CVE-2026-45415Medium· 6.0▾ SunlitDecidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the /admin/csv_census/census_logs record-management endpoints do not enforce full administrator authorizatio…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 33 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 7.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.4%
Last analysed / modified upstream
0.4% → 0.5%
Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the /admin/csv_census/census_logs record-management endpoints do not enforce full administrator authorization before rendering or mutating Decidim::Verifications::CsvDatum, allowing a participant manager to create, alter, or remove census records. This issue is fixed in versions 0.30.9, 0.31.5, and 0.32.0.rc2.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
decidim-verifications < 0.30.9decidim-verifications >= 0.31.0.rc1, < 0.31.5decidim-verifications >= 0.32.0.rc1, < 0.32.0Patched in:
decidim-verifications 0.30.9decidim-verifications 0.31.5decidim-verifications 0.32.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-45330Medium· 4.9Decidim is a participatory democracy framework
CVE-2026-45378High· 7.5Decidim is a participatory democracy framework
CVE-2026-63330High· 7.7Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux
CVE-2026-56828High· 8.8Shopper: privilege escalation via improper Livewire admin component authorization
CVE-2026-86283High· 7.1MISP's UiBeta theme collection view (app/View/Themed/UiBeta/Collections/view.ctp) performed a secondary query of member events by UUID without applying the caller's access control list (ACL)
CVE-2026-55547Medium· 4.3Yamcs is a mission control framework