Cross-Site Scripting Vulnerability in Decidim Framework
CVE-2026-45572
4.8MEDIUM
What is CVE-2026-45572?
The Decidim framework, a platform for participatory democracy, has a vulnerability that allows an administrator with landing-page editing privileges to insert arbitrary HTML and JavaScript into HTML content blocks. This content is rendered without proper sanitization, leading to the potential execution of malicious scripts in the browsers of users visiting the affected pages. The issue has been addressed in versions 0.30.9, 0.31.5, and 0.32.0.rc2, urging all users to update their installations to safeguard against possible attacks.
Affected Version(s)
decidim < 0.30.9 < 0.30.9
decidim >= 0.31.0.rc1, < 0.31.5 < 0.31.0.rc1, 0.31.5
decidim >= 0.32.0.rc1, < 0.32.0 < 0.32.0.rc1, 0.32.0
