PT-2026-60073 · Decidim+2 · Decidim+1

CVE-2026-45572

·

Published

2026-07-13

·

Updated

2026-08-07

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Decidim versions prior to 0.30.9 Decidim versions 0.31.0 through 0.31.4 Decidim version 0.32.0.rc1
Description An administrator with landing-page editing privileges can store arbitrary HTML and JavaScript within an HTML content block. The Decidim::ContentBlocks::HtmlCell#html content function renders this content using html safe without proper sanitization or output escaping, which allows the stored script to execute in the browsers of visitors who view the affected page. This is a stored Cross-Site Scripting (XSS) issue, where a malicious script is permanently stored on the server and served to other users.
Recommendations Update to version 0.30.9. Update to version 0.31.5. Update to version 0.32.0.rc2. Avoid granting administrative permissions to untrusted users.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-45572
GHSA-533C-2VH9-4R86

Affected Products

Decidim
Decidim-Core