Stored Script Execution Vulnerability in Decidim Framework
CVE-2026-44282
4.8MEDIUM
What is CVE-2026-44282?
The Decidim framework, designed for participatory democracy applications, harbors a vulnerability that allows low-privilege administrators or election editors to inject malicious HTML or script content into the question body. When users visit public election pages, the compromised content is rendered without proper sanitization, leading to executed scripts in the browsers of unsuspecting voters. This vulnerability, affecting all versions prior to 0.32.0, has been addressed in subsequent updates to ensure better security against cross-site scripting attacks.
Affected Version(s)
decidim < 0.32.0
