Executive brief
A stored cross-site scripting (XSS) vulnerability in Decidim allows low-privileged attackers to execute arbitrary code in the context of other users by manipulating the user name field.
Junglewise Threat Intelligence
CVE-2026-23891 · Severity: high · CVSS 8.7 · Published 2026-04-13
A stored cross-site scripting (XSS) vulnerability in Decidim allows low-privileged attackers to execute arbitrary code in the context of other users by manipulating the user name field.