MEDIUM6.4RubyGems
GHSA-2g9c-vf8h-prxx· CVE-2026-45573Decidim: Push subscriptions can be abused for server-side requests
Modified: 7/13/2026
package
pkg:rubygems/decidim-core
Decidim: Push subscriptions can be abused for server-side requests
Modified: 7/13/2026
Decidim's private data exports can lead to data leaks
Modified: 2/8/2026
Decidim Cross-site Scripting vulnerability in the external link redirections
Modified: 9/10/2026
Decidim: HTML content blocks allow stored script execution
Modified: 7/13/2026
Decidim Cross-site Scripting vulnerability in the processes filter
Modified: 9/10/2026
Decidim: Private exports can be downloaded through reusable links
Modified: 7/13/2026
Cross-site scripting (XSS) in the dynamic file uploads
Modified: 2/20/2024
Decidim has a cross-site scripting (XSS) in user name
Modified: 5/13/2026
Decidim amendments can be accepted or rejected by anyone
Modified: 5/29/2026