CVE-2026-45573
- EPSS 0.31%
- Veröffentlicht 06.08.2026 22:17:07
- Zuletzt bearbeitet 08.08.2026 03:16:45
Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, when VAPID delivery is enabled, the notification subscription flow stores a client-supplied push endpoint without validat...
CVE-2026-45572
- EPSS 0.18%
- Veröffentlicht 06.08.2026 22:17:07
- Zuletzt bearbeitet 07.08.2026 18:17:15
Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, an administrator with landing-page editing privileges can store arbitrary HTML and JavaScript in an HTML content block, w...
- EPSS 0.4%
- Veröffentlicht 06.08.2026 22:17:07
- Zuletzt bearbeitet 07.08.2026 16:17:24
Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the /admin/csv_census/census_logs record-management endpoints do not enforce full administrator authorization before rend...
CVE-2026-45414
- EPSS 0.32%
- Veröffentlicht 06.08.2026 22:17:06
- Zuletzt bearbeitet 07.08.2026 18:17:15
Decidim is a participatory democracy framework. Prior to 0.31.5 and in 0.32.0.rc1 before 0.32.0.rc2, JWT-backed API authentication is not bound to the organization selected by the current host, allowing a JWT issued for one tenant to be replayed agai...
CVE-2026-45378
- EPSS 0.3%
- Veröffentlicht 06.08.2026 22:17:06
- Zuletzt bearbeitet 07.08.2026 17:17:04
Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the identity-document verification admin UI embeds verification_attachment blobs through reusable signed Active Storage d...
CVE-2026-45377
- EPSS 0.27%
- Veröffentlicht 31.07.2026 23:17:24
- Zuletzt bearbeitet 01.08.2026 00:17:16
Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the normal download_your_data flow requires the requester to be logged in as the export owner, but the resulting Active S...
CVE-2026-45376
- EPSS 0.34%
- Veröffentlicht 31.07.2026 22:34:27
- Zuletzt bearbeitet 03.08.2026 18:16:39
Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the GET /admin/organization/users search interpolates params[:term] into raw Arel.sql ORDER BY similarity expressions bef...
CVE-2026-45330
- EPSS 0.28%
- Veröffentlicht 31.07.2026 22:05:21
- Zuletzt bearbeitet 03.08.2026 21:16:39
Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the identity-document verification admin controllers load pending Authorization records by raw identifier without confirm...
CVE-2026-45086
- EPSS 0.17%
- Veröffentlicht 31.07.2026 21:44:11
- Zuletzt bearbeitet 03.08.2026 18:16:39
Decidim is a participatory democracy framework. From 0.31.1 before 0.31.5 and in 0.32.0.rc1 before 0.32.0.rc2, a participant can directly load /admin/demographics/questions/edit_questions and reach the demographics questionnaire editor without the re...
CVE-2026-40869
- EPSS 0.22%
- Veröffentlicht 21.04.2026 19:08:28
- Zuletzt bearbeitet 23.04.2026 16:08:50
Decidim is a participatory democracy framework. Starting in version 0.19.0 and prior to versions 0.30.5 and 0.31.1, a vulnerability allows any registered and authenticated user to accept or reject any amendments. The impact is on any users who have c...