Unrated severityNVD Advisory· Published Nov 4, 2025· Updated Nov 4, 2025
Galette is vulnerable to Cross-site Scripting
CVE-2025-48076
Description
Galette is a membership management web application for non profit organizations. Versions 1.1.5.2 and below allow a user to edit a group name and insert an XSS payload. This issue is fixed in version 1.2.0.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- github.com/galette/galette/security/advisories/GHSA-ccwq-mxx3-chvhmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.