« Back to list

Phpmailer Project

Phpmailer Project Phpmailer: vulnerabilities and CVEs

Phpmailer Project Phpmailer has 10 published vulnerabilities, 0 of them in the last 12 months. 3 are rated critical and 1 are listed by CISA as actively exploited.

CVEs10
Last 12 months0
Critical3
Actively exploited1

All vulnerabilities in the catalogue →⭐ Follow this technology

🔴 Actively exploited (CISA KEV)

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2016-10033Critical (9.8)100%⚠ Active exploitationDec 30, 2016
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double…

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2021-3603High (8.1)2.3%—Jun 17, 2021
PHPMailer 6.4.1 and earlier contain a vulnerability that can result in untrusted code being called (if such code is injected into the host project's scope by other means). If the $patternselect parameter to…
CVE-2021-34551High (8.1)2.8%—Jun 16, 2021
PHPMailer before 6.5.0 on Windows allows remote code execution if lang_path is untrusted data and has a UNC pathname.
CVE-2020-36326Critical (9.8)3.1%—Apr 28, 2021
PHPMailer 6.1.8 through 6.4.0 allows object injection through Phar Deserialization via addAttachment with a UNC pathname. NOTE: this is similar to CVE-2018-19296, but arose because 6.1.8 fixed a functionality problem in…
CVE-2020-13625High (7.5)3.8%—Jun 8, 2020
PHPMailer before 6.1.6 contains an output escaping bug when the name of a file attachment contains a double quote character. This can result in the file type being misinterpreted by the receiver or any mail relay…
CVE-2018-19296High (8.8)2.2%—Nov 16, 2018
PHPMailer before 5.2.27 and 6.x before 6.0.6 is vulnerable to an object injection attack.
CVE-2017-11503Medium (6.1)2.4%—Jul 20, 2017
PHPMailer 5.2.23 has XSS in the "From Email Address" and "To Email Address" fields of code_generator.php.
CVE-2017-5223Medium (5.5)2.2%—Jan 16, 2017
An issue was discovered in PHPMailer before 5.2.22. PHPMailer's msgHTML method applies transformations to an HTML document to make it usable as an email message body. One of the transformations is to convert relative…
CVE-2016-10045Critical (9.8)98%—Dec 30, 2016
The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code by leveraging improper interaction between the…
CVE-2016-10033Critical (9.8)100%⚠ Active exploitationDec 30, 2016
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double…
CVE-2015-8476Medium (5)2.0%—Dec 16, 2015
Multiple CRLF injection vulnerabilities in PHPMailer before 5.2.14 allow attackers to inject arbitrary SMTP commands via CRLF sequences in an (1) email address to the validateAddress function in class.phpmailer.php or…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1059.003 Windows Command Shell1
  2. T1190 Exploit Public-Facing Application1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.