logo

Vulnerabilities in Raytha software

ID: 8ed59920-79d6-50da-a896-b1dd9079e327

STIX ID: report--8ed59920-79d6-50da-a896-b1dd9079e327

Feed Name: CERT Polska

Threat Score
70/100

Date Published: 2026-03-16

Date Updated: 2026-04-19

Author: CERT Polska

...
...

CERT Polska disclosed multiple vulnerabilities in Raytha CMS (several CVEs published 16 March 2026) affecting versions before 1.4.6 (one issue fixed in 1.5.0). Issues include a dangerous code-injection capability in the Functions module (allowing instantiation of .NET components), multiple stored/reflected XSS flaws, CSRF, SSRF in theme import, host-header spoofing enabling password-reset token capture (account takeover), user enumeration, and no brute-force protections; patches have been released.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.