PatchSiren

Combodo CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Combodo CVE published 2026-08-21

CVE-2026-31880

Combodo iTop, a web-based IT service management tool, has a Reflected Cross-Site Scripting (XSS) vulnerability in its universal search functionality prior to version 3.2.3. This vulnerability, classified as HIGH with a CVSS score of 8, allows attackers to inject malicious JavaScript code, potentially leading to unauthorized actions or data exposure. Organizations using Combodo iTop versions prior to 3.2.3 [truncated]

HIGH Combodo CVE published 2026-08-21

CVE-2026-31803

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-21T21:16:57.250Z and has not been modified since then. Combodo iTop, a web-based IT service management tool, has a Reflected Cross-Site Scripting (XSS) vulnerability in pages/tagadmin.php prior to version 3.2.3. This type of vulnerability allows an attacker to inject malicious scripts into the appli [truncated]

HIGH Combodo CVE published 2026-08-21

CVE-2026-30826

CVE-2026-30826 is a Reflected Cross-Site Scripting (XSS) vulnerability in Combodo iTop prior to version 3.2.3. The vulnerability is related to the testing OQL query functionality. This type of vulnerability allows an attacker to inject malicious scripts into the application, potentially leading to unauthorized actions or data breaches. Affected deployments likely involve web-based IT service management sy [truncated]

HIGH Combodo CVE published 2026-08-21

CVE-2026-27462

Combodo iTop, a web-based IT service management tool, is affected by a user enumeration vulnerability. This issue, identified as CVE-2026-27462, exists in versions prior to 3.2.3. The vulnerability arises from the reset password mechanism, which returns different responses for valid and invalid usernames, allowing attackers to enumerate users. The CVE record was published on 2026-08-21T20:16:33.870Z and h [truncated]