VYPR
Medium severity5.4NVD Advisory· Published Mar 16, 2026· Updated Jun 17, 2026

CVE-2025-69241

CVE-2025-69241

Description

Raytha CMS is vulnerable to Stored XSS via FirstName and LastName parameters in profile editing functionality. Authenticated attacker can inject arbitrary HTML and JS into website, which will be rendered/executed when visiting edited page.

This issue was fixed in version 1.4.6.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • Raytha/Raytha3 versions
    cpe:2.3:a:raytha:raytha:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:raytha:raytha:*:*:*:*:*:*:*:*range: <1.4.6
    • (no CPE)range: >=1.4.6
    • (no CPE)range: 0
  • Raytha/CMSllm-create
    Range: >=1.4.6

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.