PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-45572 decidim CVE debrief

Decidim, a participatory democracy framework, has a vulnerability where administrators with landing-page editing privileges can store arbitrary HTML and JavaScript in an HTML content block. This content is rendered without sanitization, potentially leading to XSS attacks. The issue affects versions prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2. Administrators and users should be aware of this vulnerability and take steps to update to a fixed version.

Vendor
decidim
Product
Unknown
CVSS
MEDIUM 4.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-06
Original CVE updated
2026-08-07
Advisory published
2026-08-06
Advisory updated
2026-08-07

Who should care

Administrators and users of Decidim platforms, especially those with landing-page editing privileges, should be aware of this vulnerability and take steps to update to a fixed version. Additionally, security teams and vulnerability management teams should review the affected scope and severity to ensure proper mitigation and remediation efforts are in place. Operators of Decidim platforms should also review compensating controls for exposed systems while remediation is scheduled and verified. Monitoring and detection teams should check relevant logs for exposed assets that need extra review. Asset inventory management should track exceptions and retest remediated assets to ensure the vulnerability is properly addressed. Rollback and change window management should be considered for updates and mitigations through normal change control where exposure is confirmed. Source tracking and verification should be performed to ensure the accuracy of the information and to prevent potential attacks. Security teams should prioritize updating to a fixed version to prevent potential XSS attacks and review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. They should also plan vendor-supported updates or mitigations through normal change control where exposure is confirmed and review compensating controls for exposed systems while remediation is scheduled and verified. Furthermore, they should check relevant monitoring, detection, and logs for exposed assets that need extra review and track exceptions, retest remediated assets, and close the item only after evidence is documented. Finally, they should confirm whether affected product deployments exist in managed environments and assign an owner for follow-up. In summary, a wide range of stakeholders including administrators, security teams, operators, and users should be aware of and act upon this vulnerability to prevent potential attacks and ensure the security of their Decidim platforms. The vulnerability can be addressed by updating to versions 0.30.9, 0.31.5, or 0.32.0.rc2, and by implementing compensating controls and monitoring and detection measures. By taking a '

Technical summary

The Decidim framework has a vulnerability where an administrator with landing-page editing privileges can store arbitrary HTML and JavaScript in an HTML content block. This content is rendered without sanitization, potentially leading to XSS attacks. The issue is fixed in versions 0.30.9, 0.31.5, and 0.32.0.rc2. Affected deployments should prioritize updating to a fixed version to prevent potential XSS attacks.

Defensive priority

Administrators using Decidim should prioritize updating to a fixed version to prevent potential XSS attacks.

Recommended defensive actions

  • Update Decidim to version 0.30.9, 0.31.5, or 0.32.0.rc2
  • Restrict HTML content block editing to trusted administrators
  • Monitor for suspicious activity on Decidim platforms
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.

Evidence notes

The CVE record indicates that Decidim, a participatory democracy framework, has a vulnerability where an administrator with landing-page editing privileges can store arbitrary HTML and JavaScript in an HTML content block. This content is rendered without sanitization, potentially leading to XSS attacks. The issue is fixed in versions 0.30.9, 0.31.5, and 0.32.0.rc2.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T22:17:07.403Z and has not been modified since then.