CVE-2024-1297: Loomio

High severity, CVSS 7.2. EPSS: 2.7% chance of exploitation in the next 30 days.

Loomio version 2.22.0 allows executing arbitrary commands on the server. This is possible because the application is vulnerable to OS Command Injection.

Affected products

  • Loomio Loomio: version 2.22.0 only

Published 2024-02-20. Last modified 2026-06-17.