Decidim is a participatory-democracy and civic-engagement platform deployed by municipalities and public institutions to manage public consultation, budgeting, and decision-making workflows. Its vulnerability footprint, concentrated in the platform itself, recurs through web-application input-handling and access-control weakness classes including cross-site scripting, cross-site request forgery, improper access control, and race conditions in shared resources, alongside information-disclosure flaws characteristic of platforms handling citizen input and voting data. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Decidim over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-23891HIGH Decidim is a participatory democracy framework. In versions below 0.30.5 and 0.31.0.rc1 through 0.31.0, a stored code execution vulnerability in the user name field allows a low-pr | Apr 13, 2026 | 8.7 | 28 | NO | NO |
CVE-2026-40869MEDIUM Decidim is a participatory democracy framework. Starting in version 0.19.0 and prior to versions 0.30.5 and 0.31.1, a vulnerability allows any registered and authenticated user to | Apr 21, 2026 | 6.5 | 23 | NO | NO |
CVE-2025-65017MEDIUM Decidim is a participatory democracy framework. In versions from 0.30.0 to before 0.30.4 and from 0.31.0.rc1 to before 0.31.0, the private data exports can lead to data leaks in ca | Feb 3, 2026 | 6.5 | 23 | NO | NO |
CVE-2023-36465HIGH Decidim is a participatory democracy framework, written in Ruby on Rails, originally developed for the Barcelona City government online and offline participation website. The `temp | Oct 6, 2023 | 7.1 | 23 | NO | NO |
CVE-2023-34090HIGH Decidim is a participatory democracy framework, written in Ruby on Rails, originally developed for the Barcelona City government online and offline participation website. Decidim u | Jul 11, 2023 | 7.5 | 23 | NO | NO |
CVE-2023-48220HIGH Decidim is a participatory democracy framework. Starting in version 0.4.rc3 and prior to version 2.0.9 of the `devise_invitable` gem, the invites feature allows users to accept the | Feb 20, 2024 | 7.4 | 21 | NO | NO |
CVE-2023-32693MEDIUM Decidim is a participatory democracy framework, written in Ruby on Rails, originally developed for the Barcelona City government online and offline participation website. The exter | Jul 11, 2023 | 6.1 | 21 | NO | NO |
CVE-2023-47635MEDIUM Decidim is a participatory democracy framework. Starting in version 0.23.0 and prior to versions 0.27.5 and 0.28.0, the CSRF authenticity token check is disabled for the questionna | Feb 20, 2024 | 5.7 | 19 | NO | NO |
CVE-2023-34089MEDIUM Decidim is a participatory democracy framework, written in Ruby on Rails, originally developed for the Barcelona City government online and offline participation website. The proce | Jul 11, 2023 | 6.1 | 19 | NO | NO |
CVE-2024-45594MEDIUM Decidim is a participatory democracy framework. The meeting embeds feature used in the online or hybrid meetings is subject to potential XSS attack through a malformed URL. This vu | Nov 13, 2024 | 5.4 | 18 | NO | NO |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Decidim.
Media articles that mention a CVE ID that affects a product developed by Decidim — matched by CVE ID, not by vendor name.