Raytha CMS Server-Side Request Forgery Vulnerability in Themes Import Feature

Vulnerability

A Server-Side Request Forgery (SSRF) vulnerability has been identified in Raytha CMS versions prior to 1.4.6. The issue arises in the 'Themes - Import from URL' feature, where an attacker with high privileges can manipulate server-side HTTP requests by providing a malicious URL. This vulnerability could potentially be exploited to access internal resources or perform actions on behalf of the server.

Impact

Exploitation of this vulnerability allows for Server-Side Request Forgery, where an attacker can make the server perform HTTP requests to arbitrary locations, potentially leading to the exposure of sensitive information or internal resources.

Remediation

Users can upgrade to Raytha CMS version 1.4.6 or later to address this vulnerability.

Added: Mar 16, 2026, 2:41 PM
Updated: Mar 16, 2026, 2:41 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
4.2
remediation
0.0
relevance
4.0
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.