Stored Script Execution Vulnerability in Decidim Framework
CVE-2026-44282

4.8MEDIUM

Key Information:

Vendor

Decidim

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-44282?

The Decidim framework, designed for participatory democracy applications, harbors a vulnerability that allows low-privilege administrators or election editors to inject malicious HTML or script content into the question body. When users visit public election pages, the compromised content is rendered without proper sanitization, leading to executed scripts in the browsers of unsuspecting voters. This vulnerability, affecting all versions prior to 0.32.0, has been addressed in subsequent updates to ensure better security against cross-site scripting attacks.

Affected Version(s)

decidim < 0.32.0

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.