decidim vulnerabilities
CVEs whose affected-version data names the decidim package (rubygems). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-44282Medium· 4.8Decidim is a participatory democracy framework
Decidim is a participatory democracy framework. Prior to 0.32.0, a low-privilege process-scoped administrator or election editor with question-management rights can store HTML or script-bearing content in question.body. The question_titl…
▾ Sunlitdecidim · decidimEPSS 0.37%via NVD
CVE-2026-45414High· 8.5Decidim is a participatory democracy framework
Decidim is a participatory democracy framework. Prior to 0.31.5 and in 0.32.0.rc1 before 0.32.0.rc2, JWT-backed API authentication is not bound to the organization selected by the current host, allowing a JWT issued for one tenant to be …
▾ Twilightdecidim · decidimEPSS 0.32%via NVD