<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 01:26:10 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-349361</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-349361</link>
      <description>EUVD-2026-349361</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-349361</guid>
    </item>
    <item>
      <title>fkie_cve-2026-45572</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-45572</link>
      <description>&lt;p&gt;Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, an administrator with landing-page editing privileges can store arbitrary HTML and JavaScript in an HTML content block, which Decidim::ContentBlocks::HtmlCell#html_content renders without sanitization, causing the script to execute in visitors&amp;#39; browsers. This issue is fixed in versions 0.30.9, 0.31.5, and 0.32.0.rc2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, an administrator with landing-page editing privileges can store arbitrary HTML and JavaScript in an HTML content block, which Decidim::ContentBlocks::HtmlCell#html_content renders without sanitization, causing the script to execute in visitors&amp;#39; browsers. This issue is fixed in versions 0.30.9, 0.31.5, and 0.32.0.rc2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-45572</guid>
    </item>
    <item>
      <title>GHSA-533c-2vh9-4r86 — Decidim: HTML content blocks allow stored script execution</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-533c-2vh9-4r86</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: decidim-core&lt;/p&gt;
&lt;p&gt;## Description
 
A privileged admin user who can edit an affected landing page can store arbitrary HTML/JavaScript in an `HTML block`, and the public page renders it with `html_safe` and no output escaping.&lt;/p&gt;
&lt;p&gt;## Technical description
    
This issue lets any admin who can edit an affected landing page store arbitrary HTML and JavaScript in an `HTML block`. The block is then rendered back through `Decidim::ContentBlocks::HtmlCell#html_content` without a sanitization boundary, so the script executes later in visitor&amp;#39;s browsers.&lt;/p&gt;
&lt;p&gt;&amp;lt;img width=&amp;#34;1541&amp;#34; height=&amp;#34;439&amp;#34; alt=&amp;#34;decidim-html-xss-01&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/acae1c06-8acb-49be-ab12-aabae33190ce&amp;#34; /&amp;gt;&lt;/p&gt;
&lt;p&gt;&amp;lt;img width=&amp;#34;1540&amp;#34; height=&amp;#34;752&amp;#34; alt=&amp;#34;decidim-html-xss-02&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/a2f1fa7f-03f3-4d17-b58b-f4db865443e9&amp;#34; /&amp;gt;&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;- A user with landing-page editing rights for an affected scope can persist JavaScript that executes in visitor&amp;#39;s browsers on that page.
- Because exploitation already requires privileged administrative access, the practical risk is lower than a participant-controlled or unauthenticated stored XSS. It still creates a browser-execution primitive in a trusted admin-editable surface.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;See https://github.com/decidim/decidim/pull/16451&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Do not give admin permissions to non-trustful users.&lt;/p&gt;
&lt;p&gt;### Reference&lt;/p&gt;
&lt;p&gt;Stored XSS&lt;/p&gt;
&lt;p&gt;### Credits&lt;/p&gt;
&lt;p&gt;This issue was discovered in a security audit organized by the [Decidim Association](https://decid…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: decidim-core&lt;/p&gt;
&lt;p&gt;## Description
 
A privileged admin user who can edit an affected landing page can store arbitrary HTML/JavaScript in an `HTML block`, and the public page renders it with `html_safe` and no output escaping.&lt;/p&gt;
&lt;p&gt;## Technical description
    
This issue lets any admin who can edit an affected landing page store arbitrary HTML and JavaScript in an `HTML block`. The block is then rendered back through `Decidim::ContentBlocks::HtmlCell#html_content` without a sanitization boundary, so the script executes later in visitor&amp;#39;s browsers.&lt;/p&gt;
&lt;p&gt;&amp;lt;img width=&amp;#34;1541&amp;#34; height=&amp;#34;439&amp;#34; alt=&amp;#34;decidim-html-xss-01&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/acae1c06-8acb-49be-ab12-aabae33190ce&amp;#34; /&amp;gt;&lt;/p&gt;
&lt;p&gt;&amp;lt;img width=&amp;#34;1540&amp;#34; height=&amp;#34;752&amp;#34; alt=&amp;#34;decidim-html-xss-02&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/a2f1fa7f-03f3-4d17-b58b-f4db865443e9&amp;#34; /&amp;gt;&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;- A user with landing-page editing rights for an affected scope can persist JavaScript that executes in visitor&amp;#39;s browsers on that page.
- Because exploitation already requires privileged administrative access, the practical risk is lower than a participant-controlled or unauthenticated stored XSS. It still creates a browser-execution primitive in a trusted admin-editable surface.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;See https://github.com/decidim/decidim/pull/16451&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Do not give admin permissions to non-trustful users.&lt;/p&gt;
&lt;p&gt;### Reference&lt;/p&gt;
&lt;p&gt;Stored XSS&lt;/p&gt;
&lt;p&gt;### Credits&lt;/p&gt;
&lt;p&gt;This issue was discovered in a security audit organized by the [Decidim Association](https://decid…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-533c-2vh9-4r86</guid>
    </item>
  </channel>
</rss>
