vciy

CVEs we hold for Decidim

Records whose assigning authority named Decidim as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-45573Decidim: Push subscriptions can be abused for server-side requestsdecidim
CVE-2026-45572Decidim: HTML content blocks allow stored script executiondecidim
CVE-2026-45415Decidim: CSV census record endpoints improper authorizationdecidim
CVE-2026-45414Decidim: JWT-backed authentication can be replayed across organizationsdecidim
CVE-2026-45378Decidim: Verification documents can be downloaded through reusable linksdecidim
CVE-2026-45377Decidim: Private exports can be downloaded through reusable linksdecidim
CVE-2026-45376Decidim: Admin user search allows SQL injection through similarity-based sortingdecidim
CVE-2026-45330Decidim: Verification admins can access supplied IDs from other organisationsdecidim
CVE-2026-45086Decidim: Forms admin question editor lacks authorizationdecidim
CVE-2026-44282Election question titles allow stored script executiondecidim
CVE-2026-40870Decidim's comments API allows access to all commentable resourcesdecidim
CVE-2026-40869Decidim amendments can be accepted or rejected by anyonedecidim
CVE-2026-23891Decidim has a Cross-site scripting (XSS) vulnerability via user name fielddecidim
CVE-2025-65017Decidim's private data exports can lead to data leaksdecidim
CVE-2024-45594Decidim allows cross-site scripting (XSS) in the online or hybrid meeting embedsdecidim
CVE-2024-43415Decidim-Awesome: SQL injection in AdminAccountabilitydecidim-ice decidim-module-decidim_awesome
CVE-2024-41673Decidim has a cross-site scripting vulnerability in the version control pagedecidim
CVE-2024-39910Cross-site scripting (XSS) in the decidim admin panel with QuillJS WYSWYG editordecidim
CVE-2024-32469Decidim has cross-site scripting (XSS) in the paginationdecidim
CVE-2024-32034Cross-site scripting (XSS) in the decidim admin activity logdecidim
CVE-2024-27095Decidim cross-site scripting (XSS) in the admin paneldecidim
CVE-2024-27090Decidim vulnerable to data disclosure through the embed featuredecidim
CVE-2023-51447Decidim vulnerable to cross-site scripting (XSS) in the dynamic file uploadsdecidim
CVE-2023-48220Decidim's devise_invitable gem vulnerable to circumvention of invitation token expiry perioddecidim
CVE-2023-47635Decidim vulnerable to possible CSRF attack at questionnaire templates previewdecidim
CVE-2023-47634Decidim has race condition in Endorsementsdecidim
CVE-2023-36465Decidim has broken access control in templatesdecidim
CVE-2023-34090Decidim vulnerable to sensitive data disclosuredecidim
CVE-2023-34089Decidim Cross-site Scripting vulnerability in the processes filterdecidim
CVE-2023-32693Decidim Cross-site Scripting vulnerability in the external link redirectionsdecidim

30 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.