PT-2026-25691 · Raytha · Raytha

Daniel Basta

·

Published

2026-03-16

·

Updated

2026-03-16

·

CVE-2025-69238

CVSS v4.0
6.9
VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
🚨 CVE-2025-69238 Raytha CMS is vulnerable to Cross-Site Request Forgery across multiple endpoints. Attacker can craft special website, which when visited by the authenticated victim, will automatically send POST request to the endpoint (e. x. deletion of the data) without enforcing token verification. 
This issue was fixed in version 1.4.6.
🎖@cveNotify

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2025-69238

Affected Products

Raytha