← back
CVE-2025-69243

User enumeration in Raytha CMS

CVSS 6.9 MEDIUMEPSS 0.3%CWE-204
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.9EPSS 0.3%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
16 Mar 2026Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Raytha CMS is vulnerable to User Enumeration in password reset functionality. Difference in messages could allow an attacker to determine if the login is valid or not, enabling a brute force attack with valid logins. This issue was fixed in version 1.5.0.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Affected products
Raytha · Raytha

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →