VYPR
Medium severity4.8NVD Advisory· Published Aug 6, 2026· Updated Sep 8, 2026

CVE-2026-45572

CVE-2026-45572

Description

Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, an administrator with landing-page editing privileges can store arbitrary HTML and JavaScript in an HTML content block, which Decidim::ContentBlocks::HtmlCell#html_content renders without sanitization, causing the script to execute in visitors' browsers. This issue is fixed in versions 0.30.9, 0.31.5, and 0.32.0.rc2.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
decidim-coreRubyGems
< 0.30.90.30.9
decidim-coreRubyGems
>= 0.31.0.rc1, < 0.31.50.31.5
decidim-coreRubyGems
>= 0.32.0.rc1, < 0.32.00.32.0

Affected products

2
  • Decidim/Decidiminferred2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: 0.30.9, 0.31.5, 0.32.0.rc2

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.