CVE-2026-23891
EUVD-2026-2202413.04.2026, 17:16
Decidim is a participatory democracy framework. In versions below 0.30.5 and 0.31.0.rc1 through 0.31.0, a stored code execution vulnerability in the user name field allows a low-privileged attacker to execute arbitrary code in the context of any user who passively visits a comment page, resulting in high confidentiality and integrity impact across security boundaries. This issue has been fixed in versions 0.30.5 and 0.31.1.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| decidim | decidim | 𝑥 < 0.30.5 |
| decidim | decidim | 0.31.0 ≤ 𝑥 < 0.31.1 |
𝑥
= Vulnerable software versions