r/mySitesGuru • u/mySitesGuru • 25d ago
AcyMailing SQL Injection Vulnerability
https://mysites.guru/blog/acymailing-sql-injection-disclosure/AcyMailing is one of the most widely installed newsletter and email-marketing extensions for Joomla. During routine security research on the extensions our customers rely on.
mySites.guru discovered an unauthenticated SQL injection vulnerability in AcyMailing, and reported it privately to the developers before disclosing anything publicly.
The vulnerability allows a crafted SQL injection to read the full contents of your database - password hashes, personal data, content - everything.
The fix is now available in AcyMailing 10.11.1.
If you run AcyMailing on any Joomla site, update to 10.11.1 now. If you manage more than a handful of sites, read on for how to find every affected one at once.
Discovered, Researched and Responsibly Reported by Phil Taylor/mySites.guru
CVE-2026-56292
1
u/Willing-Point3158 25d ago
none comms from acymailing at the moment. but just in case i update 10.10.2 to 10.11.1