In Combodo iTop a menu shortcut name can be exploited with a stored XSS payload. This is fixed in all iTop packages (community, essential, professional) in version 2.7.0 and iTop essential and iTop professional in version 2.6.4.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-11696.json"