Filter

iTopiTop limit pages/exec.php script to PHP files

First published (updated )

iTopiTop vulnerable to potential formula injection in Excel/CSV export file

First published (updated )

iTopiTop vulnerable to XSS vulnerability in authent-token

8.8
First published (updated )

iTopiTop vulnerable to XSS vulnerability in dashlet refresh

8.8
First published (updated )

iTopiTop vulnerable to XSS vulnerability in n:n relations "tagset" widget

8.7
First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

iTopiTop missing silo check on extkey in console and portal

First published (updated )

iTopiTop vulnerable to XSS in dashlet modifications ajax endpoints

First published (updated )

iTopiTop vulnerable to XSS in friendlyname in object details

First published (updated )

iTopiTop Dashboard editor vulnerable dashboard config file parameter

First published (updated )

iTopReflected Cross-site Scripting exploit in Combodo iTop

8.1
First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

iTopPortal user is able to access forbidden services information in Combodo iTop

First published (updated )

iTopCross-Site Request Forgery (CSRF) in several iTop pages

8.8
First published (updated )

iTopCombodo iTop vulnerable to XSS leading to CSRF breach on _table_id parameter

7.9
First published (updated )

iTopXSS

First published (updated )

iTopCSV injection in export as csv in Combodo iTop v.3.1.0-2-11973 allows a local attacker to execute ar…

7.8
First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

iTopiTop hub connector Information disclosure

First published (updated )

iTopSSRF through arbitrary PHP class instantiation in the user portal in Combodo iTop

8.8
First published (updated )

iTopLogic bug in ajax.render.php allows for bypass of 'backOffice' access control in Combodo iTop

7.1
First published (updated )

iTopCross-site Scripting in portal picture upload in Combodo iTop

7.1
First published (updated )

iTopPassword is stored in clear in the database in Combodo iTop

3.4
First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

iTopUsers enumeration allowed through Rest API in Combodo iTop

7.5
First published (updated )

iTopCSRF security issue on CSV import in Combodo iTop

8.8
First published (updated )

iTopCross-site Scripting vulnerability in link CSV import in Combodo iTop

8.8
First published (updated )

iTopCross-site Scripting vulnerability on pages/ajax.render.php in Combodo iTop

8.8
First published (updated )

iTopCross-site Scripting vulnerability on pages/ajax.searchform.php in Combodo iTop

8.8
First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

iTopCross-site Scripting vulnerability in the run_query.php page in Combodo iTop

8.8
First published (updated )

iTopCombodo iTop - Broken Access Control

7.5
First published (updated )

iTopCombodo iTop - Reflected XSS

7.4
First published (updated )

iTopCombodo iTop - CSRF

8.8
First published (updated )

iTopCombodo iTop - Stored XSS

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203