| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-3614 | AcyMailing 9.11.0 - 10.8.1 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation | acyba | AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress | High | 8.8 | 2026-04-16 05:29:54 | Deep Dive |
| CVE-2025-24617 | WordPress AcyMailing Plugin < 9.11.1 - Reflected Cross Site Scripting (XSS) vulnerability | AcyMailing Newsletter Team | AcyMailing SMTP Newsletter | High | 7.1 | 2025-02-14 12:44:35 | Deep Dive |
| CVE-2024-7384 | AcyMailing <= 9.7.2 - Authenticated (Subscriber+) Arbitrary File Upload via acym_extractArchive Function | acyba | AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress | High | 7.5 | 2024-08-22 02:02:02 | Deep Dive |
| CVE-2023-41867 | WordPress AcyMailing SMTP Newsletter Plugin <= 8.6.2 is vulnerable to Cross Site Scripting (XSS) | AcyMailing Newsletter Team | AcyMailing | High | 7.1 | 2023-09-25 18:41:55 | Deep Dive |
| CVE-2023-39971 | Extension - acymailing.com - XSS in AcyMailing Enterprise component for Joomla 6.7.0-8.6.3 | acymailing.com | AcyMailing Enterprise component for Joomla | 中危 | - | 2023-08-17 20:06:41 | Deep Dive |
| CVE-2023-39972 | Extension - acymailing.com - Improper Access Control in AcyMailing Enterprise component for Joomla 6.7.0-8.6.3 | acymailing.com | AcyMailing Enterprise component for Joomla | 中危 | - | 2023-08-17 20:06:39 | Deep Dive |
| CVE-2023-39974 | Extension - acymailing.com - Exposure of Sensitive Information in AcyMailing Enterprise component for Joomla 6.7.0-8.6.3 | acymailing.com | AcyMailing Enterprise component for Joomla | 中危 | - | 2023-08-17 20:06:39 | Deep Dive |
| CVE-2023-39973 | Extension - acymailing.com - Improper Access Control in AcyMailing Enterprise component for Joomla 6.7.0-8.6.3 | acymailing.com | AcyMailing Enterprise component for Joomla | 中危 | - | 2023-08-17 20:06:35 | Deep Dive |
| CVE-2023-39970 | Extension - acymailing.com - RCE in AcyMailing component for Joomla 6.7.0-8.5.0 | acymailing.com | AcyMailing component for Joomla | 超危 | - | 2023-08-17 20:06:33 | Deep Dive |
| CVE-2023-28733 | Stored XSS affecting the AcyMailing plugin for Joomla | AcyMailing | Newsletter Plugin for Joomla in the Enterprise version | High | 7.2 | 2023-03-30 11:27:41 | Deep Dive |
| CVE-2023-28732 | Missing access control affecting the AcyMailing plugin for Joomla | AcyMailing | Newsletter Plugin for Joomla | Medium | 6.5 | 2023-03-30 11:26:27 | Deep Dive |
| CVE-2023-28731 | Unauthenticated RCE affecting the AcyMailing plugin for Joomla | AcyMailing | Newsletter Plugin for Joomla in the Enterprise version | Critical | 9.8 | 2023-03-30 11:25:37 | Deep Dive |
| CVE-2021-24288 | AcyMailing < 7.5.0 - Unauthenticated Open Redirect | AcyMailing | Newsletter via SMTP, Sendinblue, Sendgrid, Mailgun - AcyMailing SMTP Newsletter | 中危 | - | 2021-05-17 16:48:52 | Deep Dive |