Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 10 Nov 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:galette:galette:*:*:*:*:*:*:*:* cpe:2.3:a:galette:galette:1.2.0:alpha:*:*:*:*:*:* |
|
| Metrics |
cvssV3_1
|
Wed, 05 Nov 2025 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Galette
Galette galette |
|
| Vendors & Products |
Galette
Galette galette |
Tue, 04 Nov 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 04 Nov 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Galette is a membership management web application for non profit organizations. Versions 1.1.5.2 and below allow a user to edit a group name and insert an XSS payload. This issue is fixed in version 1.2.0. | |
| Title | Galette is vulnerable to Cross-site Scripting | |
| Weaknesses | CWE-87 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-11-04T21:04:06.991Z
Reserved: 2025-05-15T16:06:40.942Z
Link: CVE-2025-48076
Updated: 2025-11-04T21:04:02.576Z
Status : Analyzed
Published: 2025-11-04T21:15:37.513
Modified: 2025-11-10T18:14:15.173
Link: CVE-2025-48076
No data.
OpenCVE Enrichment
Updated: 2025-11-05T10:47:07Z