Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2686▼ 84 respecto a la semana anterior
Críticas / altas1444▲ 301 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

14 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (3.5)0.29%—PhpmailerAIWallosapp WallosAI31/8/20268/9/2026
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, Wallos lets any authenticated user store an arbitrary SMTP host — including private and cloud-metadata IP addresses — in their personal email notification settings, with no server-side SSRF validation. When the scheduled…
AplazadaMedia (6.3)0.27%—PHP Server MonitorAIPhpmailerAI24/5/202417/6/2026
PHP Server Monitor, version 3.2.0, is vulnerable to an XSS via the /phpservermon-3.2.0/vendor/phpmailer/phpmailer/test_script/index.php page in all visible parameters. An attacker could create a specially crafted URL, send it to a victim and retrieve their session details.
ModificadaAlta (8.1)2.3%—Phpmailer Project PhpmailerFedoraproject Fedora17/6/202117/6/2026
PHPMailer 6.4.1 and earlier contain a vulnerability that can result in untrusted code being called (if such code is injected into the host project's scope by other means). If the $patternselect parameter to validateAddress() is set to 'php' (the default, defined by PHPMailer::$validator), and the global namespace…
ModificadaAlta (8.1)2.8%—Phpmailer Project PhpmailerFedoraproject Fedora16/6/202117/6/2026
PHPMailer before 6.5.0 on Windows allows remote code execution if lang_path is untrusted data and has a UNC pathname.
ModificadaCrítica (9.8)3.1%—Phpmailer Project PhpmailerWordpress28/4/202117/6/2026
PHPMailer 6.1.8 through 6.4.0 allows object injection through Phar Deserialization via addAttachment with a UNC pathname. NOTE: this is similar to CVE-2018-19296, but arose because 6.1.8 fixed a functionality problem in which UNC pathnames were always considered unreadable by PHPMailer, even in safe contexts. As an…
ModificadaAlta (7.5)3.8%—Phpmailer Project PhpmailerFedoraproject FedoraCanonical Ubuntu LinuxDebian Linux8/6/202017/6/2026
PHPMailer before 6.1.6 contains an output escaping bug when the name of a file attachment contains a double quote character. This can result in the file type being misinterpreted by the receiver or any mail relay processing the message.
ModificadaAlta (8.8)2.2%—Phpmailer Project PhpmailerDebian LinuxFedoraproject FedoraWordpress16/11/201817/6/2026
PHPMailer before 5.2.27 and 6.x before 6.0.6 is vulnerable to an object injection attack.
ModificadaMedia (6.1)2.4%—Phpmailer Project Phpmailer20/7/201717/6/2026
PHPMailer 5.2.23 has XSS in the "From Email Address" and "To Email Address" fields of code_generator.php.
ModificadaMedia (5.5)2.2%—Phpmailer Project Phpmailer16/1/201717/6/2026
An issue was discovered in PHPMailer before 5.2.22. PHPMailer's msgHTML method applies transformations to an HTML document to make it usable as an email message body. One of the transformations is to convert relative image URLs into attachments using a script-provided base directory. If no base directory is provided,…
ModificadaCrítica (9.8)98%—Phpmailer Project PhpmailerWordpressJoomla!30/12/201617/6/2026
The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code by leveraging improper interaction between the escapeshellarg function and internal escaping performed in the mail function in PHP. NOTE: this vulnerability…
AnalizadaCrítica (9.8)100%⚠ Explotación activaPhpmailer Project PhpmailerWordpressJoomla!30/12/201617/6/2026
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted Sender property.
ModificadaMedia (5)2.0%—Debian LinuxPhpmailer Project Phpmailer16/12/201517/6/2026
Multiple CRLF injection vulnerabilities in PHPMailer before 5.2.14 allow attackers to inject arbitrary SMTP commands via CRLF sequences in an (1) email address to the validateAddress function in class.phpmailer.php or (2) SMTP command to the sendCommand function in class.smtp.php, a different vulnerability than…
ModificadaMedia (6.8)2.4%—Phpmailer14/6/200716/6/2026
PHPMailer 1.7, when configured to use sendmail, allows remote attackers to execute arbitrary shell commands via shell metacharacters in the SendmailSend function in class.phpmailer.php.
ModificadaMedia (5)4.5%—Phpmailer28/5/200516/6/2026
The Data function in class.smtp.php in PHPMailer 1.7.2 and earlier allows remote attackers to cause a denial of service (infinite loop leading to memory and CPU consumption) via a long header field.