Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-23891

28
FAUCET Score

CVE-2026-23891 is a stored code execution vulnerability in Decidim, an open-source participatory democracy platform, affecting versions below 0.30.5 and 0.31.0.rc1 through 0.31.1. The flaw exists in the user name field and allows low-privileged attackers to inject and execute arbitrary code that runs in the context of any user who views affected comment pages, compromising both confidentiality and integrity across security boundaries. The vulnerability has been patched in versions 0.30.5 and 0.31.1. The attack requires network access with low privilege credentials and user interaction, as victims must passively visit a compromised comment page for exploitation. The CVSS 3.1 score of 8.7 reflects the high severity due to significant confidentiality and integrity impacts, though availability is not affected. An attacker can steal sensitive information or modify content visible to legitimate users without requiring complex technical conditions. There is currently no active exploitation detected in the wild, and this vulnerability is not included on CISA's Known Exploited Vulnerabilities catalog. The EPSS score of 0.00046 indicates minimal real-world exploitation likelihood compared to other CVEs, and the vulnerability has not generated substantial community attention or readily available exploit code, suggesting a measured rather than critical threat posture at present.

Impacted Technologies

VendorProductVersion(s)CPE
< 0.30.5CPE matchmatch criteria
cpe:2.3:a:decidim:decidim:*:*:*:*:*:ruby:*:*
>= 0.31.0, < 0.31.1CPE matchmatch criteria
cpe:2.3:a:decidim:decidim:*:*:*:*:*:ruby:*:*

CVSS Data

CVSS version used by this source: 4.0

9.3CRITICAL

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
LOW
User Interaction
PASSIVE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
LOW
SS Confidentiality
HIGH
SS Integrity
HIGH
SS Availability
LOW
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.36%
Probability of exploitation in next 30 days
EPSS Percentile
28.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0036 is in the 36th percentile among its peer group of 890 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

rubygemspatch availablevia ghsa
Product: decidim-coreFixed in: 0.31.1
rubygemspatch availablevia ghsa
Product: decidim-coreFixed in: 0.30.5
github_advisoryvendor investigatingvia nvd_reference
View patch

Vendor Advisories (1)

rubygemsGHSA-fc46-r95f-hq7gcritical

Decidim has a cross-site scripting (XSS) in user name

Apr 13, 2026

References

github.com / decidim/decidim/releases/tag/v0.30.5
ProductRelease Notes
github.com / decidim/decidim/releases/tag/v0.31.1
ProductRelease Notes
github.com / decidim/decidim/security/advisories/GHSA-fc46-r95f-hq7g
Vendor Advisory