{"id":"CVE-2026-94132","published":"2026-09-26T15:16:55.397","lastModified":"2026-09-29T21:39:02.570","description":"Joomla Extension - acymailing.com - Remote Code Execution vulnerability in mailbox action feature in AcyMailing Enterprise extension < 11.1.0 - MIME parts of incoming emails were saved to media/com_acym/upload/ with no extension check, so anyone who could email the monitored mailbox could write a PHP file into the web root.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":["CWE-434"],"vendors":[],"products":[],"references":[{"url":"https://www.acymailing.com/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}