Phpmailer Project
Phpmailer Project Phpmailer: vulnerabilities and CVEs
Phpmailer Project Phpmailer has 10 published vulnerabilities, 0 of them in the last 12 months. 3 are rated critical and 1 are listed by CISA as actively exploited.
CVEs10
Last 12 months0
Critical3
Actively exploited1
All vulnerabilities in the catalogue →⭐ Follow this technology
🔴 Actively exploited (CISA KEV)
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-10033 | Critical (9.8) | 100% | ⚠ Active exploitation | Dec 30, 2016 | The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double… |
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-3603 | High (8.1) | 2.3% | — | Jun 17, 2021 | PHPMailer 6.4.1 and earlier contain a vulnerability that can result in untrusted code being called (if such code is injected into the host project's scope by other means). If the $patternselect parameter to… |
| CVE-2021-34551 | High (8.1) | 2.8% | — | Jun 16, 2021 | PHPMailer before 6.5.0 on Windows allows remote code execution if lang_path is untrusted data and has a UNC pathname. |
| CVE-2020-36326 | Critical (9.8) | 3.1% | — | Apr 28, 2021 | PHPMailer 6.1.8 through 6.4.0 allows object injection through Phar Deserialization via addAttachment with a UNC pathname. NOTE: this is similar to CVE-2018-19296, but arose because 6.1.8 fixed a functionality problem in… |
| CVE-2020-13625 | High (7.5) | 3.8% | — | Jun 8, 2020 | PHPMailer before 6.1.6 contains an output escaping bug when the name of a file attachment contains a double quote character. This can result in the file type being misinterpreted by the receiver or any mail relay… |
| CVE-2018-19296 | High (8.8) | 2.2% | — | Nov 16, 2018 | PHPMailer before 5.2.27 and 6.x before 6.0.6 is vulnerable to an object injection attack. |
| CVE-2017-11503 | Medium (6.1) | 2.4% | — | Jul 20, 2017 | PHPMailer 5.2.23 has XSS in the "From Email Address" and "To Email Address" fields of code_generator.php. |
| CVE-2017-5223 | Medium (5.5) | 2.2% | — | Jan 16, 2017 | An issue was discovered in PHPMailer before 5.2.22. PHPMailer's msgHTML method applies transformations to an HTML document to make it usable as an email message body. One of the transformations is to convert relative… |
| CVE-2016-10045 | Critical (9.8) | 98% | — | Dec 30, 2016 | The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code by leveraging improper interaction between the… |
| CVE-2016-10033 | Critical (9.8) | 100% | ⚠ Active exploitation | Dec 30, 2016 | The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double… |
| CVE-2015-8476 | Medium (5) | 2.0% | — | Dec 16, 2015 | Multiple CRLF injection vulnerabilities in PHPMailer before 5.2.14 allow attackers to inject arbitrary SMTP commands via CRLF sequences in an (1) email address to the validateAddress function in class.phpmailer.php or… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.