Stored XSS Vulnerability in Raytha CMS Affects Post Editing Functionality
CVE-2025-69236

5.1MEDIUM

Key Information:

Vendor

Raytha

Status
Vendor
CVE Published:
16 March 2026

What is CVE-2025-69236?

Raytha CMS contains a stored Cross-Site Scripting vulnerability that permits authenticated users with post editing rights to inject arbitrary HTML and JavaScript code. This can lead to the execution of malicious scripts on the web pages that other users visit, potentially compromising their sessions or exposing sensitive data. It is crucial for users to upgrade to version 1.4.6 or later to mitigate this risk.

Affected Version(s)

Raytha 0 < 1.4.6

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Daniel Basta
.