CVE-2025-48076

Publication date 4 November 2025

Last updated 25 December 2025


Ubuntu priority

Description

Galette is a membership management web application for non profit organizations. Versions 1.1.5.2 and below allow a user to edit a group name and insert an XSS payload. This issue is fixed in version 1.2.0.

Status

Package Ubuntu Release Status
galette 25.10 questing Not in release
25.04 plucky Not in release
24.04 LTS noble Not in release
22.04 LTS jammy Not in release
16.04 LTS xenial
Needs evaluation


Access our resources on patching vulnerabilities