CVE-2018-9107: Acyba Acymailing
High severity, CVSS 8.8. EPSS: 7% chance of exploitation in the next 30 days.
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in the Acyba AcyMailing extension before 5.9.6 for Joomla! via a value that is mishandled in a CSV export.
Affected products
- Acyba Acymailing: up to and including 5.9.5
Published 2018-03-28. Last modified 2026-06-17.