📦 Decidim

by Decidim

🔍 What is Decidim?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-36465

CRITICAL CVSS 9.1 Oct 6, 2023

This vulnerability in Decidim's templates module allows any authenticated user to access administrative template management functions, enabling unauthorized creation, modification, or deletion of surv...

CVE-2024-45594

HIGH CVSS 7.7 Nov 13, 2024

This Cross-Site Scripting (XSS) vulnerability in Decidim's meeting embeds feature allows attackers to inject malicious scripts through specially crafted URLs. Users who view or interact with these mal...

CVE-2023-34089

HIGH CVSS 8.1 Jul 11, 2023

CVE-2023-34089 is a cross-site scripting (XSS) vulnerability in Decidim's processes filter feature that allows remote attackers to execute JavaScript in the context of logged-in users. This could enab...

CVE-2023-32693

HIGH CVSS 8.1 Jul 11, 2023

CVE-2023-32693 is a cross-site scripting (XSS) vulnerability in Decidim's external link feature that allows remote attackers to execute JavaScript in logged-in users' browsers. This affects Decidim in...

CVE-2025-65017

MEDIUM CVSS 6.5 Feb 3, 2026

This vulnerability in Decidim's private data export feature allows UUID collisions that could lead to unauthorized access to sensitive user data. Organizations using Decidim versions 0.30.0-0.30.3 or ...

CVE-2024-32034

MEDIUM CVSS 6.8 Sep 16, 2024

This vulnerability allows cross-site scripting (XSS) attacks in Decidim's admin panel when administrators perform actions that generate activity logs containing malicious content. Attackers could exec...