VulnerabilityAnalyzed
CVE-2025-69238
Raytha CMS is vulnerable to Cross-Site Request Forgery across multiple endpoints.
MEDIUM 6.9EPSS 0.12%
Does this matter?
Lower severity and a low EPSS score (0.12%). Track it; it rarely justifies an emergency change on its own.
Description
Raytha CMS is vulnerable to Cross-Site Request Forgery across multiple endpoints. Attacker can craft special website, which when visited by the authenticated victim, will automatically send POST request to the endpoint (e. x. deletion of the data) without enforcing token verification. This issue was fixed in version 1.4.6.
- CVSS 4.0
- 6.9 MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.12% probability · 2th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-352
- Affected
- raytha/raytha
- Source
- cvd@cert.pl
References
- https://cert.pl/en/posts/2026/03/CVE-2025-69236Third Party Advisory
- https://raytha.comProduct
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.