Skip to content
Noroxi

decidim records

16 published records for vendor decidim.

All records

16 records
  • Decidim has a Cross-site scripting (XSS) vulnerability via user name field

    CriticalCVSS 9.3No exploitEPSS 0%

    decidim · decidimApr 13, 2026

  • Decidim's private data exports can lead to data leaks

    HighCVSS 8.2No exploitEPSS 0%

    decidim · decidimFeb 3, 2026

  • Decidim vulnerable to sensitive data disclosure

    HighCVSS 7.5No exploitEPSS 1%

    decidim · decidimJul 11, 2023

  • Decidim's devise_invitable gem vulnerable to circumvention of invitation token expiry period

    HighCVSS 7.4No exploitEPSS 1%

    decidim · decidimFeb 20, 2024

  • Decidim has broken access control in templates

    HighCVSS 7.1No exploitEPSS 1%

    decidim · decidimOct 6, 2023

  • Decidim amendments can be accepted or rejected by anyone

    MediumCVSS 6.5No exploitEPSS 0%

    decidim · decidimApr 21, 2026

  • Decidim Cross-site Scripting vulnerability in the external link redirections

    MediumCVSS 6.1No exploitEPSS 1%

    decidim · decidimJul 11, 2023

  • Decidim Cross-site Scripting vulnerability in the processes filter

    MediumCVSS 6.1No exploitEPSS 1%

    decidim · decidimJul 11, 2023

  • Decidim vulnerable to possible CSRF attack at questionnaire templates preview

    MediumCVSS 5.7No exploitEPSS 0%

    decidim · decidimFeb 20, 2024

  • Decidim vulnerable to cross-site scripting (XSS) in the dynamic file uploads

    MediumCVSS 5.4No exploitEPSS 0%

    decidim · decidimFeb 20, 2024

  • Decidim vulnerable to data disclosure through the embed feature

    MediumCVSS 5.3No exploitEPSS 0%

    decidim · decidimJul 10, 2024

  • Decidim allows cross-site scripting (XSS) in the online or hybrid meeting embeds

    MediumCVSS 5.4No exploitEPSS 0%

    decidim · decidimNov 13, 2024

  • Cross-site scripting (XSS) in the decidim admin activity log

    MediumCVSS 4.8No exploitEPSS 0%

    decidim · decidimSep 16, 2024

  • Decidim cross-site scripting (XSS) in the admin panel

    MediumCVSS 4.8No exploitEPSS 0%

    decidim · decidimJul 10, 2024

  • Cross-site scripting (XSS) in the decidim admin panel with QuillJS WYSWYG editor

    MediumCVSS 4.8No exploitEPSS 0%

    decidim · decidimSep 16, 2024

  • Decidim has race condition in Endorsements

    LowCVSS 3.1No exploitEPSS 0%

    decidim · decidimFeb 28, 2024