MEDIUM
Stored XSS in Raytha CMS
Published Mar 16, 2026
5.1
MEDIUMCVSS 4.0
EPSS 0.18%
Description
Raytha CMS is vulnerable to Stored XSS via FieldValues[0].Value parameter in page creation functionality. Authenticated attacker with permissions to create content can inject arbitrary HTML and JS into website, which will be rendered/executed when visiting edited page.
This issue was fixed in version 1.4.6.
Affected products
-
Affected
- ≥ 0, < 1.4.6
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://cert.pl/en/posts/2026/03/CVE-2025-69236 third-party-advisoryThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-208701 Advisory
- https://raytha.com product
| Link | Providers | Tags |
|---|---|---|
| https://cert.pl/en/posts/2026/03/CVE-2025-69236 | third-party-advisoryThird Party Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-208701 | Advisory | |
| https://raytha.com | product |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner CERT-PL
Published Mar 16, 2026
Updated Mar 16, 2026
Reserved Dec 30, 2025
Link CVE-2025-69237
CISA Vulnrichment
Updated Mar 16, 2026
Red Hat
No data
GitHub
No data