Sploitus

CVE-2026-23891

No indexed exploits for CVE-2026-23891 yet

Decidim is a participatory democracy framework. In versions below 0.30.5 and 0.31.0.rc1 through 0.31.0, a stored code execution vulnerability in the user name field allows a low-privileged attacker to execute arbitrary code in the context of any user who passively visits a comment page, resulting in high confidentiality and integrity impact across security boundaries. This issue has been fixed in versions 0.30.5 and 0.31.1.

Affected products
Decidim
Decidim
< 0.30.5, 0.31.1
Fix
Available
CVSS 4.0
9.3 CRITICAL
CVSS 3.1
8.7 HIGH
EPSS
0.4% (28th percentile)
Weakness
CWE-79
NVD status
Analyzed
Published
2026-04-13
CVE-2026-23891 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-23891 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-23891 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.