CVE-2026-45086Medium· 5.4▾ SunlitDecidim is a participatory democracy framework. From 0.31.1 before 0.31.5 and in 0.32.0.rc1 before 0.32.0.rc2, a participant can directly load /admin/demographics/questions/edit_questions and reach the demographics questionnaire editor w…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 1.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.2%
Last analysed / modified upstream
Decidim is a participatory democracy framework. From 0.31.1 before 0.31.5 and in 0.32.0.rc1 before 0.32.0.rc2, a participant can directly load /admin/demographics/questions/edit_questions and reach the demographics questionnaire editor without the required administrator authorization. The demographics questionnaire editor should require admin access, but the route under /admin/demographics/questions renders the editor interface without checking whether the caller is an admin. A normal participant can load the page and see the live update form action, which proves the protected interface is reachable. This issue is fixed in versions 0.31.5 and 0.32.0.rc2.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
decidim-demographics >= 0.31.0, < 0.31.5decidim-demographics >= 0.32.0.rc1, < 0.32.0Patched in:
decidim-demographics 0.31.5decidim-demographics 0.32.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-1609High· 8.1A flaw was found in Keycloak
CVE-2026-50006Critical· 9.1Anyquery is an SQL query engine built on top of SQLite
CVE-2026-49822High· 7.7Fission: Cross-namespace event leakage via KubernetesWatchTrigger allows persistent tenant surveillance
CVE-2026-20736High· 7.5Gitea does not properly verify repository context when deleting attachments
CVE-2026-20750Critical· 9.1Gitea does not properly validate project ownership in organization project operations
CVE-2026-45377Medium· 6.5Decidim is a participatory democracy framework