PT-2026-60073 · Decidim+2 · Decidim+1
CVE-2026-45572
·
Published
2026-07-13
·
Updated
2026-08-07
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Decidim versions prior to 0.30.9
Decidim versions 0.31.0 through 0.31.4
Decidim version 0.32.0.rc1
Description
An administrator with landing-page editing privileges can store arbitrary HTML and JavaScript within an HTML content block. The
Decidim::ContentBlocks::HtmlCell#html content function renders this content using html safe without proper sanitization or output escaping, which allows the stored script to execute in the browsers of visitors who view the affected page. This is a stored Cross-Site Scripting (XSS) issue, where a malicious script is permanently stored on the server and served to other users.Recommendations
Update to version 0.30.9.
Update to version 0.31.5.
Update to version 0.32.0.rc2.
Avoid granting administrative permissions to untrusted users.
Exploit
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Decidim
Decidim-Core