LIVE · cybersecurity feed
Live wire
cve recordmedium

CVE-2025-69241

raytha · raytha

Published
CVSS5.4
Severitymedium
WeaknessCWE-79
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Description

Raytha CMS is vulnerable to Stored XSS via FirstName and LastName parameters in profile editing functionality. Authenticated attacker can inject arbitrary HTML and JS into website, which will be rendered/executed when visiting edited page. This issue was fixed in version 1.4.6.

References

← Back to the CVE Tracker

Our coverage of CVE-2025-69241

No stories yet. This page updates automatically when we publish reporting that references CVE-2025-69241.