CVE-2024-45594: Decidim

Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.

Decidim is a participatory democracy framework. The meeting embeds feature used in the online or hybrid meetings is subject to potential XSS attack through a malformed URL. This vulnerability is fixed in 0.28.3 and 0.29.0.

Affected products

  • Decidim Decidim: from 0.28.0, before 0.28.3 (fixed in 0.28.3)

Published 2024-11-13. Last modified 2026-06-17.