CVE-2020-11546: Superwebmailer
Critical severity, CVSS 9.8. EPSS: 32.8% chance of exploitation in the next 30 days.
SuperWebMailer 7.21.0.01526 is susceptible to a remote code execution vulnerability in the Language parameter of mailingupgrade.php. An unauthenticated remote attacker can exploit this behavior to execute arbitrary PHP code via Code Injection.
Affected products
- Superwebmailer Superwebmailer: before 7.40.0.01550 (fixed in 7.40.0.01550)
Published 2020-07-14. Last modified 2026-06-17.