<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 04:46:15 +0000</lastBuildDate>
    <item>
      <title>CVE-2025-69238 — Cross-Site Request Forgery in Raytha CMS</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2025-69238</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Raytha&lt;/p&gt;
&lt;p&gt;Raytha CMS is vulnerable to Cross-Site Request Forgery across multiple endpoints. Attacker can craft special website, which when visited by the authenticated victim, will automatically send POST request to the endpoint (e. x. deletion of the data) without enforcing token verification.&lt;/p&gt;
&lt;p&gt;This issue was fixed in version 1.4.6.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Raytha&lt;/p&gt;
&lt;p&gt;Raytha CMS is vulnerable to Cross-Site Request Forgery across multiple endpoints. Attacker can craft special website, which when visited by the authenticated victim, will automatically send POST request to the endpoint (e. x. deletion of the data) without enforcing token verification.&lt;/p&gt;
&lt;p&gt;This issue was fixed in version 1.4.6.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2025-69238</guid>
    </item>
  </channel>
</rss>
