CVE-2026-44282
- EPSS 0.37%
- Veröffentlicht 15.09.2026 15:25:56
- Zuletzt bearbeitet 30.09.2026 17:51:56
Decidim is a participatory democracy framework. Prior to 0.32.0, a low-privilege process-scoped administrator or election editor with question-management rights can store HTML or script-bearing content in question.body. The question_title helper retu...
CVE-2026-45573
- EPSS 0.31%
- Veröffentlicht 06.08.2026 22:17:07
- Zuletzt bearbeitet 08.09.2026 20:51:43
Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, when VAPID delivery is enabled, the notification subscription flow stores a client-supplied push endpoint without validat...
CVE-2026-45572
- EPSS 0.18%
- Veröffentlicht 06.08.2026 22:17:07
- Zuletzt bearbeitet 08.09.2026 20:51:43
Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, an administrator with landing-page editing privileges can store arbitrary HTML and JavaScript in an HTML content block, w...
- EPSS 0.4%
- Veröffentlicht 06.08.2026 22:17:07
- Zuletzt bearbeitet 08.09.2026 20:51:43
Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the /admin/csv_census/census_logs record-management endpoints do not enforce full administrator authorization before rend...
CVE-2026-45414
- EPSS 0.32%
- Veröffentlicht 06.08.2026 22:17:06
- Zuletzt bearbeitet 08.09.2026 20:51:43
Decidim is a participatory democracy framework. Prior to 0.31.5 and in 0.32.0.rc1 before 0.32.0.rc2, JWT-backed API authentication is not bound to the organization selected by the current host, allowing a JWT issued for one tenant to be replayed agai...
CVE-2026-45378
- EPSS 0.3%
- Veröffentlicht 06.08.2026 22:17:06
- Zuletzt bearbeitet 08.09.2026 20:51:43
Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the identity-document verification admin UI embeds verification_attachment blobs through reusable signed Active Storage d...
CVE-2026-45377
- EPSS 0.27%
- Veröffentlicht 31.07.2026 23:17:24
- Zuletzt bearbeitet 08.09.2026 20:51:43
Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the normal download_your_data flow requires the requester to be logged in as the export owner, but the resulting Active S...
CVE-2026-45376
- EPSS 0.34%
- Veröffentlicht 31.07.2026 22:34:27
- Zuletzt bearbeitet 08.09.2026 20:51:43
Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the GET /admin/organization/users search interpolates params[:term] into raw Arel.sql ORDER BY similarity expressions bef...
CVE-2026-45330
- EPSS 0.28%
- Veröffentlicht 31.07.2026 22:05:21
- Zuletzt bearbeitet 08.09.2026 20:51:43
Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the identity-document verification admin controllers load pending Authorization records by raw identifier without confirm...
CVE-2026-45086
- EPSS 0.17%
- Veröffentlicht 31.07.2026 21:44:11
- Zuletzt bearbeitet 08.09.2026 20:51:43
Decidim is a participatory democracy framework. From 0.31.1 before 0.31.5 and in 0.32.0.rc1 before 0.32.0.rc2, a participant can directly load /admin/demographics/questions/edit_questions and reach the demographics questionnaire editor without the re...