CVE 9.3 CRITICAL

Decidim has a Cross-site scripting (XSS) vulnerability via user name field_CVE-2026-23891

9.3 / 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L

Description

Decidim is a participatory democracy framework. In versions below 0.30.5 and 0.31.0.rc1 through 0.31.0, a stored code execution vulnerability in the user name field allows a low-privileged attacker to execute arbitrary code in the context of any user who passively visits a comment page, resulting in high confidentiality and integrity impact across security boundaries. This issue has been fixed in versions 0.30.5 and 0.31.1.

AI Analysis

Stored code execution vulnerability in the user name field, allowing a low-privileged attacker to execute arbitrary code in the context of any user who passively visits a comment page.

Basic Information

ID CVE-2026-23891
Source GitHub_M
Published Apr 13, 2026 at 16:52

Affected Product

Vendor decidim
Product decidim
Version >= 0.31.0.rc1, < 0.31.1
Affected Versions decidim decidim >= 0.31.0.rc1, < 0.31.1
decidim decidim < 0.30.5

CWE Classification

AI Assessment

AI Score 9.3 / 10
AI Severity Critical
Vendor Decidim
Product Decidim
Version <= 0.31.0.rc1, < 0.30.5

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.