CVE-2024-1297: Loomio
High severity, CVSS 7.2. EPSS: 2.7% chance of exploitation in the next 30 days.
Loomio version 2.22.0 allows executing arbitrary commands on the server. This is possible because the application is vulnerable to OS Command Injection.
Affected products
- Loomio Loomio: version 2.22.0 only
Published 2024-02-20. Last modified 2026-06-17.