VORANT. Threat Intelligence Sign in Get the full feed

Raytha CMS Patches Multiple Vulnerabilities

medium vulnerability technology

CERT Polska coordinated disclosure of 11 vulnerabilities in Raytha CMS, including stored/reflected XSS, CSRF, SSRF, account takeover, and brute-force flaws, fixed in versions 1.4.6 and 1.5.0.

CERT Polska disclosed a set of vulnerabilities affecting Raytha CMS, ranging from code execution risks in the platform's custom "Functions" module to multiple cross-site scripting, CSRF, SSRF, and authentication weaknesses. The most severe issue, CVE-2025-15540, allows privileged users to execute unsandboxed JavaScript that can instantiate .NET components, effectively enabling arbitrary code execution within the hosting environment. A chained header-spoofing and password-reset vulnerability (CVE-2025-69240) is particularly notable, as it allows an attacker who knows a victim's email address to hijack the password reset flow via a spoofed Host/X-Forwarded-Host header, capture the reset token, and take over the account.

Additional issues include several stored and reflected XSS vulnerabilities in post editing, page creation, profile editing, and URL parameters (CVE-2025-69236, -69237, -69241, -69242, -69245), a CSRF weakness affecting multiple endpoints lacking token verification (CVE-2025-69238), SSRF in the theme import feature (CVE-2025-69239), user enumeration in password reset (CVE-2025-69243), and a lack of brute-force protection on login (CVE-2025-69246). All vulnerabilities require some level of authenticated access or user interaction to exploit, and there is no indication of active exploitation in the wild.

Vendor has addressed CVE-2025-69243 in version 1.5.0, with all remaining vulnerabilities patched in version 1.4.6. Organizations running Raytha CMS should upgrade to the latest patched version. The report credits researchers Daniel Basta and Patryk Kieszek for identifying and reporting these issues through CERT Polska's coordinated vulnerability disclosure process.

Mentioned in this report

Vulnerabilities CVE-2025-15540CVE-2025-69236CVE-2025-69237CVE-2025-69238CVE-2025-69239CVE-2025-69240CVE-2025-69241CVE-2025-69242CVE-2025-69243CVE-2025-69245CVE-2025-69246

Source reporting: https://cert.pl/en/posts/2026/03/CVE-2025-69236

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free