Vulnerability Description
Raytha CMS is vulnerable to Stored XSS via FieldValues[0].Value parameter in page creation functionality. Authenticated attacker with permissions to create content can inject arbitrary HTML and JS into website, which will be rendered/executed when visiting edited page. This issue was fixed in version 1.4.6.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Raytha | Raytha | < 1.4.6 |
Related Weaknesses (CWE)
References
- https://cert.pl/en/posts/2026/03/CVE-2025-69236Third Party Advisory
- https://raytha.comProduct
FAQ
What is CVE-2025-69237?
CVE-2025-69237 is a vulnerability with a CVSS score of 5.4 (MEDIUM). Raytha CMS is vulnerable to Stored XSS via FieldValues[0].Value parameter in page creation functionality. Authenticated attacker with permissions to create content can inject arbitrary HTML and JS int...
How severe is CVE-2025-69237?
CVE-2025-69237 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-69237?
Check the references section above for vendor advisories and patch information. Affected products include: Raytha Raytha.