CVE-2025-69246

Publication date

2026-03-16 11:54:50

Family

CERT-PL

State

PUBLISHED

Description

Raytha CMS does not have any brute force protection mechanism implemented. It allows an attacker to send multiple automated logon requests without triggering lockout, throttling, or step-up challenges. This issue was fixed in version 1.4.6.