← Vulnerability feed

Vulnerability record · CVE-2025-47286 · published 10 November 2025

CVE-2025-47286: Combodo itop injection vulnerability

Combodo · Itop

Combodo iTop is a web based IT service management tool. In versions prior to 2.7.13 and 3.2.2, an administrator can, by editing the configuration of the iTop instance, execute code on the server. Versions 2.7.13 and 3.2.2 escape and check the config parameter before executing a command based on it.

8.6 CVSS 4.0 High EPSS 0.47% · top 62.1% CWE-74 · Injection
8.6CVSS 4.0 base score
0.47%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

Combodo iTop is a web based IT service management tool. In versions prior to 2.7.13 and 3.2.2, an administrator can, by editing the configuration of the iTop instance, execute code on the server. Versions 2.7.13 and 3.2.2 escape and check the config parameter before executing a command based on it.

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-47286 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-48710Combodo itop vulnerabilityiTop is an IT service management platform. Files from the `env-production` folder can be retrieved even though they should have restricted access. Ho…EPSS 0.72%9.8CVE-2022-39216Combodo itop vulnerabilityCombodo iTop is an open source, web-based IT service management platform. Prior to versions 2.7.8 and 3.0.2-1, the reset password token is generated …EPSS 0.91%9.6CVE-2024-54139Combodo itop cross-site scripting vulnerabilityCombodo iTop is an open source and web-based IT service management platform. Prior to versions 2.7.11, 3.1.2, and 3.2.0., iTop has a cross-site scrip…EPSS 0.22%8.8CVE-2024-52002Combodo itop cross-site request forgery vulnerabilityCombodo iTop is a simple, web based IT Service Management tool. Several url endpoints are subject to a Cross-Site Request Forgery (CSRF) vulnerabilit…EPSS 0.66%8.8CVE-2024-51740Combodo itop server-side request forgery (ssrf) vulnerabilityCombodo iTop is a simple, web based IT Service Management tool. This vulnerability can be used to create HTTP requests on behalf of the server, from …EPSS 0.54%8.8CVE-2024-31998Combodo itop cross-site request forgery vulnerabilityCombodo iTop is a simple, web based IT Service Management tool. A CSRF can be performed on CSV import simulation. This issue has been fixed in versio…EPSS 0.24%8.8CVE-2022-24780Combodo itop code injection vulnerabilityCombodo iTop is a web based IT Service Management tool. In versions prior to 2.7.6 and 3.0.0, users of the iTop user portal can send TWIG code to the…EPSS 5.7%8.8CVE-2021-32776Combodo itop cross-site request forgery vulnerabilityCombodo iTop is a web based IT Service Management tool. In versions prior to 2.7.4, CSRF tokens can be reused by a malicious user, as on Windows serv…EPSS 0.38%

Source: NIST National Vulnerability Database (record CVE-2025-47286), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.