decidim-admin
RubyGems3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting decidim-adminpage 1 of 1
- CVE-2023-48220MEDIUMCVSS 5.7EG 5.7✓ Fixed in 0.27.52024-02-20
vulnerable: 0.27.0, 0.27.1, 0.27.2, 0.27.3, 0.27.4
Decidim is a participatory democracy framework. Starting in version 0.4.rc3 and prior to version 2.0.9 of the `devise_invitable` gem, the invites feature allows users to accept the invitation for an unlimited amount of time through the pas…
- CVE-2024-27095MEDIUMCVSS 5.4EG 5.4✓ Fixed in 0.28.12024-07-10
vulnerable: 0.28.0, 0.28.0.rc4, 0.28.0.rc5
Decidim is a participatory democracy framework. The admin panel is subject to potential XSS attach in case the attacker manages to modify some records being uploaded to the server. This vulnerability is fixed in 0.27.6 and 0.28.1.
- CVE-2024-32034MEDIUMCVSS 6.8EG 6.8✓ Fixed in 0.28.22024-09-16
vulnerable: 0.28.0, 0.28.1
decidim is a Free Open-Source participatory democracy, citizen participation and open government for cities and organizations. The admin panel is subject to potential Cross-site scripting (XSS) attach in case an admin assigns a valuator to…
Check whether decidim-admin is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for decidim-admin CVEs against the assets you own.
Start Free Scan →