This page aggregates publicly disclosed CVE and security risk information related to loomio, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2024-1297 | Loomio version 2.22.0 allows executing arbitrary commands on the server. This is possible because the application is vulnerable to OS Command Injection. | [email protected] | 7.2 | 1.46% | 2024-02-20 | 2026-04-20 |
| CVE-2017-11594 | Cross-site scripting (XSS) vulnerability in the Markdown parser in Loomio before 1.8.0 allows remote attackers to inject arbitrary web script or HTML via non-sanitized Markdown content in a new thread or a thread comment. | [email protected] | 5.4 | 0.23% | 2017-07-24 | 2026-05-13 |