Vulnerability index

Browse CVEs

9 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Raytha CRITICAL 9.8
CVE-2025-69246

Raytha CMS does not have any brute force protection mechanism implemented. It allows an attacker to send multiple automated logon requests without tr…

Fix: 1.4.6+
Fix from $2,300 2026-03-16
Raytha HIGH 8.8
CVE-2025-69240

Raytha CMS allows an attacker to spoof `X-Forwarded-Host` or `Host` headers to attacker controlled domain. The attacker (who knows the victim's email…

Fix: 1.4.6+
Fix from $1,950 2026-03-16
Raytha MEDIUM 6.1
CVE-2025-69242

Raytha CMS is vulnerable to reflected XSS via the backToListUrl parameter. An attacker can craft a malicious URL which, when opened by authenticated …

Fix: 1.4.6+
Fix from $1,600 2026-03-16
Raytha MEDIUM 6.1
CVE-2025-69245

Raytha CMS is vulnerable to Reflected XSS via returnUrl parameter in logon functionality. An attacker can craft a malicious URL which, when opened by…

Fix: 1.4.6+
Fix from $1,600 2026-03-16
Raytha MEDIUM 5.4
CVE-2025-69241

Raytha CMS is vulnerable to Stored XSS via FirstName and LastName parameters in profile editing functionality. Authenticated attacker can inject arbi…

Fix: 1.4.6+
Fix from $1,600 2026-03-16
Raytha MEDIUM 5.3
CVE-2025-69243

Raytha CMS is vulnerable to User Enumeration in password reset functionality. Difference in messages could allow an attacker to determine if the logi…

Fix: 1.5.0+
Fix from $1,600 2026-03-16
Raytha MEDIUM 5.4
CVE-2025-69236

Raytha CMS is vulnerable to Stored XSS via FieldValues[1].Value parameter in post editing functionality. Authenticated attacker with permissions to e…

Fix: 1.4.6+
Fix from $1,600 2026-03-16
Raytha MEDIUM 5.4
CVE-2025-69237

Raytha CMS is vulnerable to Stored XSS via FieldValues[0].Value parameter in page creation functionality. Authenticated attacker with permissions to …

Fix: 1.4.6+
Fix from $1,600 2026-03-16
Raytha HIGH 8.8
CVE-2025-15540

"Functions" module in Raytha CMS allows privileged users to write custom code to add functionality to application. Due to a lack of sandboxing or acc…

Fix: 1.4.6+
Fix from $1,950 2026-03-16