PT-2026-25691 · Raytha+1 · Raytha

·

CVE-2025-69238

·

Published

2026-03-16

·

Updated

2026-03-16

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Raytha CMS versions prior to 1.4.6
Description Raytha CMS is susceptible to Cross-Site Request Forgery (CSRF) across multiple endpoints. An attacker can create a malicious website that, when visited by an authenticated user, automatically sends a POST request to an endpoint, potentially leading to unauthorized actions such as data deletion, because token verification is not enforced. The vulnerable endpoints are not specified.
Recommendations Update Raytha CMS to version 1.4.6 or later.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-69238

Affected Products

Raytha