Cross-Site Scripting Vulnerability in Decidim Framework
CVE-2026-45572

4.8MEDIUM

Key Information:

Vendor

Decidim

Status
Vendor
CVE Published:
6 August 2026

What is CVE-2026-45572?

The Decidim framework, a platform for participatory democracy, has a vulnerability that allows an administrator with landing-page editing privileges to insert arbitrary HTML and JavaScript into HTML content blocks. This content is rendered without proper sanitization, leading to the potential execution of malicious scripts in the browsers of users visiting the affected pages. The issue has been addressed in versions 0.30.9, 0.31.5, and 0.32.0.rc2, urging all users to update their installations to safeguard against possible attacks.

Affected Version(s)

decidim < 0.30.9 < 0.30.9

decidim >= 0.31.0.rc1, < 0.31.5 < 0.31.0.rc1, 0.31.5

decidim >= 0.32.0.rc1, < 0.32.0 < 0.32.0.rc1, 0.32.0

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.