Raytha
Raytha is a headless content management system positioned in the modestly represented vendor segment, with its vulnerability exposure concentrated in a single product. The recurring weakness classes—cross-site scripting, cross-site request forgery, code injection, and authentication bypass patterns—reflect the input-handling and session-management demands typical of web-based CMS platforms, and the vendor's disclosures carry a moderate tendency toward serious severity outcomes. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
Trends Over Time
The number and severity of CVEs published that impact products developed by Raytha over time
Products(1 total)
Top CVEs
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-69246CRITICAL Raytha CMS does not have any brute force protection mechanism implemented. It allows an attacker to send multiple automated logon requests without triggering lockout, throttling, o | Mar 16, 2026 | 9.8 | 31 | NO | NO |
CVE-2025-15540HIGH "Functions" module in Raytha CMS allows privileged users to write custom code to add functionality to application. Due to a lack of sandboxing or access restrictions, JavaScript co | Mar 16, 2026 | 8.8 | 28 | NO | NO |
CVE-2025-69240HIGH Raytha CMS allows an attacker to spoof `X-Forwarded-Host` or `Host` headers to attacker controlled domain. The attacker (who knows the victim's email address) can force the server | Mar 16, 2026 | 8.8 | 27 | NO | NO |
CVE-2025-69245MEDIUM Raytha CMS is vulnerable to Reflected XSS via returnUrl parameter in logon functionality. An attacker can craft a malicious URL which, when opened by the authenticated victim, resu | Mar 16, 2026 | 6.1 | 22 | NO | NO |
CVE-2025-69242MEDIUM Raytha CMS is vulnerable to reflected XSS via the backToListUrl parameter. An attacker can craft a malicious URL which, when opened by authenticated victim, results in arbitrary Ja | Mar 16, 2026 | 6.1 | 21 | NO | NO |
CVE-2025-69241MEDIUM Raytha CMS is vulnerable to Stored XSS via FirstName and LastName parameters in profile editing functionality. Authenticated attacker can inject arbitrary HTML and JS into website, | Mar 16, 2026 | 5.4 | 21 | NO | NO |
CVE-2025-69243MEDIUM Raytha CMS is vulnerable to User Enumeration in password reset functionality. Difference in messages could allow an attacker to determine if the login is valid or not, enabling a b | Mar 16, 2026 | 5.3 | 20 | NO | NO |
CVE-2025-69236MEDIUM Raytha CMS is vulnerable to Stored XSS via FieldValues[1].Value parameter in post editing functionality. Authenticated attacker with permissions to edit posts can inject arbitrary | Mar 16, 2026 | 5.4 | 20 | NO | NO |
CVE-2025-69237MEDIUM Raytha CMS is vulnerable to Stored XSS via FieldValues[0].Value parameter in page creation functionality. Authenticated attacker with permissions to create content can inject arbit | Mar 16, 2026 | 5.4 | 19 | NO | NO |
CVE-2025-69238MEDIUM Raytha CMS is vulnerable to Cross-Site Request Forgery across multiple endpoints. Attacker can craft special website, which when visited by the authenticated victim, will automatic | Mar 16, 2026 | 4.3 | 17 | NO | NO |
CVE Severity & Scoring
Exploit Exposure
Signals from CVEs in this vendor scope (11 CVEs).
Social Chatter
An overview of all social media posts that mention a CVE ID that affects a product developed by Raytha.
Media Mentions
Media articles that mention a CVE ID that affects a product developed by Raytha — matched by CVE ID, not by vendor name.