Junglewise Threat Intelligence

CVE-2026-23891: Decidim stored XSS in user name field

CVE-2026-23891 · Severity: high · CVSS 8.7 · Published 2026-04-13

Executive brief

A stored cross-site scripting (XSS) vulnerability in Decidim allows low-privileged attackers to execute arbitrary code in the context of other users by manipulating the user name field.

References