Back to Database
Status published
Medium
CVE-2024-27095
Decidim cross-site scripting (XSS) in the admin panel
Vulnerability Description
Decidim is a participatory democracy framework. The admin panel is subject to potential XSS attach in case the attacker manages to modify some records being uploaded to the server. This vulnerability is fixed in 0.27.6 and 0.28.1.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-27095
Credits & Attribution
No credits recorded in the NVD database.
References
More from decidim
View All →CVE-2025-65017
Decidim's private data exports can lead to data leaks
High
8.2
CVE-2024-45594
Decidim allows cross-site scripting (XSS) in the online or hybrid meeting embeds
High
7.7
CVE-2024-41673
Decidim has a cross-site scripting vulnerability in the version control page
High
7.1
CVE-2024-39910
Cross-site scripting (XSS) in the decidim admin panel with QuillJS WYSWYG editor
Medium
5.4
CVE-2024-32469
Decidim has cross-site scripting (XSS) in the pagination
High
7.1
Affected Vendor
decidim
View all reports →Affected Software
decidim
Vulnerable Versions:
< 0.27.6, >= 0.28.0.rc1, < 0.28.1
Timeline
Official Publish:
July 10th, 2024
Last Modified:
August 2nd, 2024
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:N/A:N