Vulnerabilities
Vulnerable Software
Loomio:  >> Loomio  Security Vulnerabilities
Loomio version 2.22.0 allows executing arbitrary commands on the server. This is possible because the application is vulnerable to OS Command Injection.
CVSS Score
10.0
EPSS Score
0.017
Published
2024-02-20
Cross-site scripting (XSS) vulnerability in the Markdown parser in Loomio before 1.8.0 allows remote attackers to inject arbitrary web script or HTML via non-sanitized Markdown content in a new thread or a thread comment.
CVSS Score
5.4
EPSS Score
0.002
Published
2017-07-24


Contact Us

Shodan ® - All rights reserved