Decidim

Decidim

16 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.03%
  • Veröffentlicht 03.02.2026 15:16:12
  • Zuletzt bearbeitet 23.02.2026 17:32:33

Decidim is a participatory democracy framework. In versions from 0.30.0 to before 0.30.4 and from 0.31.0.rc1 to before 0.31.0, the private data exports can lead to data leaks in case the UUID generation, causing collisions for the generated UUIDs. Th...

  • EPSS 0.21%
  • Veröffentlicht 13.11.2024 17:15:10
  • Zuletzt bearbeitet 14.02.2025 16:35:51

Decidim is a participatory democracy framework. The meeting embeds feature used in the online or hybrid meetings is subject to potential XSS attack through a malformed URL. This vulnerability is fixed in 0.28.3 and 0.29.0.

  • EPSS 0.42%
  • Veröffentlicht 01.10.2024 15:15:07
  • Zuletzt bearbeitet 04.10.2024 13:51:25

Decidim is a participatory democracy framework. The version control feature used in resources is subject to potential XSS attack through a malformed URL. This vulnerability is fixed in 0.27.8.

  • EPSS 0.57%
  • Veröffentlicht 16.09.2024 19:16:10
  • Zuletzt bearbeitet 29.09.2024 00:14:35

decidim is a Free Open-Source participatory democracy, citizen participation and open government for cities and organizations. The admin panel is subject to potential Cross-site scripting (XSS) attach in case an admin assigns a valuator to a proposal...

  • EPSS 0.63%
  • Veröffentlicht 16.09.2024 19:16:10
  • Zuletzt bearbeitet 29.09.2024 00:33:03

decidim is a Free Open-Source participatory democracy, citizen participation and open government for cities and organizations. The WYSWYG editor QuillJS is subject to potential XSS attach in case the attacker manages to modify the HTML before being u...

  • EPSS 0.28%
  • Veröffentlicht 10.07.2024 19:15:10
  • Zuletzt bearbeitet 21.11.2024 09:03:50

Decidim is a participatory democracy framework, written in Ruby on Rails, originally developed for the Barcelona City government online and offline participation website. If an attacker can infer the slug or URL of an unpublished or private resource,...

  • EPSS 0.28%
  • Veröffentlicht 10.07.2024 19:15:10
  • Zuletzt bearbeitet 21.11.2024 09:03:50

Decidim is a participatory democracy framework. The admin panel is subject to potential XSS attach in case the attacker manages to modify some records being uploaded to the server. This vulnerability is fixed in 0.27.6 and 0.28.1.

  • EPSS 0.49%
  • Veröffentlicht 10.07.2024 19:15:10
  • Zuletzt bearbeitet 21.11.2024 09:14:58

Decidim is a participatory democracy framework. The pagination feature used in searches and filters is subject to potential XSS attack through a malformed URL using the GET parameter `per_page`. This vulnerability is fixed in 0.27.6 and 0.28.1.

  • EPSS 0.29%
  • Veröffentlicht 29.02.2024 01:41:28
  • Zuletzt bearbeitet 14.02.2025 17:29:55

Decidim is a participatory democracy framework. Starting in version 0.10.0 and prior to versions 0.26.9, 0.27.5, and 0.28.0, a race condition in the endorsement of resources (for instance, a proposal) allows a user to make more than once endorsement....

  • EPSS 0.11%
  • Veröffentlicht 20.02.2024 18:15:50
  • Zuletzt bearbeitet 16.12.2024 21:28:47

Decidim is a participatory democracy framework. Starting in version 0.23.0 and prior to versions 0.27.5 and 0.28.0, the CSRF authenticity token check is disabled for the questionnaire templates preview. The issue does not imply a serious security thr...