PT-2026-25691 · Raytha+1 · Raytha

Daniel Basta

·

Published

2026-03-16

·

Updated

2026-03-16

·

CVE-2025-69238

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Raytha CMS versions prior to 1.4.6
Description Raytha CMS is susceptible to Cross-Site Request Forgery (CSRF) across multiple endpoints. An attacker can create a malicious website that, when visited by an authenticated user, automatically sends a POST request to an endpoint, potentially leading to unauthorized actions such as data deletion, because token verification is not enforced. The vulnerable endpoints are not specified.
Recommendations Update Raytha CMS to version 1.4.6 or later.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2025-69238

Affected Products

Raytha