acymailing.com has 2 CVEs on record. 2 were published in the last 90 days. The median CVSS is 8.9 (high), with 1 rated critical.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 8.9
- Publish → KEV
- —
- Last 90 days
- 2 prev 0
Products
- AcyMailing Enterprise extension for Joomla 1
- AcyMailing extension for Joomla 1
Worst active — by depth score
CVE-2026-94132Critical· 9.5Joomla Extension - acymailing.com - Remote Code Execution vulnerability in mailbox action feature in AcyMailing Enterprise extension < 11.1.0 - MIME parts of incoming emails were saved to media/com_acym/upload/ with no extension check, s…52CVE-2026-94131High· 8.3Joomla Extension - acymailing.com - Unauthenticated arbitrary file deletion in AcyMailing Enterprise extension < 11.1.0 - A subscriber could store a path in a file-type custom field and have AcyMailing delete that file when the field was…46
acymailing.com vulnerabilities
CVEs affecting acymailing.com, newest first. Open any entry for full detail, references, and exploit status.
2 CVEsRSS
CVE-2026-94132Critical· 9.5Joomla Extension - acymailing.com - Remote Code Execution vulnerability in mailbox action feature in AcyMailing Enterprise extension < 11.1.0 - MIME parts of incoming emails were saved to media/com_acym/upload/ with no extension check, s…
Joomla Extension - acymailing.com - Remote Code Execution vulnerability in mailbox action feature in AcyMailing Enterprise extension < 11.1.0 - MIME parts of incoming emails were saved to media/com_acym/upload/ with no extension check, s…
CVE-2026-94131High· 8.3Joomla Extension - acymailing.com - Unauthenticated arbitrary file deletion in AcyMailing Enterprise extension < 11.1.0 - A subscriber could store a path in a file-type custom field and have AcyMailing delete that file when the field was…
Joomla Extension - acymailing.com - Unauthenticated arbitrary file deletion in AcyMailing Enterprise extension < 11.1.0 - A subscriber could store a path in a file-type custom field and have AcyMailing delete that file when the field was…