← back
CVE-2025-69246

Lack of bruteforce protection in Raytha CMS

CVSS 6.9 MEDIUMEPSS 0.4%CWE-307
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.9EPSS 0.4%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
16 Mar 2026Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Raytha CMS does not have any brute force protection mechanism implemented. It allows an attacker to send multiple automated logon requests without triggering lockout, throttling, or step-up challenges. This issue was fixed in version 1.4.6.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
Affected products
Raytha · Raytha

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →