decidim-demographics
The participatory democracy framework. A generator and multiple gems made with Ruby on Rails
Activity
- Latest release
- 1mo ago
- Total releases
- 15
- Cadence
- ~23 days
- Last 12 months
- 14
Reach
- Stars
- 1.8k
Details
- License
- unknown
- First release
- Sep 25, 2025
| Version | Released | |
|---|---|---|
0.32.1
patch
| ||
0.31.7
patch
| ||
0.31.6
patch
| ||
0.32.0
minor
| ||
0.32.0.rc3
pre
1 CVE
CVE-2026-45086
GHSA-vq6j-hj8w-7v39
Jul 13, 2026
Decidim: Forms admin question editor lacks authorization
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
DescriptionA participant can load the demographics questionnaire admin editor and make changes. Technical descriptionThe demographics questionnaire editor should require admin access, but the route under Reproduction steps: Step 1. Sign in as a normal participant: Open Note that access was denied when attempting to see question responses or settings. Impact
PatchesSee https://github.com/decidim/decidim/pull/16665 WorkaroundsDisable the "decidim-demographics" module ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.31.0
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.32.0.rc2
pre
1 CVE
CVE-2026-45086
GHSA-vq6j-hj8w-7v39
Jul 13, 2026
Decidim: Forms admin question editor lacks authorization
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
DescriptionA participant can load the demographics questionnaire admin editor and make changes. Technical descriptionThe demographics questionnaire editor should require admin access, but the route under Reproduction steps: Step 1. Sign in as a normal participant: Open Note that access was denied when attempting to see question responses or settings. Impact
PatchesSee https://github.com/decidim/decidim/pull/16665 WorkaroundsDisable the "decidim-demographics" module ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.31.0
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.31.5
patch
| ||
0.32.0.rc1
pre
1 CVE
CVE-2026-45086
GHSA-vq6j-hj8w-7v39
Jul 13, 2026
Decidim: Forms admin question editor lacks authorization
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
DescriptionA participant can load the demographics questionnaire admin editor and make changes. Technical descriptionThe demographics questionnaire editor should require admin access, but the route under Reproduction steps: Step 1. Sign in as a normal participant: Open Note that access was denied when attempting to see question responses or settings. Impact
PatchesSee https://github.com/decidim/decidim/pull/16665 WorkaroundsDisable the "decidim-demographics" module ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.31.0
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.31.4
patch
1 CVE
CVE-2026-45086
GHSA-vq6j-hj8w-7v39
Jul 13, 2026
Decidim: Forms admin question editor lacks authorization
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
DescriptionA participant can load the demographics questionnaire admin editor and make changes. Technical descriptionThe demographics questionnaire editor should require admin access, but the route under Reproduction steps: Step 1. Sign in as a normal participant: Open Note that access was denied when attempting to see question responses or settings. Impact
PatchesSee https://github.com/decidim/decidim/pull/16665 WorkaroundsDisable the "decidim-demographics" module ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.31.0
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.31.3
patch
1 CVE
CVE-2026-45086
GHSA-vq6j-hj8w-7v39
Jul 13, 2026
Decidim: Forms admin question editor lacks authorization
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
DescriptionA participant can load the demographics questionnaire admin editor and make changes. Technical descriptionThe demographics questionnaire editor should require admin access, but the route under Reproduction steps: Step 1. Sign in as a normal participant: Open Note that access was denied when attempting to see question responses or settings. Impact
PatchesSee https://github.com/decidim/decidim/pull/16665 WorkaroundsDisable the "decidim-demographics" module ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.31.0
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.31.2
patch
1 CVE
CVE-2026-45086
GHSA-vq6j-hj8w-7v39
Jul 13, 2026
Decidim: Forms admin question editor lacks authorization
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
DescriptionA participant can load the demographics questionnaire admin editor and make changes. Technical descriptionThe demographics questionnaire editor should require admin access, but the route under Reproduction steps: Step 1. Sign in as a normal participant: Open Note that access was denied when attempting to see question responses or settings. Impact
PatchesSee https://github.com/decidim/decidim/pull/16665 WorkaroundsDisable the "decidim-demographics" module ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.31.0
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.31.1
patch
1 CVE
CVE-2026-45086
GHSA-vq6j-hj8w-7v39
Jul 13, 2026
Decidim: Forms admin question editor lacks authorization
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
DescriptionA participant can load the demographics questionnaire admin editor and make changes. Technical descriptionThe demographics questionnaire editor should require admin access, but the route under Reproduction steps: Step 1. Sign in as a normal participant: Open Note that access was denied when attempting to see question responses or settings. Impact
PatchesSee https://github.com/decidim/decidim/pull/16665 WorkaroundsDisable the "decidim-demographics" module ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.31.0
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.31.0
initial
1 CVE
CVE-2026-45086
GHSA-vq6j-hj8w-7v39
Jul 13, 2026
Decidim: Forms admin question editor lacks authorization
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
DescriptionA participant can load the demographics questionnaire admin editor and make changes. Technical descriptionThe demographics questionnaire editor should require admin access, but the route under Reproduction steps: Step 1. Sign in as a normal participant: Open Note that access was denied when attempting to see question responses or settings. Impact
PatchesSee https://github.com/decidim/decidim/pull/16665 WorkaroundsDisable the "decidim-demographics" module ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.31.0
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.31.0.rc2
pre
| ||
0.31.0.rc1
pre
|