Home/Product/raytha
Product

raytha

11 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-69246
< 1.4.6
Raytha CMS does not have any brute force protection mechanism implemented. It allows an attacker to send multiple automated logon
9.8CRITICAL
CVE-2025-69245
< 1.4.6
Raytha CMS is vulnerable to Reflected XSS via returnUrl parameter in logon functionality. An attacker can craft a malicious URL w
6.1MEDIUM
CVE-2025-69243
< 1.5.0
Raytha CMS is vulnerable to User Enumeration in password reset functionality. Difference in messages could allow an attacker to de
5.3MEDIUM
CVE-2025-69242
< 1.4.6
Raytha CMS is vulnerable to reflected XSS via the backToListUrl parameter. An attacker can craft a malicious URL which, when open
6.1MEDIUM
CVE-2025-69241
< 1.4.6
Raytha CMS is vulnerable to Stored XSS via FirstName and LastName parameters in profile editing functionality. Authenticated att
5.4MEDIUM
CVE-2025-69240
< 1.4.6
Raytha CMS allows an attacker to spoof X-Forwarded-Host or Host headers to attacker controlled domain. The attacker (who knows
8.8HIGH
CVE-2025-69239
< 1.4.6
Raytha CMS is vulnerable to Server-Side Request Forgery in the “Themes - Import from URL” feature. It allows an attacker with
2.7LOW
CVE-2025-69238
< 1.4.6
Raytha CMS is vulnerable to Cross-Site Request Forgery across multiple endpoints. Attacker can craft special website, which when v
4.3MEDIUM
CVE-2025-69237
< 1.4.6
Raytha CMS is vulnerable to Stored XSS via FieldValues[0].Value parameter in page creation functionality. Authenticated attacker
5.4MEDIUM
CVE-2025-69236
< 1.4.6
Raytha CMS is vulnerable to Stored XSS via FieldValues[1].Value parameter in post editing functionality. Authenticated attacker w
5.4MEDIUM
CVE-2025-15540
< 1.4.6
"Functions" module in Raytha CMS allows privileged users to write custom code to add functionality to application. Due to a lack
8.8HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin