CVE-2026-44282: decidim-elections: Election question titles allow stored script execution
A low-privilege process-scoped admin who can manage elections can store arbitrary HTML in the question statement/body without sanitization, and the public elections UI renders that value unsafely.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-44282 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →