Show filters
2 Total Results
Displaying 1-2 of 2
Sort by:
Attacker Value
Unknown

CVE-2024-1297

Disclosure Date: February 20, 2024 (last updated January 06, 2025)
Loomio version 2.22.0 allows executing arbitrary commands on the server. This is possible because the application is vulnerable to OS Command Injection.
Attacker Value
Unknown

CVE-2017-11594

Disclosure Date: July 24, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in the Markdown parser in Loomio before 1.8.0 allows remote attackers to inject arbitrary web script or HTML via non-sanitized Markdown content in a new thread or a thread comment.
0