CVE-2025-69242
MEDIUMReflected XSS in Raytha CMS
Title source: cnaDescription
Raytha CMS is vulnerable to reflected XSS via the backToListUrl parameter. An attacker can craft a malicious URL which, when opened by authenticated victim, results in arbitrary JavaScript execution in the victim’s browser. This issue was fixed in version 1.4.6.
Scores
CVSS v3
6.1
EPSS
0.0004
EPSS Percentile
13.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (2)
Raytha/Raytha
< 1.4.6
raytha/raytha
< 1.4.6
Published
Mar 16, 2026
Tracked Since
Mar 16, 2026