PatchSiren

decidim CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM decidim CVE published 2026-07-31

CVE-2026-45377

Decidim is a participatory democracy framework that has a vulnerability allowing replay of download_your_data flow without authentication. This affects versions prior to 0.30.9, 0.31.5, and 0.32.0.rc2. The vulnerability allows an attacker to access sensitive data without proper authentication. Decidim users and administrators should be aware of this vulnerability and take necessary actions to prevent unau [truncated]

MEDIUM decidim CVE published 2026-07-31

CVE-2026-45376

The Decidim framework, used for participatory democracy, has a blind SQL injection vulnerability in versions prior to 0.30.9, 0.31.5, and 0.32.0.rc2. This vulnerability allows an authenticated organization administrator to inject malicious SQL expressions through the GET /admin/organization/users search endpoint, potentially leading to data inference through timing differences. The vulnerability was publi [truncated]

MEDIUM decidim CVE published 2026-07-31

CVE-2026-45330

The Decidim framework, a participatory democracy platform, has a vulnerability (CVE-2026-45330) that allows administrators from one tenant to access and manage ID-document requests from another tenant. This issue arises from the lack of proper current_organization ownership verification in the identity-document verification admin controllers. The vulnerability has a CVSS score of 4.9 and is classified as [truncated]

MEDIUM decidim CVE published 2026-07-31

CVE-2026-45086

CVE-2026-45086 is a MEDIUM severity vulnerability in Decidim, a participatory democracy framework. The issue allows participants to directly access the demographics questionnaire editor without administrator authorization in versions 0.31.1 to 0.31.4 and 0.32.0.rc1. This access could lead to unauthorized modifications. The vulnerability has a CVSS score of 5.4 and can lead to unauthorized modifications of [truncated]