
CVE-2025-69242 Raytha CMS is vulnerable to reflected XSS via the backToListUrl parameter. An attacker can craft a malicious URL which, when opened by authenticated victim, results i… https://www.cve.org/CVERecord?id=CVE-2025-69242
Post summary
A new reflected XSS vulnerability (CVE‑2025‑69242) has been disclosed in Raytha CMS, allowing attackers to inject malicious scripts via the backToListUrl parameter when authenticated users visit crafted URLs.
