CVE-2025-58053
- EPSS 0.07%
- Veröffentlicht 19.12.2025 16:26:00
- Zuletzt bearbeitet 05.01.2026 17:59:50
Galette is a membership management web application for non profit organizations. Prior to version 1.2.0, while updating any existing account with a self forged POST request, one can gain higher privileges. Version 1.2.0 fixes the issue.
CVE-2025-58052
- EPSS 0.05%
- Veröffentlicht 19.12.2025 16:24:10
- Zuletzt bearbeitet 05.01.2026 18:03:38
Galette is a membership management web application for non profit organizations. Starting in version 0.9.6 and prior to version 1.2.0, attackers with group manager role can bypass intended restrictions allowing unauthorized access and changes despite...
CVE-2025-53922
- EPSS 0.04%
- Veröffentlicht 19.12.2025 15:10:00
- Zuletzt bearbeitet 02.01.2026 14:55:01
Galette is a membership management web application for non profit organizations. Starting in version 1.1.4 and prior to version 1.2.0, a user who is logged in as group manager may bypass intended restrictions on Contributions and Transactions. Versio...
CVE-2025-48884
- EPSS 0.04%
- Veröffentlicht 04.11.2025 20:44:29
- Zuletzt bearbeitet 10.11.2025 18:13:05
Galette is a membership management web application for non profit organizations. In versions 1.1.5.2 and below, Galette's Document Type is vulnerable to Cross-site Scripting. This issue is fixed in version 1.2.0.
CVE-2025-48076
- EPSS 0.04%
- Veröffentlicht 04.11.2025 20:40:09
- Zuletzt bearbeitet 10.11.2025 18:14:15
Galette is a membership management web application for non profit organizations. Versions 1.1.5.2 and below allow a user to edit a group name and insert an XSS payload. This issue is fixed in version 1.2.0.
CVE-2024-24761
- EPSS 0.21%
- Veröffentlicht 06.03.2024 18:15:46
- Zuletzt bearbeitet 17.12.2024 20:06:11
Galette is a membership management web application for non profit organizations. Starting in version 1.0.0 and prior to version 1.0.2, public pages are per default restricted to only administrators and staff members. From configuration, it is possibl...
CVE-2021-41261
- EPSS 0.35%
- Veröffentlicht 16.12.2021 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:25:54
Galette is a membership management web application built for non profit organizations and released under GPLv3. Versions prior to 0.9.6 are subject to stored cross site scripting attacks via the preferences footer. The preference footer can only be a...
CVE-2021-41262
- EPSS 0.3%
- Veröffentlicht 16.12.2021 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:25:54
Galette is a membership management web application built for non profit organizations and released under GPLv3. Versions prior to 0.9.6 are subject to SQL injection attacks by users with "member" privilege. Users are advised to upgrade to version 0.9...
CVE-2021-41260
- EPSS 0.16%
- Veröffentlicht 16.12.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 06:25:54
Galette is a membership management web application built for non profit organizations and released under GPLv3. Versions prior to 0.9.6 do not check for Cross Site Request Forgery attacks. All users are advised to upgrade to 0.9.6 as soon as possible...
CVE-2021-21319
- EPSS 0.72%
- Veröffentlicht 25.10.2021 16:15:08
- Zuletzt bearbeitet 21.11.2024 05:48:00
Galette is a membership management web application geared towards non profit organizations. In versions prior to 0.9.5, malicious javascript code can be stored to be displayed later on self subscription page. The self subscription feature can be disa...