Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4411 articles · 196819 vulns · 37/41 feeds (7d)
← Back to list
4.8
CVE-2026-45572PATCHED
rubygems · decidim-core

Decidim: HTML content blocks allow stored script execution

Description

Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, an administrator with landing-page editing privileges can store arbitrary HTML and JavaScript in an HTML content block, which Decidim::ContentBlocks::HtmlCell#html_content renders without sanitization, causing the script to execute in visitors' browsers. This issue is fixed in versions 0.30.9, 0.31.5, and 0.32.0.rc2.

Affected Products

VendorProductVersions
rubygemsdecidim-core< 0.30.9, >= 0.31.0.rc1, < 0.31.5, >= 0.32.0.rc1, < 0.32.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
rubygemsdecidim-coreGHSA85%

References

  • https://github.com/decidim/decidim/security/advisories/GHSA-533c-2vh9-4r86(x_refsource_CONFIRM)
  • https://github.com/decidim/decidim/pull/16451(x_refsource_MISC)

Related News (1 articles)

Tier C
VulDB18d ago
CVE-2026-45572 | Decidim up to 0.30.8/0.31.4/0.32.0.rc1 HtmlCell HtmlCell#html_content HTML injection
→ No new info (linked only)
CVSS 3.14.8 MEDIUM
VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
CISA KEV❌ No
Actively exploited❌ No
Patch available
decidim-core@0.30.9decidim-core@0.31.5decidim-core@0.32.0
CWECWE-94
PublishedJul 13, 2026
Tags
GHSA-533c-2vh9-4r86rubygems
Trending Score2
Source articles1
Independent1
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-66066EXPKEV
Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing
Trending: 87
NONECVE-2026-61666
websocket-driver: Denial of service via malformed Host header
Trending: 6
HIGHCVE-2026-45378
Decidim: Verification documents can be downloaded through reusable links
Trending: 6
NONECVE-2026-71847
Ruby JSON: JSON::ResumableParser#partial_value dereferences a freed input buffer and crashes on truncated duplicate-key streams
Trending: 5
HIGHCVE-2026-45414
Decidim: JWT-backed authentication can be replayed across organizations
Trending: 4

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 13, 2026
Discovered by ZDM
Jul 13, 2026
Patch Available
Aug 7, 2026