12 Total advisories
12 Vulnerabilities
0 Malware
Dependency scanning
Check whether decidim is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
HIGH 7.5
CVE-2023-34090
Decidim vulnerable to sensitive data disclosure
UNKNOWN
CVE-2025-65017
Decidim's private data exports can lead to data leaks
LOW 3.1
CVE-2023-47634
Race condition in Endorsements
HIGH 7.1
CVE-2024-32469
Decidim cross-site scripting (XSS) in the pagination
HIGH 7.1
CVE-2024-41673
Decidim has a cross-site scripting vulnerability in the version control page
MEDIUM 5.4
CVE-2024-39910
Decidim::Admin vulnerable to cross-site scripting (XSS) in the admin panel with QuillJS WYSWYG editor
MEDIUM 5.3
CVE-2024-27090
Decidim vulnerable to data disclosure through the embed feature
MEDIUM 6.3
CVE-2023-51447
Cross-site scripting (XSS) in the dynamic file uploads
MEDIUM 5.7
CVE-2023-48220
Possibility to circumvent the invitation token expiry period
HIGH 7.1
CVE-2023-36465
Decidim has broken access control in templates
HIGH 8.1
CVE-2023-34089
Decidim Cross-site Scripting vulnerability in the processes filter
MEDIUM 6.1
CVE-2023-32693
Decidim Cross-site Scripting vulnerability in the external link redirections
Browse more RubyGems advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes