CVE-2025-69241Disclosure(raytha / raytha)

LOWCVSS 5.4 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch raytha raytha systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Raytha CMS is vulnerable to Stored XSS via FirstName and LastName parameters in profile editing functionality. Authenticated attacker can inject arbitrary HTML and JS into website, which will be rendered/executed when visiting edited page. This issue was fixed in version 1.4.6.

0.5/ 10 priority

Sources & remediation

Other references
Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • raytha

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
raytha

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-16: 3Patch / Workaround · 2026-03-16: 1Technical Details · 2026-03-16: 303-16
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • Fernando Karl@fernandokarl
    Patch

    🚨 Atenção, administradores do Raytha CMS! Uma vulnerabilidade *Stored XSS* foi descoberta em campos de perfil. Atualize para a v1.4.6 imediatamente para evitar execuções de scripts maliciosos. Proteja seus usuários! 🔒💻 #CyberSecurity #XSS #RaythaCMS https://www.tenable.com/cve/CVE-2025-69241

    Post summary

    Raytha CMS administrators are warned of a stored XSS flaw in profile fields and urged to upgrade to v1.4.6 to block malicious script execution.

    00000120
    257 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-69241 Raytha CMS is vulnerable to Stored XSS via FirstName and LastName parameters in profile editing functionality. Authenticated attacker can inject arbitrary HTML and JS… https://www.cve.org/CVERecord?id=CVE-2025-69241

    Post summary

    The text announces that Raytha CMS has a stored XSS vulnerability (CVE-2025-69241) where authenticated users can inject arbitrary HTML and JavaScript via profile fields.

    00000135
    56.7K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2025-69241 - Stored XSS in Raytha CMS Intel Report: https://ift.tt/AczyQwK

    Post summary

    The alert announces CVE-2025-69241, a stored XSS vulnerability in Raytha CMS, and provides a link to an Intel report for further details.

    0000079
    335 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appraytharaytha---

Explore more