CVE-2024-24230: Komm.one CMS

High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.

Komm.One CMS 10.4.2.14 has a Server-Side Template Injection (SSTI) vulnerability via the Velocity template engine. It allows remote attackers to execute arbitrary code via a URL that specifies java.lang.Runtime in conjunction with getRuntime().exec followed by an OS command.

Affected products

Published 2024-03-18. Last modified 2026-06-17.