LIVE · cybersecurity feed
Live wire
vendor

Raytha

11 CVEs published in the last four months. Exploited flaws first.

Critical1
High2
Medium7
Exploited (KEV)0

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2025-692469.8criticalraythaRaytha CMS does not have any brute force protection mechanism implemented.173d ago
CVE-2025-155408.8highraytha"Functions" module in Raytha CMS allows privileged users to write custom code to add functionality to application.173d ago
CVE-2025-692408.8highraythaRaytha CMS allows an attacker to spoof `X-Forwarded-Host` or `Host` headers to attacker controlled domain.173d ago
CVE-2025-692456.1mediumraythaRaytha CMS is vulnerable to Reflected XSS via returnUrl parameter in logon functionality.173d ago
CVE-2025-692426.1mediumraythaRaytha CMS is vulnerable to reflected XSS via the backToListUrl parameter.173d ago
CVE-2025-692415.4mediumraythaRaytha CMS is vulnerable to Stored XSS via FirstName and LastName parameters in profile editing functionality.173d ago
CVE-2025-692375.4mediumraythaRaytha CMS is vulnerable to Stored XSS via FieldValues[0].Value parameter in page creation functionality.173d ago
CVE-2025-692365.4mediumraythaRaytha CMS is vulnerable to Stored XSS via FieldValues[1].Value parameter in post editing functionality.173d ago
CVE-2025-692435.3mediumraythaRaytha CMS is vulnerable to User Enumeration in password reset functionality.173d ago
CVE-2025-692384.3mediumraythaRaytha CMS is vulnerable to Cross-Site Request Forgery across multiple endpoints.173d ago
CVE-2025-692392.7lowraythaRaytha CMS is vulnerable to Server-Side Request Forgery in the “Themes - Import from URL” feature.173d ago

Filter the full tracker by Raytha