CVE-2024-32469: Decidim

High severity, CVSS 7.1. EPSS: 0.4% chance of exploitation in the next 30 days.

Decidim is a participatory democracy framework. The pagination feature used in searches and filters is subject to potential XSS attack through a malformed URL using the GET parameter `per_page`. This vulnerability is fixed in 0.27.6 and 0.28.1.

Affected products

  • Decidim Decidim: before 0.27.6 (fixed in 0.27.6); from 0.28.0.rc1, before 0.28.1 (fixed in 0.28.1)

Published 2024-07-10. Last modified 2026-06-17.