CVE-2026-23891: Decidim
High severity, CVSS 8.7. EPSS: 0.4% chance of exploitation in the next 30 days.
Decidim is a participatory democracy framework. In versions below 0.30.5 and 0.31.0.rc1 through 0.31.0, a stored code execution vulnerability in the user name field allows a low-privileged attacker to execute arbitrary code in the context of any user who passively visits a comment page, resulting in high confidentiality and integrity impact across security boundaries. This issue has been fixed in versions 0.30.5 and 0.31.1.
Affected products
- Decidim Decidim: before 0.30.5 (fixed in 0.30.5); from 0.31.0, before 0.31.1 (fixed in 0.31.1)
Published 2026-04-13. Last modified 2026-06-17.