GHSA-rx9f-5ggv-5rh6 · Severity: medium · Ecosystem: rubygems — Decidim::Admin vulnerable to cross-site scripting (XSS) in the admin activity log
decidim is a Free Open-Source participatory democracy, citizen participation and open government for cities and organizations. The admin panel is subject to potential Cross-site scripting (XSS) attach in case an admin assigns a valuator to a proposal, or does any other action that generates an admin activity log where one of the resources has an XSS crafted. This issue has been addressed in release version 0.27.7, 0.28.2, and newer. Users are advised to upgrade. Users unable to upgrade may redirect the pages /admin and /admin/logs to other admin pages to prevent this access (i.e. `/admin/organization/edit`).
Conclusion & alert: CVE-2024-32034 is rated Low Risk (36.2/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.35%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.57% | 0.35% | -0.22% |
| 2 | 2026-02-05 | 0.42% | 0.57% | +0.15% |
| 3 | 2025-11-21 | — | 0.42% | — |
Full EPSS history (8 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 6.8 | 3.1 | MEDIUM |
|
2.3 | 4.0 | [email protected] |
| 4.8 | 3.1 | MEDIUM |
|
1.7 | 2.7 | [email protected] |
GHSA-rx9f-5ggv-5rh6 · Severity: medium · Ecosystem: rubygems — Decidim::Admin vulnerable to cross-site scripting (XSS) in the admin activity log