CVE-2025-53922: Galette
Medium severity, CVSS 4.9. EPSS: 0.2% chance of exploitation in the next 30 days.
Galette is a membership management web application for non profit organizations. Starting in version 1.1.4 and prior to version 1.2.0, a user who is logged in as group manager may bypass intended restrictions on Contributions and Transactions. Version 1.2.0 fixes the issue.
Affected products
- Galette Galette: from 1.1.4, before 1.2.0 (fixed in 1.2.0)
Published 2025-12-19. Last modified 2026-06-17.