{"id":"CVE-2026-94131","published":"2026-09-26T15:16:54.183","lastModified":"2026-09-29T21:39:02.570","description":"Joomla Extension - acymailing.com - Unauthenticated arbitrary file deletion in AcyMailing Enterprise extension < 11.1.0 - A subscriber could store a path in a file-type custom field and have AcyMailing delete that file when the field was cleared, including files outside the upload folder such as configuration.php.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":["CWE-89"],"vendors":[],"products":[],"references":[{"url":"https://www.acymailing.com/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}