CVE-2023-39970: Acyba Acymailing Starter

Critical severity, CVSS 9.8. EPSS: 1.1% chance of exploitation in the next 30 days.

Unrestricted Upload of File with Dangerous Type vulnerability in AcyMailing component for Joomla. It allows remote code execution.

Affected products

  • Acyba Acymailing Starter: from 6.7.0, up to and including 8.5.0

Published 2023-08-17. Last modified 2026-06-17.