CVE-2018-9106: Acyba Acysms
High severity, CVSS 8.8. EPSS: 6.4% chance of exploitation in the next 30 days.
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in the Acyba AcySMS extension before 3.5.1 for Joomla! via a value that is mishandled in a CSV export.
Affected products
- Acyba Acysms: up to and including 3.5.0
Published 2018-03-28. Last modified 2026-06-17.