CVE-2024-41673: Decidim

High severity, CVSS 7.1. EPSS: 0.4% chance of exploitation in the next 30 days.

Decidim is a participatory democracy framework. The version control feature used in resources is subject to potential XSS attack through a malformed URL. This vulnerability is fixed in 0.27.8.

Affected products

  • Decidim Decidim: before 0.27.8 (fixed in 0.27.8)

Published 2024-10-01. Last modified 2026-06-17.