# CERT Polska coordinated disclosure of 11 vulnerabilities in Raytha CMS including code…

Published: 2026-03-16 · Severity: critical
Canonical: https://vorant.io/reports/fbd171d8-6721-49ad-a174-8d549e2aad7f/cert-polska-coordinated-disclosure-of-11-vulnerabilities-in-raytha-cms

> CERT Polska coordinated disclosure of 11 vulnerabilities in Raytha CMS including code execution, multiple XSS flaws, CSRF, SSRF, and authentication weaknesses; patched in versions 1.4.6 and 1.5.0.

CERT Polska coordinated the responsible disclosure of multiple critical and high-severity vulnerabilities affecting Raytha CMS, an open-source content management system. The most severe issue is CVE-2025-15540, which allows privileged users to execute arbitrary .NET code through the 'Functions' module due to lack of sandboxing, enabling complete compromise of the hosting environment. Additional vulnerabilities include a host header injection flaw (CVE-2025-69240) that enables account takeover via password reset token theft, and server-side request forgery (CVE-2025-69239) in the theme import functionality.

The vulnerability set also encompasses eight stored and reflected cross-site scripting (XSS) issues across multiple parameters in post editing, page creation, profile management, and authentication flows. Cross-site request forgery (CSRF) protection is missing across multiple endpoints (CVE-2025-69238), allowing attackers to perform unauthorized actions on behalf of authenticated users. Authentication security is further weakened by user enumeration in password reset (CVE-2025-69243) and complete absence of brute-force protection (CVE-2025-69246).

The vendor has released patches addressing these issues across two versions: CVE-2025-69243 was fixed in version 1.5.0, while the remaining ten vulnerabilities were addressed in version 1.4.6. Organizations running Raytha CMS should immediately upgrade to the latest patched version. The vulnerabilities were discovered by Daniel Basta with support from Patryk Kieszek, following CERT Polska's coordinated vulnerability disclosure process.

## Mentioned in this report

- Vulnerabilities: CVE-2025-15540, CVE-2025-69236, CVE-2025-69237, CVE-2025-69238, CVE-2025-69239, CVE-2025-69240, CVE-2025-69241, CVE-2025-69242, CVE-2025-69243, CVE-2025-69245, CVE-2025-69246

Source reporting: https://cert.pl/en/posts/2026/03/CVE-2025-69236

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/fbd171d8-6721-49ad-a174-8d549e2aad7f/cert-polska-coordinated-disclosure-of-11-vulnerabilities-in-raytha-cms.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
