Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-44282— Election question titles allow stored script execution

Quick assessment

Affected
decidim decidim
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Decidim 是一个参与式民主框架。在 0.32.0 版本之前,具有低权限的流程级管理员或拥有问题管理权限的选举编辑器可以在 字段中存储包含 HTML 或脚本的内容。 辅助函数通过 方法返回可翻译的问题正文,但缺乏内容净化(sanitization)边界,导致当访客打开公共选举页面或投票界面时,会触发存储型脚本执行(Stored XSS)。持久化的脚本将在访客的浏览器中执行。该漏洞已在 0.32.0 版本中修复。

CVSS 4.8 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-44282

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Election question titles allow stored script execution
Source: CVE Program / CVE List V5
Vulnerability Description
Decidim is a participatory democracy framework. Prior to 0.32.0, a low-privilege process-scoped administrator or election editor with question-management rights can store HTML or script-bearing content in question.body. The question_title helper returns the translatable question body through html_safe without a sanitization boundary, causing stored script execution when visitors open public election pages or voting booth screens. The persisted script executes in visitors' browsers. The vulnerability is fixed in 0.32.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
decidim decidim < 0.32.0 -

II. Public POCs for CVE-2026-44282

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-44282

登录查看更多情报信息。

Patches & Fixes for CVE-2026-44282 (4)

Vendor Advisories for CVE-2026-44282 (1)

Vendor Pages for CVE-2026-44282 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-44282

No comments yet


Leave a comment