PHPMailer is a widely embedded PHP library for message composition and transmission that presents attack surface disproportionate to its narrow product scope, as a single vulnerability can affect thousands of downstream web applications and services that integrate the library. The observed weakness classes reflect the complexity of email protocol handling and message sanitization in a general-purpose library context. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Phpmailer over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-10033CRITICAL The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrar | Dec 30, 2016 | 9.8 | 99 | YES | YES |
CVE-2016-10045CRITICAL The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code by leveraging impr | Dec 30, 2016 | 9.8 | 91 | NO | YES |
CVE-2020-36326CRITICAL PHPMailer 6.1.8 through 6.4.0 allows object injection through Phar Deserialization via addAttachment with a UNC pathname. NOTE: this is similar to CVE-2018-19296, but arose because | Apr 28, 2021 | 9.8 | 31 | NO | NO |
CVE-2017-5223MEDIUM An issue was discovered in PHPMailer before 5.2.22. PHPMailer's msgHTML method applies transformations to an HTML document to make it usable as an email message body. One of the tr | Jan 16, 2017 | 5.5 | 31 | NO | YES |
CVE-2021-3603HIGH PHPMailer 6.4.1 and earlier contain a vulnerability that can result in untrusted code being called (if such code is injected into the host project's scope by other means). If the $ | Jun 17, 2021 | 8.1 | 25 | NO | NO |
CVE-2021-34551HIGH PHPMailer before 6.5.0 on Windows allows remote code execution if lang_path is untrusted data and has a UNC pathname. | Jun 16, 2021 | 8.1 | 25 | NO | NO |
CVE-2018-19296HIGH PHPMailer before 5.2.27 and 6.x before 6.0.6 is vulnerable to an object injection attack. | Nov 16, 2018 | 8.8 | 25 | NO | NO |
CVE-2005-1807MEDIUM The Data function in class.smtp.php in PHPMailer 1.7.2 and earlier allows remote attackers to cause a denial of service (infinite loop leading to memory and CPU consumption) via a | May 28, 2005 | 5.0 | 24 | NO | YES |
CVE-2020-13625HIGH PHPMailer before 6.1.6 contains an output escaping bug when the name of a file attachment contains a double quote character. This can result in the file type being misinterpreted b | Jun 8, 2020 | 7.5 | 23 | NO | NO |
CVE-2017-11503MEDIUM PHPMailer 5.2.23 has XSS in the "From Email Address" and "To Email Address" fields of code_generator.php. | Jul 20, 2017 | 6.1 | 22 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Phpmailer.
Media articles that mention a CVE ID that affects a product developed by Phpmailer — matched by CVE ID, not by vendor name.