Acyba
4 CVEs tracked since 2018. Since Mar 2018, none of them reached CISA KEV.
Acyba CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2018-03 | 2 | 0 |
| 2018-04 | null or fewer | |
| 2018-05 | null or fewer | |
| 2018-06 | null or fewer | |
| 2018-07 | null or fewer | |
| 2018-08 | null or fewer | |
| 2018-09 | null or fewer | |
| 2018-10 | null or fewer | |
| 2018-11 | null or fewer | |
| 2018-12 | null or fewer | |
| 2019-01 | null or fewer | |
| 2019-02 | null or fewer | |
| 2019-03 | null or fewer | |
| 2019-04 | null or fewer | |
| 2019-05 | null or fewer | |
| 2019-06 | null or fewer | |
| 2019-07 | null or fewer | |
| 2019-08 | null or fewer | |
| 2019-09 | null or fewer | |
| 2019-10 | null or fewer | |
| 2019-11 | null or fewer | |
| 2019-12 | null or fewer | |
| 2020-01 | null or fewer | |
| 2020-02 | null or fewer | |
| 2020-03 | 2 | 0 |
Products
The products that kept showing up in Acyba's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 11 most recently published vulnerabilities affecting Acyba.
- CVE-2026-77807AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress <= 11.0.4 - Unauthenticated Arbitrary File Read via 'user[name]' Parameter7.5
- CVE-2026-15426AcyMailing <= 10.11.1 - Authenticated (Subscriber+) Missing Authorization to Account Takeover via Notification Template Update8.8
- CVE-2026-12170AcyMailing <= 10.10.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'alignment' Attribute6.4
- CVE-2026-5200AcyMailing <= 10.8.2 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation via 'acymailing_router'8.8
- CVE-2026-3614AcyMailing 9.11.0 - 10.8.1 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation8.8
- CVE-2024-7384AcyMailing <= 9.7.2 - Authenticated (Subscriber+) Arbitrary File Upload via acym_extractArchive Function7.5
- CVE-2023-39970Extension - acymailing.com - RCE in AcyMailing component for Joomla 6.7.0-8.5.09.8
- CVE-2020-10934Acyba AcyMailing before 6.9.2 mishandles file uploads by admins.7.2
- CVE-2015-7338SQL Injection exists in AcyMailing Joomla Component before 4.9.5 via exportgeolocorder in a geolocation_longitude request to index.php.7.2
- CVE-2018-9106CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in the Acyba AcySMS extension before 3.5.1 for Joomla! via a value that is mishandled in a CSV export.8.8
- CVE-2018-9107CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in the Acyba AcyMailing extension before 5.9.6 for Joomla! via a value that is mishandled in a CSV export.8.8
The record
- Peak rank
- #154 in Mar 2018
- Busiest month shown
- Mar 2018, 2 CVEs
- Months with a KEV entry
- 0 since Mar 2018
- Monthly snapshots
- 2 since 2018