet 09.09.2026 21:06:39
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there was a Reflected Cross-Site Scripting (XSS) vulnerability in the foreign key search criteria API. This issue has been fixed in version 3.2.3.
- EPSS 0.23%
- Veröffentlicht 21.08.2026 21:16:57
- Zuletzt bearbeitet 09.09.2026 21:20:38
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the synchro import script. This issue has been fixed in version 3.2.3.
- EPSS 0.23%
- Veröffentlicht 21.08.2026 21:16:57
- Zuletzt bearbeitet 09.09.2026 21:20:38
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in pages/tagadmin.php. This issue has been fixed in version 3.2.3.
- EPSS 0.23%
- Veröffentlicht 21.08.2026 21:16:57
- Zuletzt bearbeitet 09.09.2026 21:20:38
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the universal search. This issue has been fixed in version 3.2.3.
- EPSS 0.23%
- Veröffentlicht 21.08.2026 21:16:56
- Zuletzt bearbeitet 09.09.2026 21:20:38
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the testing OQL query functionality. This issue has been fixed in version 3.2.3.
CVE-2026-30865
- EPSS 0.19%
- Veröffentlicht 21.08.2026 21:16:56
- Zuletzt bearbeitet 09.09.2026 21:20:38
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the dashboard save functionality. This issue has been fixed in version 3.2.3.
CVE-2026-27463
- EPSS 0.25%
- Veröffentlicht 21.08.2026 20:16:34
- Zuletzt bearbeitet 09.09.2026 21:20:38
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, the HTML title attribute of the logo in the login page contains the complete iTop version. This issue has been fixed in version 3.2.3.
CVE-2026-27490
- EPSS 0.31%
- Veröffentlicht 21.08.2026 20:16:34
- Zuletzt bearbeitet 09.09.2026 21:20:38
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, inline images that are accessible without being authenticated are protected by a weak 24-bit pseudo-random secret. This issue has been fixed in version 3.2.3.
CVE-2026-30819
- EPSS 0.26%
- Veröffentlicht 21.08.2026 20:16:34
- Zuletzt bearbeitet 09.09.2026 21:20:38
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop has a reflected Cross-Site Scripting (XSS) vulnerability in its dashboard revert functionality with the parameter dashboard_id in /pages/ajax.render.php. This issue has been...
CVE-2026-30866
- EPSS 0.27%
- Veröffentlicht 21.08.2026 20:16:34
- Zuletzt bearbeitet 09.09.2026 21:20:38
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, unauthenticated users can access uploaded sensitive via sniffed url. This issue has been fixed in version 3.2.3.