PT-2025-45045 · Galette · Galette

Published

2025-11-04

·

Updated

2025-11-05

·

CVE-2025-48884

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Galette versions 1.1.5.2 and below
Description Galette is a membership management web application for non profit organizations. Versions 1.1.5.2 and below are susceptible to Cross-site Scripting through the Document Type functionality.
Recommendations Update to version 1.2.0 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-48884
GHSA-3RC3-RC5X-VMR4

Affected Products

Galette