Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

galette — Vulnerabilities & Security Advisories 10

Browse all 10 CVE security advisories affecting galette. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Galette serves as a membership management system for associations and non-profits, handling member data, contributions, and event organization. Historically, it has been susceptible to multiple remote code execution vulnerabilities, cross-site scripting flaws, and privilege escalation issues, often stemming from improper input validation and insecure file handling. The application's PHP-based architecture and frequent exposure to public networks have made it a target for attackers seeking to compromise server infrastructure. Notable incidents include CVE-2021-39227, which allowed unauthenticated RCE via crafted API requests, and CVE-2020-35847, enabling XSS through member profile fields. These vulnerabilities highlight ongoing challenges in secure coding practices within the project.

Top products by galette: galette

This page lists every published CVE security advisory associated with galette. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.