Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Galette

First CVE: Oct 25, 2021Active for: 5 yearsTotal CVEs: 10
30.3
VTI Score
Low

Galette is a membership management and association administration application, narrowly scoped in product footprint but positioned prominently in the nonprofit and volunteer-organization sector. Its vulnerability profile centers consistently on web-application input-handling and access-control weaknesses, including cross-site scripting variants, cross-site request forgery, and authorization flaws that are characteristic of form-driven administrative interfaces. Live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
10
Total CVEs
More Total CVEs than 92% of tracked vendors
3.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 49% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Galette over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 25, 2021
4 years ago
Most Recent CVE
Dec 19, 2025
217 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-58053CRITICAL
Galette is a membership management web application for non profit organizations. Prior to version 1.2.0, while updating any existing account with a self forged POST request, one ca
Dec 19, 20259.833NONO
CVE-2021-41262HIGH
Galette is a membership management web application built for non profit organizations and released under GPLv3. Versions prior to 0.9.6 are subject to SQL injection attacks by user
Dec 16, 20218.828NONO
CVE-2021-41260HIGH
Galette is a membership management web application built for non profit organizations and released under GPLv3. Versions prior to 0.9.6 do not check for Cross Site Request Forgery
Dec 16, 20218.828NONO
CVE-2025-58052HIGH
Galette is a membership management web application for non profit organizations. Starting in version 0.9.6 and prior to version 1.2.0, attackers with group manager role can bypass
Dec 19, 20258.126NONO
CVE-2025-48884MEDIUM
Galette is a membership management web application for non profit organizations. In versions 1.1.5.2 and below, Galette's Document Type is vulnerable to Cross-site Scripting. This
Nov 4, 20256.121NONO
CVE-2025-48076MEDIUM
Galette is a membership management web application for non profit organizations. Versions 1.1.5.2 and below allow a user to edit a group name and insert an XSS payload. This issue
Nov 4, 20255.421NONO
CVE-2024-24761HIGH
Galette is a membership management web application for non profit organizations. Starting in version 1.0.0 and prior to version 1.0.2, public pages are per default restricted to on
Mar 6, 20247.520NONO
CVE-2021-41261MEDIUM
Galette is a membership management web application built for non profit organizations and released under GPLv3. Versions prior to 0.9.6 are subject to stored cross site scripting a
Dec 16, 20214.819NONO
CVE-2021-21319MEDIUM
Galette is a membership management web application geared towards non profit organizations. In versions prior to 0.9.5, malicious javascript code can be stored to be displayed late
Oct 25, 20215.419NONO
CVE-2025-53922MEDIUM
Galette is a membership management web application for non profit organizations. Starting in version 1.1.4 and prior to version 1.2.0, a user who is logged in as group manager may
Dec 19, 20254.918NONO
View all 10 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products10 CVEs
50%
40%
10%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network10 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None5 (50.0%)
Unknown0 (0.0%)
Required5 (50.0%)
Privileges Required
Low4 (40.0%)
High2 (20.0%)
None4 (40.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Galette.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Galette — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Galette's Products

View all 1 CNAs →

Top CWEs