๐Ÿ” CVE Alert

CVE-2026-94132

UNKNOWN 0.0

Joomla Extension - acymailing.com - Remote Code Execution vulnerability in mailbox action feature in AcyMailing Enterprise extension < 11.1.0

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Joomla Extension - acymailing.com - Remote Code Execution vulnerability in mailbox action feature in AcyMailing Enterprise extension < 11.1.0 - MIME parts of incoming emails were saved to media/com_acym/upload/ with no extension check, so anyone who could email the monitored mailbox could write a PHP file into the web root.

CWE CWE-434
Vendor acymailing.com
Product acymailing enterprise extension for joomla
Published Sep 26, 2026
Stay Ahead of the Next One

Get instant alerts for acymailing.com acymailing enterprise extension for joomla

Be the first to know when new unknown vulnerabilities affecting acymailing.com acymailing enterprise extension for joomla are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

acymailing.com / AcyMailing Enterprise extension for Joomla
1.0.0-11.0.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
acymailing.com: https://www.acymailing.com/