CVE-2025-69243

MEDIUM

User enumeration in Raytha CMS

Title source: cna
STIX 2.1

Description

Raytha CMS is vulnerable to User Enumeration in password reset functionality. Difference in messages could allow an attacker to determine if the login is valid or not, enabling a brute force attack with valid logins. This issue was fixed in version 1.5.0.

References (2)

Core 2
Core References
Third Party Advisory third-party-advisory
https://cert.pl/en/posts/2026/03/CVE-2025-69236
Product product
https://raytha.com

Scores

CVSS v3 5.3
EPSS 0.0028
EPSS Percentile 19.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-204
Status published
Products (2)
Raytha/Raytha < 1.5.0
raytha/raytha < 1.5.0
Published Mar 16, 2026
Tracked Since Mar 16, 2026