Swiftmailer is a widely used PHP email-sending library commonly embedded in web applications and content management systems for message composition and transmission. The observed vulnerability signal centers on command-injection weaknesses that can arise from improper handling of special characters in email headers and message construction. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Swiftmailer over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-10074CRITICAL The mail transport (aka Swift_Transport_MailTransport) in Swift Mailer before 5.4.5 might allow remote attackers to pass extra parameters to the mail command and consequently execu | Dec 30, 2016 | 9.8 | 61 | NO | YES |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Swiftmailer.
Media articles that mention a CVE ID that affects a product developed by Swiftmailer — matched by CVE ID, not by vendor name.