CVE-2025-15540 PUBLISHED

Authenticated RCE in Raytha CMS

Assigner: CERT-PL
Reserved: 19.01.2026 Published: 16.03.2026 Updated: 16.03.2026

"Functions" module in Raytha CMS allows privileged users to write custom code to add functionality to application. Due to a lack of sandboxing or access restrictions, JavaScript code executed through Raytha’s “functions” feature can instantiate .NET components and perform arbitrary operations within the application’s hosting environment.

This issue was fixed in version 1.4.6.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L
CVSS Score: 8.6

Product Status

Vendor Raytha
Product Raytha
Versions Default: unaffected
  • affected from 0 to 1.4.6 (excl.)

Credits

  • Daniel Basta finder

References

Problem Types

  • CWE-94 Improper Control of Generation of Code ('Code Injection') CWE

Impacts

  • CAPEC-242 Code Injection