Lucene search

K

Decidim Security Vulnerabilities

cve
cve

CVE-2023-32693

Decidim is a participatory democracy framework, written in Ruby on Rails, originally developed for the Barcelona City government online and offline participation website. The external link feature is susceptible to cross-site scripting. This allows a remote attacker to execute JavaScript code in th...

8.1CVSS

6.2AI Score

0.002EPSS

2023-07-11 06:15 PM
18
cve
cve

CVE-2023-34089

Decidim is a participatory democracy framework, written in Ruby on Rails, originally developed for the Barcelona City government online and offline participation website. The processes filter feature is susceptible to Cross-site scripting. This allows a remote attacker to execute JavaScript code in...

8.1CVSS

6.3AI Score

0.002EPSS

2023-07-11 06:15 PM
26
cve
cve

CVE-2023-34090

Decidim is a participatory democracy framework, written in Ruby on Rails, originally developed for the Barcelona City government online and offline participation website. Decidim uses a third-party library named Ransack for filtering certain database collections (e.g., public meetings). By default,...

7.5CVSS

7.4AI Score

0.002EPSS

2023-07-11 06:15 PM
14
cve
cve

CVE-2023-36465

Decidim is a participatory democracy framework, written in Ruby on Rails, originally developed for the Barcelona City government online and offline participation website. The templates module doesn't enforce the correct permissions, allowing any logged-in user to access to this functionality in the...

9.1CVSS

6.8AI Score

0.001EPSS

2023-10-06 12:15 PM
49
cve
cve

CVE-2024-27095

Decidim is a participatory democracy framework. The admin panel is subject to potential XSS attach in case the attacker manages to modify some records being uploaded to the server. This vulnerability is fixed in 0.27.6 and 0.28.1.

5.4CVSS

5.9AI Score

0.001EPSS

2024-07-10 07:15 PM
39