VYPR

Decidim

by Decidim

gem: decidim

Source repositories

CVEs (28)

  • CVE-2026-45376MedJul 31, 2026
    risk 0.29cvss 5.5epss 0.00

    Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the GET /admin/organization/users search interpolates params[:term] into raw Arel.sql ORDER BY similarity expressions before sanitization, allowing an…

  • CVE-2026-45086MedJul 31, 2026
    risk 0.28cvss 5.4epss 0.00

    Decidim is a participatory democracy framework. From 0.31.1 before 0.31.5 and in 0.32.0.rc1 before 0.32.0.rc2, a participant can directly load /admin/demographics/questions/edit_questions and reach the demographics questionnaire editor without the required administrator…

  • CVE-2024-39910MedSep 16, 2024
    risk 0.28cvss 5.4epss 0.00

    decidim is a Free Open-Source participatory democracy, citizen participation and open government for cities and organizations. The WYSWYG editor QuillJS is subject to potential XSS attach in case the attacker manages to modify the HTML before being uploaded to the server. The…

  • CVE-2024-27095MedJul 10, 2024
    risk 0.28cvss 5.4epss 0.00

    Decidim is a participatory democracy framework. The admin panel is subject to potential XSS attach in case the attacker manages to modify some records being uploaded to the server. This vulnerability is fixed in 0.27.6 and 0.28.1.

  • CVE-2024-27090MedJul 10, 2024
    risk 0.27cvss 5.3epss 0.00

    Decidim is a participatory democracy framework, written in Ruby on Rails, originally developed for the Barcelona City government online and offline participation website. If an attacker can infer the slug or URL of an unpublished or private resource, and this resource can be…

  • CVE-2026-45330MedJul 31, 2026
    risk 0.25cvss 4.9epss 0.00

    Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the identity-document verification admin controllers load pending Authorization records by raw identifier without confirming current_organization…

  • CVE-2023-47635MedFeb 20, 2024
    risk 0.22cvss 4.5epss 0.00

    Decidim is a participatory democracy framework. Starting in version 0.23.0 and prior to versions 0.27.5 and 0.28.0, the CSRF authenticity token check is disabled for the questionnaire templates preview. The issue does not imply a serious security thread as you need to have…

  • CVE-2023-47634LowFeb 29, 2024
    risk 0.13cvss 3.1epss 0.00

    Decidim is a participatory democracy framework. Starting in version 0.10.0 and prior to versions 0.26.9, 0.27.5, and 0.28.0, a race condition in the endorsement of resources (for instance, a proposal) allows a user to make more than once endorsement. To exploit this…

Page 2 of 2