Decidim
This hub aggregates every CVE we track for Decidim, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
19
CVEs tracked
1
Critical
9
High
0
In CISA KEV
Severity distribution
HIGH9MEDIUM8LOW1CRITICAL1
Monthly trend
3
0
2
1
1
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
0
3
0
0
2024-072026-06
Latest CVEs
The 15 most recently published vulnerabilities affecting Decidim.
- CVE-2026-40869Decidim amendments can be accepted or rejected by anyone7.5
- CVE-2026-40870Decidim's comments API allows access to all commentable resources7.5
- CVE-2026-23891Decidim has a Cross-site scripting (XSS) vulnerability via user name field8.7
- CVE-2025-65017Decidim's private data exports can lead to data leaks6.5
- CVE-2024-45594Decidim allows cross-site scripting (XSS) in the online or hybrid meeting embeds7.7
- CVE-2024-41673Decidim has a cross-site scripting vulnerability in the version control page7.1
- CVE-2024-39910Cross-site scripting (XSS) in the decidim admin panel with QuillJS WYSWYG editor5.4
- CVE-2024-32034Cross-site scripting (XSS) in the decidim admin activity log6.8
- CVE-2024-32469Decidim has cross-site scripting (XSS) in the pagination7.1
- CVE-2024-27095Decidim cross-site scripting (XSS) in the admin panel5.4
- CVE-2024-27090Decidim vulnerable to data disclosure through the embed feature5.3
- CVE-2023-51447Decidim vulnerable to cross-site scripting (XSS) in the dynamic file uploads6.3
- CVE-2023-48220Decidim's devise_invitable gem vulnerable to circumvention of invitation token expiry period5.7
- CVE-2023-47635Decidim vulnerable to possible CSRF attack at questionnaire templates preview4.5
- CVE-2023-47634Decidim has race condition in Endorsements3.1
Product normalization is registry-driven with AI assist and human review. How it works