PT-2026-25688 · Raytha · Raytha

Daniel Basta

·

Published

2026-03-16

·

Updated

2026-03-16

·

CVE-2025-15540

CVSS v4.0
8.6
VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L
"Functions" module in Raytha CMS allows privileged users to write custom code to add functionality to application. Due to a lack of sandboxing or access restrictions, JavaScript code executed through Raytha’s “functions” feature can instantiate .NET components and perform arbitrary operations within the application’s hosting environment.
This issue was fixed in version 1.4.6.

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-15540

Affected Products

Raytha