Galette is a membership management and association administration application, narrowly scoped in product footprint but positioned prominently in the nonprofit and volunteer-organization sector. Its vulnerability profile centers consistently on web-application input-handling and access-control weaknesses, including cross-site scripting variants, cross-site request forgery, and authorization flaws that are characteristic of form-driven administrative interfaces. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Galette over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-58053CRITICAL Galette is a membership management web application for non profit organizations. Prior to version 1.2.0, while updating any existing account with a self forged POST request, one ca | Dec 19, 2025 | 9.8 | 33 | NO | NO |
CVE-2021-41262HIGH Galette is a membership management web application built for non profit organizations and released under GPLv3. Versions prior to 0.9.6 are subject to SQL injection attacks by user | Dec 16, 2021 | 8.8 | 28 | NO | NO |
CVE-2021-41260HIGH Galette is a membership management web application built for non profit organizations and released under GPLv3. Versions prior to 0.9.6 do not check for Cross Site Request Forgery | Dec 16, 2021 | 8.8 | 28 | NO | NO |
CVE-2025-58052HIGH Galette is a membership management web application for non profit organizations. Starting in version 0.9.6 and prior to version 1.2.0, attackers with group manager role can bypass | Dec 19, 2025 | 8.1 | 26 | NO | NO |
CVE-2025-48884MEDIUM Galette is a membership management web application for non profit organizations. In versions 1.1.5.2 and below, Galette's Document Type is vulnerable to Cross-site Scripting. This | Nov 4, 2025 | 6.1 | 21 | NO | NO |
CVE-2025-48076MEDIUM Galette is a membership management web application for non profit organizations. Versions 1.1.5.2 and below allow a user to edit a group name and insert an XSS payload. This issue | Nov 4, 2025 | 5.4 | 21 | NO | NO |
CVE-2024-24761HIGH Galette is a membership management web application for non profit organizations. Starting in version 1.0.0 and prior to version 1.0.2, public pages are per default restricted to on | Mar 6, 2024 | 7.5 | 20 | NO | NO |
CVE-2021-41261MEDIUM Galette is a membership management web application built for non profit organizations and released under GPLv3. Versions prior to 0.9.6 are subject to stored cross site scripting a | Dec 16, 2021 | 4.8 | 19 | NO | NO |
CVE-2021-21319MEDIUM Galette is a membership management web application geared towards non profit organizations. In versions prior to 0.9.5, malicious javascript code can be stored to be displayed late | Oct 25, 2021 | 5.4 | 19 | NO | NO |
CVE-2025-53922MEDIUM Galette is a membership management web application for non profit organizations. Starting in version 1.1.4 and prior to version 1.2.0, a user who is logged in as group manager may | Dec 19, 2025 | 4.9 | 18 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Galette.
Media articles that mention a CVE ID that affects a product developed by Galette — matched by CVE ID, not by vendor name.