Unrated severityNVD Advisory· Published Mar 16, 2026· Updated Mar 16, 2026
Reflected XSS in Raytha CMS
CVE-2025-69242
Description
Raytha CMS is vulnerable to reflected XSS via the backToListUrl parameter. An attacker can craft a malicious URL which, when opened by authenticated victim, results in arbitrary JavaScript execution in the victim’s browser.
This issue was fixed in version 1.4.6.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- cert.pl/en/posts/2026/03/CVE-2025-69236mitrethird-party-advisory
- raytha.commitreproduct
News mentions
0No linked articles in our index yet.