CVE-2024-27090
- EPSS 0.49%
- Veröffentlicht 10.07.2024 19:15:10
- Zuletzt bearbeitet 15.04.2026 00:35:42
Decidim is a participatory democracy framework, written in Ruby on Rails, originally developed for the Barcelona City government online and offline participation website. If an attacker can infer the slug or URL of an unpublished or private resource,...
CVE-2023-47634
- EPSS 0.44%
- Veröffentlicht 29.02.2024 01:41:28
- Zuletzt bearbeitet 14.02.2025 17:29:55
Decidim is a participatory democracy framework. Starting in version 0.10.0 and prior to versions 0.26.9, 0.27.5, and 0.28.0, a race condition in the endorsement of resources (for instance, a proposal) allows a user to make more than once endorsement....
CVE-2023-51447
- EPSS 0.49%
- Veröffentlicht 20.02.2024 18:15:50
- Zuletzt bearbeitet 16.12.2024 22:43:27
Decidim is a participatory democracy framework. Starting in version 0.27.0 and prior to versions 0.27.5 and 0.28.0, the dynamic file upload feature is subject to potential cross-site scripting attacks in case the attacker manages to modify the file n...
CVE-2023-48220
- EPSS 0.79%
- Veröffentlicht 20.02.2024 18:15:50
- Zuletzt bearbeitet 16.12.2024 21:46:47
Decidim is a participatory democracy framework. Starting in version 0.4.rc3 and prior to version 2.0.9 of the `devise_invitable` gem, the invites feature allows users to accept the invitation for an unlimited amount of time through the password reset...
CVE-2023-47635
- EPSS 0.31%
- Veröffentlicht 20.02.2024 18:15:50
- Zuletzt bearbeitet 16.12.2024 21:28:47
Decidim is a participatory democracy framework. Starting in version 0.23.0 and prior to versions 0.27.5 and 0.28.0, the CSRF authenticity token check is disabled for the questionnaire templates preview. The issue does not imply a serious security thr...
CVE-2023-36465
- EPSS 0.54%
- Veröffentlicht 06.10.2023 12:15:11
- Zuletzt bearbeitet 21.11.2024 08:09:46
Decidim is a participatory democracy framework, written in Ruby on Rails, originally developed for the Barcelona City government online and offline participation website. The `templates` module doesn't enforce the correct permissions, allowing any lo...
CVE-2023-34090
- EPSS 0.97%
- Veröffentlicht 11.07.2023 18:15:16
- Zuletzt bearbeitet 21.11.2024 08:06:31
Decidim is a participatory democracy framework, written in Ruby on Rails, originally developed for the Barcelona City government online and offline participation website. Decidim uses a third-party library named Ransack for filtering certain database...
CVE-2023-34089
- EPSS 0.58%
- Veröffentlicht 11.07.2023 18:15:16
- Zuletzt bearbeitet 21.11.2024 08:06:31
Decidim is a participatory democracy framework, written in Ruby on Rails, originally developed for the Barcelona City government online and offline participation website. The processes filter feature is susceptible to Cross-site scripting. This allow...
CVE-2023-32693
- EPSS 0.64%
- Veröffentlicht 11.07.2023 18:15:14
- Zuletzt bearbeitet 21.11.2024 08:03:51
Decidim is a participatory democracy framework, written in Ruby on Rails, originally developed for the Barcelona City government online and offline participation website. The external link feature is susceptible to cross-site scripting. This allows a...