{"id":"CVE-2026-56292","title":"A SQLi vulnerability in AcyMailing component < 10.11.1 for Joomla was discovered","summary":"A SQLi vulnerability in AcyMailing component < 10.11.1 for Joomla was discovered. Exploiting this flaw can lead to unauthorized database access and data leakage.","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-89"],"vendor":"acymailing","product":"acymailing","affected":["acymailing >= 6.0.0, < 10.11.1"],"patched":["acymailing 10.11.1"],"published":"2026-07-09","updated":"2026-07-10","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-56292","references":[{"url":"https://mysites.guru/blog/acymailing-sql-injection-disclosure/","label":"security@joomla.org"},{"url":"https://www.acymailing.com/","label":"security@joomla.org"}],"tags":["nvd","exploit-available"],"epss":0.01381,"epssPercentile":0.70955,"ingestedAt":"2026-07-11T20:15:25.644Z","exploits":{"github":1,"githubRepos":["https://github.com/nullwhisper/CVE-2026-56292-AcyMailing-SQLi"],"nuclei":["CVE-2026-56292"],"checkedAt":"2026-09-24T07:53:08.563Z"},"exploitAvailable":true,"slug":"CVE-2026-56292","body":"## Overview\n\nA SQLi vulnerability in AcyMailing component < 10.11.1 for Joomla was discovered. Exploiting this flaw can lead to unauthorized database access and data leakage.\n\n## Affected\n\n- `acymailing >= 6.0.0, < 10.11.1`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `acymailing 10.11.1`","depth":"midnight","depthScore":54,"depthScoreParts":{"impact":41.3,"likelihood":0.3,"exploitation":12,"ransomware":0},"changes":[{"seq":5360,"id":"CVE-2026-56292","ts":1788887272146,"field":"exploit_available","old":"false","new":"true"},{"seq":4243,"id":"CVE-2026-56292","ts":1788886387063,"field":"exploit_available","old":"true","new":"false"},{"seq":2999,"id":"CVE-2026-56292","ts":1788883050438,"field":"exploit_available","old":"false","new":"true"},{"seq":2028,"id":"CVE-2026-56292","ts":1788882455046,"field":"exploit_available","old":"true","new":"false"},{"seq":1102,"id":"CVE-2026-56292","ts":1788881891966,"field":"exploit_available","old":"false","new":"true"}]}