CVE-2026-45330Medium· 4.9▾ SunlitDecidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the identity-document verification admin controllers load pending Authorization records by raw identifier wi…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 1.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.3%
Last analysed / modified upstream
0.3% → 0.3%
Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the identity-document verification admin controllers load pending Authorization records by raw identifier without confirming current_organization ownership, allowing an administrator from one tenant to view, approve, or reject another tenant’s ID-document request. This issue is fixed in versions 0.30.9, 0.31.5, and 0.32.0.rc2.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
decidim-verifications < 0.30.9decidim-verifications >= 0.31.0.rc1, < 0.31.5decidim-verifications >= 0.32.0.rc1, < 0.32.0Patched in:
decidim-verifications 0.30.9decidim-verifications 0.31.5decidim-verifications 0.32.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-45378High· 7.5Decidim is a participatory democracy framework
CVE-2026-45415Medium· 6.0Decidim is a participatory democracy framework
CVE-2026-50025Medium· 6.9Mousehole is a background service to update a seedbox IP for MAM and web app to manage it
CVE-2021-25122High· 7.5When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to another meaning u…
CVE-2022-31746Medium· 6.5Internal URLs are protected by a secret UUID key, which could have been leaked to web page through the Referrer header
CVE-2026-50105Medium· 4.3Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698)