CVEs we hold for Decidim
Records whose assigning authority named Decidim as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-45573Decidim: Push subscriptions can be abused for server-side requestsdecidim CVE-2026-45572Decidim: HTML content blocks allow stored script executiondecidim CVE-2026-45415Decidim: CSV census record endpoints improper authorizationdecidim CVE-2026-45414Decidim: JWT-backed authentication can be replayed across organizationsdecidim CVE-2026-45378Decidim: Verification documents can be downloaded through reusable linksdecidim CVE-2026-45377Decidim: Private exports can be downloaded through reusable linksdecidim CVE-2026-45376Decidim: Admin user search allows SQL injection through similarity-based sortingdecidim CVE-2026-45330Decidim: Verification admins can access supplied IDs from other organisationsdecidim CVE-2026-45086Decidim: Forms admin question editor lacks authorizationdecidim CVE-2026-44282Election question titles allow stored script executiondecidim CVE-2026-40870Decidim's comments API allows access to all commentable resourcesdecidim CVE-2026-40869Decidim amendments can be accepted or rejected by anyonedecidim CVE-2026-23891Decidim has a Cross-site scripting (XSS) vulnerability via user name fielddecidim CVE-2025-65017Decidim's private data exports can lead to data leaksdecidim CVE-2024-45594Decidim allows cross-site scripting (XSS) in the online or hybrid meeting embedsdecidim CVE-2024-43415Decidim-Awesome: SQL injection in AdminAccountabilitydecidim-ice decidim-module-decidim_awesome CVE-2024-41673Decidim has a cross-site scripting vulnerability in the version control pagedecidim CVE-2024-39910Cross-site scripting (XSS) in the decidim admin panel with QuillJS WYSWYG editordecidim CVE-2024-32469Decidim has cross-site scripting (XSS) in the paginationdecidim CVE-2024-32034Cross-site scripting (XSS) in the decidim admin activity logdecidim CVE-2024-27095Decidim cross-site scripting (XSS) in the admin paneldecidim CVE-2024-27090Decidim vulnerable to data disclosure through the embed featuredecidim CVE-2023-51447Decidim vulnerable to cross-site scripting (XSS) in the dynamic file uploadsdecidim CVE-2023-48220Decidim's devise_invitable gem vulnerable to circumvention of invitation token expiry perioddecidim CVE-2023-47635Decidim vulnerable to possible CSRF attack at questionnaire templates previewdecidim CVE-2023-34089Decidim Cross-site Scripting vulnerability in the processes filterdecidim CVE-2023-32693Decidim Cross-site Scripting vulnerability in the external link redirectionsdecidim 30 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.