VYPR

AcyMailing Enterprise

by Acymailing

CVEs (5)

  • CVE-2026-94132CriSep 26, 2026
    risk 0.62cvss —epss —

    Joomla Extension - acymailing.com - Remote Code Execution vulnerability in mailbox action feature in AcyMailing Enterprise extension < 11.1.0 - MIME parts of incoming emails were saved to media/com_acym/upload/ with no extension check, so anyone who could email the monitored…

  • CVE-2023-39971MedAug 17, 2023
    risk 0.40cvss 6.1epss 0.00

    Improper Neutralization of Input During Web Page Generation vulnerability in AcyMailing Enterprise component for Joomla allows XSS. This issue affects AcyMailing Enterprise component for Joomla: 6.7.0-8.6.3.

  • CVE-2023-39974MedAug 17, 2023
    risk 0.34cvss 5.3epss 0.01

    Exposure of Sensitive Information vulnerability in AcyMailing Enterprise component for Joomla. It allows unauthorized actors to get the number of subscribers in a specific list.

  • CVE-2023-39973MedAug 17, 2023
    risk 0.28cvss 4.3epss 0.00

    Improper Access Control vulnerability in AcyMailing Enterprise component for Joomla. It allows the unauthorized removal of attachments from campaigns.

  • CVE-2023-39972MedAug 17, 2023
    risk 0.28cvss 4.3epss 0.00

    Improper Access Control vulnerability in AcyMailing Enterprise component for Joomla. It allows unauthorized users to create new mailing lists.