6 Total advisories
6 Vulnerabilities
0 Malware
Dependency scanning
Check whether decidim-core is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
HIGH 7.5
CVE-2026-40869
Decidim amendments can be accepted or rejected by anyone
HIGH 8.7
CVE-2026-23891
Decidim has a cross-site scripting (XSS) in user name
UNKNOWN
CVE-2025-65017
Decidim's private data exports can lead to data leaks
MEDIUM 6.3
CVE-2023-51447
Cross-site scripting (XSS) in the dynamic file uploads
HIGH 8.1
CVE-2023-34089
Decidim Cross-site Scripting vulnerability in the processes filter
MEDIUM 6.1
CVE-2023-32693
Decidim Cross-site Scripting vulnerability in the external link redirections
Browse more RubyGems advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes