PT-2026-25692 · Raytha+1 · Raytha
Daniel Basta
·
Published
2026-03-16
·
Updated
2026-03-16
·
CVE-2025-69239
CVSS v4.0
5.1
Medium
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L |
Name of the Vulnerable Software and Affected Versions
Raytha CMS versions prior to 1.4.6
Description
Raytha CMS has a Server-Side Request Forgery (SSRF) issue in the “Themes - Import from URL” feature. An attacker with high privileges can provide a URL to redirect server-side HTTP requests. The vulnerable feature allows an attacker to control the destination of server-side requests, potentially leading to unauthorized access to internal resources or data exfiltration.
Recommendations
Update Raytha CMS to version 1.4.6 or later.
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Raytha