PT-2025-45044 · Galette · Galette

Published

2025-11-04

·

Updated

2025-11-05

·

CVE-2025-48076

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Galette versions 1.1.5.2 and below
Description Galette is a membership management web application for non profit organizations. Versions 1.1.5.2 and below allow a user to edit a group name and insert a Cross-site Scripting (XSS) payload. This issue is fixed in version 1.2.0.
Recommendations Update to version 1.2.0 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-48076
GHSA-CCWQ-MXX3-CHVH

Affected Products

Galette