Vulnerability index

Browse CVEs

9 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Acymailing HIGH 7.5
CVE-2026-56292

Joomla Extension - acymailing.com - SQL Injection in AcyMailing extension < 10.11.1 - A SQLi vulnerability in AcyMailing component < 10.11.1 for Joom…

Fix: 10.11.1+
Fix from $1,950 2026-07-09
Acymailing HIGH 8.8
CVE-2024-7384

The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to arbitrary file u…

Fix: 9.8.0+
Fix from $1,950 2024-08-22
Acymailing MEDIUM 6.1
CVE-2023-41867

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in AcyMailing Newsletter Team AcyMailing plugin <= 8.6.2 versions.

Fix: 8.6.3+
Fix from $1,600 2023-09-25
Acymailing MEDIUM 6.1
CVE-2023-39971

Improper Neutralization of Input During Web Page Generation vulnerability in AcyMailing Enterprise component for Joomla allows XSS. This issue affect…

Fix: 8.7.0+
Fix from $1,600 2023-08-17
Acymailing MEDIUM 5.3
CVE-2023-39974

Exposure of Sensitive Information vulnerability in AcyMailing Enterprise component for Joomla. It allows unauthorized actors to get the number of sub…

Fix: 8.7.0+
Fix from $1,600 2023-08-17
Acymailing CRITICAL 9.8
CVE-2023-28731

AnyMailing Joomla Plugin is vulnerable to unauthenticated remote code execution, when being granted access to the campaign's creation on front-office…

Fix: 8.3.0+
Fix from $2,300 2023-03-30
Acymailing HIGH 7.5
CVE-2023-28732

Missing access control in AnyMailing Joomla Plugin allows to list and access files containing sensitive information from the plugin itself and access…

Fix: 8.3.0+
Fix from $1,950 2023-03-30
Acymailing MEDIUM 6.1
CVE-2023-28733

AnyMailing Joomla Plugin is vulnerable to stored cross site scripting (XSS) in templates and emails of AcyMailing, exploitable without authentication…

Fix: 8.3.0+
Fix from $1,600 2023-03-30
Acymailing MEDIUM 6.1
CVE-2021-24288

When subscribing using AcyMailing, the 'redirect' parameter isn't properly sanitized. Turning the request from POST to GET, an attacker can craft a l…

Fix: 7.5.0+
Fix from $1,600 2021-05-17