CVE-2026-94131
EUVD-2026-8777326.09.2026, 15:16
Joomla Extension - acymailing.com - Unauthenticated arbitrary file deletion in AcyMailing Enterprise extension < 11.1.0 - A subscriber could store a path in a file-type custom field and have AcyMailing delete that file when the field was cleared, including files outside the upload folder such as configuration.php.
Awaiting analysis
This vulnerability is currently awaiting analysis.
References