VYPR
Vendor

Acymailing.com

Products
2
CVEs
7
Across products
7
Status
Private

Products

2

Recent CVEs

7
  • CVE-2023-39970CriAug 17, 2023
    risk 0.64cvss 9.8epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in AcyMailing component for Joomla. It allows remote code execution.

  • CVE-2026-94131HigSep 26, 2026
    risk 0.54cvss —epss —

    Joomla Extension - acymailing.com - Unauthenticated arbitrary file deletion in AcyMailing Enterprise extension < 11.1.0 - A subscriber could store a path in a file-type custom field and have AcyMailing delete that file when the field was cleared, including files outside the…

  • CVE-2015-7338HigMar 9, 2020
    risk 0.47cvss 7.2epss 0.01

    SQL Injection exists in AcyMailing Joomla Component before 4.9.5 via exportgeolocorder in a geolocation_longitude request to index.php.

  • CVE-2023-39971MedAug 17, 2023
    risk 0.40cvss 6.1epss 0.00

    Improper Neutralization of Input During Web Page Generation vulnerability in AcyMailing Enterprise component for Joomla allows XSS. This issue affects AcyMailing Enterprise component for Joomla: 6.7.0-8.6.3.

  • CVE-2023-39974MedAug 17, 2023
    risk 0.34cvss 5.3epss 0.01

    Exposure of Sensitive Information vulnerability in AcyMailing Enterprise component for Joomla. It allows unauthorized actors to get the number of subscribers in a specific list.

  • CVE-2023-39973MedAug 17, 2023
    risk 0.28cvss 4.3epss 0.00

    Improper Access Control vulnerability in AcyMailing Enterprise component for Joomla. It allows the unauthorized removal of attachments from campaigns.

  • CVE-2023-39972MedAug 17, 2023
    risk 0.28cvss 4.3epss 0.00

    Improper Access Control vulnerability in AcyMailing Enterprise component for Joomla. It allows unauthorized users to create new mailing lists.