Loading product vulnerabilities…
Total
3
Critical
0
High
2
Medium
0
CISA KEV
0
Acyba AcyMailing before 6.9.2 mishandles file uploads by admins.
SQL Injection exists in AcyMailing Joomla Component before 4.9.5 via exportgeolocorder in a geolocation_longitude request to index.php.
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in the Acyba AcyMailing extension before 5.9.6 for Joomla! via a value that is mishandled in a CSV export.