shouldiuse.io

VERDICT

Should I use Raytha?

Open source .NET CMS with an easy-to-use admin interface - raytha.com

Depends. A fit for .NET teams who can self-host, audit code, and patch fast — the core is free and capable. Anyone without dedicated technical help should skip it: 10+ CVEs since 2025, including remote code execution, make it a liability for hands-off sites.

Confidence

Medium. Based on ~30 public sources; heavy on official pages and CVE databases. No independent review ratings found, so ease-of-use and support scores are partially inferred.

Ratings

  • Value for money
  • Ease of use
  • Feature depth
  • Support quality
  • Security posture

Pricing

Free

Open source

ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Free tierYes
Professional supportPaid, unpublished

Best for

  • .NET/C# developer teams
  • Nonprofit associations
  • Self-hosters wanting a lean Umbraco alternative

Not for

  • Non-technical teams wanting a set-and-forget website
  • Orgs with nobody to patch CVEs quickly
  • High-security or public-facing regulated deployments
  • Buyers expecting a WordPress-size plugin ecosystem

Gotchas - check before you buy

high

CVE-2025-15540 is remote code execution via the built-in functions feature — patch or disable immediately.

medium

Free core means you pay in ops time: hosting, upgrades, and security response are all on you.

medium

Support is paid and the company is tiny (~$225.9K funding); expect limited depth and SLAs.

medium

Young project with a small community — fewer extensions and answers when you hit problems.

Pros and cons

Pros

  • Free and open source
  • Self-host via Docker or one-click Railway deploy
  • Role-based admin permissions built in
  • Marketed as a leaner .NET alternative to Umbraco and WordPress
  • Paid professional support available from the vendor

Cons

  • 10+ CVEs since 2025, including remote code execution
  • RCE in the CMS functions feature (CVE-2025-15540)
  • Tiny team, ~$225.9K funding — limits patching and support bandwidth
  • No independent review ratings found to validate quality

Sources & method

Analyzed 9/26/2026 - 11 sources - Poor record: 10+ CVEs published 2025–2026, including RCE and SQL injection. Ongoing patch discipline is mandatory.

official x5review x2security x3news x1
  • CVE-2025-15540 — Remote code execution, RCE via the CMS 'functions' feature.
  • CVE-2026-12076 — SQL injection, SQL injection vulnerability in Raytha CMS.
  • CVE-2025-69238 — CSRF, Cross-site request forgery, CVSS 4.3.
  • CVE-2025-69237 through CVE-2025-69243 — disclosure batch, Multiple vulnerabilities disclosed March 2026, including CSRF and host-header spoofing.
  • CVE-2026-31904 — WebSocket API, Vulnerability in the WebSocket application programming interface.

Key stats

  • Value for money: 5/5

    Rating

  • Free

    Starting price

  • 11

    Sources

  • Analyzed

  • Value for money: 5/5. Free open source; support optional and paid
  • Ease of use: 3/5. Easy admin is vendor-claimed; no third-party reviews
  • Feature depth: 3/5. Templating engine and role permissions; no plugin marketplace
  • Support quality: 2/5. Paid support offered; very small vendor team
  • Security posture: 1/5. 10+ CVEs incl. RCE in two years
  • Free Price Open source, self-hosted
  • 10+ Known CVEs Published 2025–2026
  • $225.9K Funding Per Crunchbase
  • 2023 Founded Per founder's LinkedIn

Pricing

Open source

Free

  • Full CMS, self-hosted
  • Docker image or Railway one-click deploy
  • Community support

Professional support

Paid, unpublished

  • Expert guidance from vendor
  • Deployment and customization help

Security

Poor record: 10+ CVEs published 2025–2026, including RCE and SQL injection.

  • CVE-2025-15540 — Remote code executionRCE via the CMS 'functions' feature.⁶
  • CVE-2026-12076 — SQL injectionSQL injection vulnerability in Raytha CMS.⁷

Ongoing patch discipline is mandatory.

  • CVE-2025-69238 — CSRFCross-site request forgery, CVSS 4.3.
  • CVE-2025-69237 through CVE-2025-69243 — disclosure batchMultiple vulnerabilities disclosed March 2026, including CSRF and host-header spoofing.⁸
  • CVE-2026-31904 — WebSocket APIVulnerability in the WebSocket application programming interface.

What users say

Reddit activity is mostly the founder's own launch and release announcements; no independent review ratings were found.

Alternatives

Compare Raytha with each alternative.

  • Hosted site builders (Squarespace/Webflow)

    For non-developers who need a site with zero patching.

Full analysis

Based on ~30 public sources; heavy on official pages and CVE databases. No independent review ratings found, so ease-of-use and support scores are partially inferred.

Free .NET CMS for dev teams — but 10+ CVEs incl. RCE since 2025. Patch fast or pick another.

Methodology

Based on ~30 public sources; heavy on official pages and CVE databases. No independent review ratings found, so ease-of-use and support scores are partially inferred.

Sources

  1. official
  2. official
  3. official
  4. official
  5. official
  6. security
  7. security
  8. security
  9. review
  10. news
  11. review

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.