CVE Tools

Phpmailer-project

3 CVEs tracked since 2015. Since Dec 2015, 1 of them reached CISA KEV.

Phpmailer-project CVEs per month

Dec 2015 to Dec 2016. Point at a month, or focus the strip and use the arrow keys.
Phpmailer-project CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2015-1210
2016-01null or fewer
2016-02null or fewer
2016-03null or fewer
2016-04null or fewer
2016-05null or fewer
2016-06null or fewer
2016-07null or fewer
2016-08null or fewer
2016-09null or fewer
2016-10null or fewer
2016-11null or fewer
2016-1221

Products

The products that kept showing up in Phpmailer-project's monthly top three, with their CVEs summed over those months.

  1. Phpmailer32 months

Latest CVEs

The 10 most recently published vulnerabilities affecting Phpmailer-project.

  1. CVE-2021-3603Inclusion of Functionality from Untrusted Control Sphere in PHPMailer/PHPMailer8.1
  2. CVE-2021-34551PHPMailer before 6.5.0 on Windows allows remote code execution if lang_path is untrusted data and has a UNC pathname.8.1
  3. CVE-2020-36326PHPMailer 6.1.8 through 6.4.0 allows object injection through Phar Deserialization via addAttachment with a UNC pathname. NOTE: this is similar to CVE-2018-19296, but arose because 6.1.8 fixed a fu...9.8
  4. CVE-2020-13625PHPMailer before 6.1.6 contains an output escaping bug when the name of a file attachment contains a double quote character. This can result in the file type being misinterpreted by the receiver or...7.5
  5. CVE-2018-19296PHPMailer before 5.2.27 and 6.x before 6.0.6 is vulnerable to an object injection attack.8.8
  6. CVE-2017-11503PHPMailer 5.2.23 has XSS in the "From Email Address" and "To Email Address" fields of code_generator.php.6.1
  7. CVE-2017-5223An issue was discovered in PHPMailer before 5.2.22. PHPMailer's msgHTML method applies transformations to an HTML document to make it usable as an email message body. One of the transformations is ...5.5
  8. CVE-2016-10033The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (...9.8
  9. CVE-2016-10045The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code by leveraging improper interaction ...9.8
  10. CVE-2015-8476Multiple CRLF injection vulnerabilities in PHPMailer before 5.2.14 allow attackers to inject arbitrary SMTP commands via CRLF sequences in an (1) email address to the validateAddress function in cl...5.0

The record

Peak rank
#57 in Dec 2016
Busiest month shown
Dec 2016, 2 CVEs
Months with a KEV entry
1 since Dec 2015
Monthly snapshots
2 since 2015
Phpmailer-project's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store