Decidim is a participatory democracy framework. In versions below 0.30.5 and 0.31.0.rc1 through 0.31.0, a stored code execution vulnerability in the user name field allows a low-privileged attacker to execute arbitrary code in the context of any user who passively visits a comment page, resulting in high confidentiality and integrity impact across security boundaries. This issue has been fixed in versions 0.30.5 and 0.31.1.
History

Mon, 13 Apr 2026 17:15:00 +0000

Type Values Removed Values Added
Description Decidim is a participatory democracy framework. In versions below 0.30.5 and 0.31.0.rc1 through 0.31.0, a stored code execution vulnerability in the user name field allows a low-privileged attacker to execute arbitrary code in the context of any user who passively visits a comment page, resulting in high confidentiality and integrity impact across security boundaries. This issue has been fixed in versions 0.30.5 and 0.31.1.
Title Decidim has a Cross-site scripting (XSS) vulnerability via user name field
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-04-13T16:52:16.448Z

Reserved: 2026-01-16T21:02:02.902Z

Link: CVE-2026-23891

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-04-13T17:16:28.063

Modified: 2026-04-13T17:16:28.063

Link: CVE-2026-23891

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.