Stored XSS Vulnerability in Raytha CMS Affects Content Creation Features
CVE-2025-69237

5.1MEDIUM

Key Information:

Vendor

Raytha

Status
Vendor
CVE Published:
16 March 2026

What is CVE-2025-69237?

Raytha CMS contains a vulnerability that allows authenticated attackers with content creation permissions to exploit the FieldValues[0].Value parameter. By injecting arbitrary HTML and JavaScript into the page creation functionality, attackers can effectively execute malicious scripts when users visit the compromised page. The issue has been addressed in version 1.4.6 of Raytha CMS, highlighting the importance of updating to secure versions to prevent potential exploitation.

Affected Version(s)

Raytha 0 < 1.4.6

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Daniel Basta
.