SQL Injection Vulnerability in Decidim Participatory Democracy Framework
CVE-2026-45376
5.5MEDIUM
What is CVE-2026-45376?
The Decidim participatory democracy framework has a vulnerability that allows authenticated organization administrators to exploit SQL injection through unsanitized input in the admin user search feature. This vulnerability permits the execution of blind PostgreSQL expressions, potentially leading to sensitive data inference based on timing discrepancies. The issue has been resolved in versions 0.30.9, 0.31.5, and 0.32.0.rc2, where proper input sanitization measures have been implemented.
Affected Version(s)
decidim < 0.30.9 < 0.30.9
decidim >= 0.31.0.rc1, < 0.31.5 < 0.31.0.rc1, 0.31.5
decidim >= 0.32.0.rc1, < 0.32.0 < 0.32.0.rc1, 0.32.0
