PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-45572 decidim CVE debrief

CVE-2026-45572 is a medium-severity vulnerability in Decidim, a participatory democracy framework. An administrator with landing-page editing privileges can store arbitrary HTML and JavaScript in an HTML content block, which is rendered without sanitization, causing the script to execute in visitors' browsers. This issue affects Decidim versions prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2. The vulnerability allows for potential phishing or malicious activities. Decidim administrators and users with landing-page editing privileges should assess exposure and prioritize updating to a fixed version.

Vendor
decidim
Product
Unknown
CVSS
MEDIUM 4.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-06
Original CVE updated
2026-09-08
Advisory published
2026-08-06
Advisory updated
2026-09-08

Who should care

Decidim administrators and users with landing-page editing privileges should assess exposure and prioritize updating to a fixed version. Additionally, security teams and vulnerability management teams should review the vulnerability and its potential impact on their systems.

Why it matters

CVE-2026-45572 is a medium-severity vulnerability in Decidim that allows administrators with landing-page editing privileges to store arbitrary HTML and JavaScript, which is rendered without sanitization. This could lead to execution of malicious scripts in visitors' browsers, potentially resulting in phishing or other malicious activities. Decidim administrators and users with landing-page editing privileges should assess exposure and prioritize updating to a fixed version.

  • Execution of arbitrary JavaScript in visitors' browsers
  • Potential for phishing or malicious activity
  • Need for urgent patching or mitigation
  • Possible impact on user trust and platform reputation

Technical summary

The vulnerability allows an administrator with landing-page editing privileges to store arbitrary HTML and JavaScript in an HTML content block, which is rendered without sanitization, causing the script to execute in visitors' browsers. This issue affects Decidim versions prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2. The vulnerability has a CVSS score of 4.8 and is classified as medium-severity. There is no evidence of public exploitation at the time of CVE publication. The CVE Program and NVD provide official information on the vulnerability.

Defensive priority

Decidim administrators and users with landing-page editing privileges should assess exposure and prioritize updating to a fixed version.

Recommended defensive actions

  • Update Decidim to version 0.30.9, 0.31.5, or 0.32.0.rc2
  • Restrict landing-page editing privileges to trusted administrators
  • Monitor for suspicious activity on Decidim platforms
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, including its description, CVSS score, and affected versions. The vulnerability has been fixed in versions 0.30.9, 0.31.5, and 0.32.0.rc2. There is no evidence of public exploitation at the time of CVE publication. The CVE Program and NVD provide official information on the vulnerability. Additional information may be available from [email protected].

Sources and references

Verified primary and authoritative sources

  • CVE-2026-45572 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-45572

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-45572 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-45572

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.