Unrated severityNVD Advisory· Published Mar 16, 2026· Updated Mar 16, 2026
Stored XSS in Raytha CMS
CVE-2025-69237
Description
Raytha CMS is vulnerable to Stored XSS via FieldValues[0].Value parameter in page creation functionality. Authenticated attacker with permissions to create content can inject arbitrary HTML and JS into website, which will be rendered/executed when visiting edited page.
This issue was fixed in version 1.4.6.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- cert.pl/en/posts/2026/03/CVE-2025-69236mitrethird-party-advisory
- raytha.commitreproduct
News mentions
0No linked articles in our index yet.