CVE-2025-15540Disclosure(raytha / raytha)

LOWCVSS 8.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

"Functions" module in Raytha CMS allows privileged users to write custom code to add functionality to application. Due to a lack of sandboxing or access restrictions, JavaScript code executed through Raytha’s “functions” feature can instantiate .NET components and perform arbitrary operations within the application’s hosting environment. This issue was fixed in version 1.4.6.

0.0/ 10 priority

Sources & remediation

Other references
Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • raytha

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
raytha

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-16: 2Technical Details · 2026-03-16: 203-16
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • Misbar | مسبار@MisbarSec
    Disclosure

    📌 ثغرات أمنية حرجة في برنامج Raytha تم الكشف عن مجموعة من الثغرات الأمنية، منها CVE-2025-15540 وCVE-2025-69236، التي تستهدف برنامج Raytha وتُصنف ضمن فئة (Improper Control). تؤثر هذه الثغرات على جميع الإصدارات السابقة للإصدار 1.4.6. 🔗 للمزيد: https://cert.pl/en/posts/2026/03/CVE-2025-69236/ #Raytha #الامن_السيبراني #cybersecuritytips

    Post summary

    A CERT advisory announces critical vulnerabilities CVE-2025-15540 and CVE-2025-69236 in Raytha, affecting all versions older than 1.4.6.

    01040480
    70 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-15540 "Functions" module in Raytha CMS allows privileged users to write custom code to add functionality to application. Due to a lack of sandboxing or access restrictions,… https://www.cve.org/CVERecord?id=CVE-2025-15540

    Post summary

    The CVE-2025-15540 vulnerability in Raytha CMS allows privileged users to write arbitrary custom code because the Functions module lacks sandboxing or proper access restrictions.

    00000146
    56.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appraytharaytha---

Explore more