acyba records
5 published records for vendor acyba.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-1236 Improper Neutralization of Formula Elements in a CSV File2
- CWE-434 Unrestricted Upload of File with Dangerous Type2
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
5 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2023-39970No exploit | Extension - acymailing.com - RCE in AcyMailing component for Joomla 6.7.0-8.5.0acyba · acymailing starter · CWE-434 | Critical9.8 | — | 1.1% | Aug 17, 2023 |
37Monitor | CVE-2018-9107Proof of concept | CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in the Acyba AcyMailing extension before 5.9.6 facyba · acymailing · CWE-1236 | High8.8 | — | 7.0% | Mar 28, 2018 |
37Monitor | CVE-2018-9106Proof of concept | CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in the Acyba AcySMS extension before 3.5.1 for Jacyba · acysms · CWE-1236 | High8.8 | — | 6.4% | Mar 28, 2018 |
28Monitor | CVE-2020-10934No exploit | Acyba AcyMailing before 6.9.2 mishandles file uploads by admins.acyba · acymailing · CWE-434 | High7.2 | — | 1.3% | Mar 24, 2020 |
28Monitor | CVE-2015-7338No exploit | SQL Injection exists in AcyMailing Joomla Component before 4.9.5 via exportgeolocorder in a geolocation_longitude request to index.php.acyba · acymailing · CWE-89 | High7.2 | — | 1.0% | Mar 9, 2020 |
- CVE-2023-3997039Monitor
Extension - acymailing.com - RCE in AcyMailing component for Joomla 6.7.0-8.5.0
CriticalCVSS 9.8No exploitEPSS 1%acyba · acymailing starterAug 17, 2023
- CVE-2018-910737Monitor
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in the Acyba AcyMailing extension before 5.9.6 f
HighCVSS 8.8Proof of conceptEPSS 7%acyba · acymailingMar 28, 2018
- CVE-2018-910637Monitor
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in the Acyba AcySMS extension before 3.5.1 for J
HighCVSS 8.8Proof of conceptEPSS 6%acyba · acysmsMar 28, 2018
- CVE-2020-1093428Monitor
Acyba AcyMailing before 6.9.2 mishandles file uploads by admins.
HighCVSS 7.2No exploitEPSS 1%acyba · acymailingMar 24, 2020
- CVE-2015-733828Monitor
SQL Injection exists in AcyMailing Joomla Component before 4.9.5 via exportgeolocorder in a geolocation_longitude request to index.php.
HighCVSS 7.2No exploitEPSS 1%acyba · acymailingMar 9, 2020