CVE-2026-23891Disclosure(decidim / decidim)

LOWCVSS 8.7 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Decidim is a participatory democracy framework. In versions below 0.30.5 and 0.31.0.rc1 through 0.31.0, a stored code execution vulnerability in the user name field allows a low-privileged attacker to execute arbitrary code in the context of any user who passively visits a comment page, resulting in high confidentiality and integrity impact across security boundaries. This issue has been fixed in versions 0.30.5 and 0.31.1.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • decidim

Threat summary

  • Public PoC is present in monitored signal
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 1 mentions (2026-04-13); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
decidim

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-13: 1Mentions · 2026-04-15: 1Mentions · 2026-04-28: 1PoC Mentioned / Linked · 2026-04-13: 1Technical Details · 2026-04-13: 1Technical Details · 2026-04-15: 1Technical Details · 2026-04-28: 104-1304-1504-28
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • cvereports@_cvereports
    Disclosure

    CVE-2026-23891: CVE-2026-23891: Critical Stored Cross-Site Scripting (XSS) in Decidim User Profiles Decidim versions prior to 0.30.5 and 0.31.1 suffer from a critical stored Cross-Site Scripting (XSS) vulnerability. The framework fails to properly san... https://cvereports.com/reports/CVE-2026-23891

    Post summary

    The report reveals a critical stored XSS flaw in Decidim user profiles affecting versions before 0.30.5 and 0.31.1, but provides no PoC, exploitation details, or patch information.

    0000027
    36 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    A critical XSS vulnerability (CVE-2026-23891) affects `Decidim` through its user name handling. This could lead to script execution in other users' browsers. Monitor for updates. #Decidim #XSS #WebSecurity https://www.pulsepatch.io/posts/cve-2026-23891-decidim-xss

    Post summary

    A critical XSS flaw in Decidim’s user name handling could allow malicious scripts to run in other users’ browsers; monitoring for vendor updates is advised.

    0000034
    12 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-23891: Decidim has a Cross-site scripti... Stored XSS in username field = instant account takeover for anyone viewing comments - democracy platforms just became e... https://zerodaysignal.com/vulnerability/CVE-2026-23891 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    A newly disclosed Stored XSS in Decidim’s username field (CVE‑2026‑23891) enables instant account takeover when comments are viewed, with a reference link to details on ZeroDaySignal.

    0000078
    217 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdecidimdecidim-ruby-

Explore more