Phpmailer Project

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 10
    Known Exploited: 0
    3
    Critical Level Threats
    4
    High Level Threats
    3
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2021-3603

    Inclusion of Functionality from Untrusted Control Sphere in PHPMailer/PHPMailer

    Last Modified: Nov 21, 2024
    Published: Jun 17, 2021

    CVE-2021-34551

    PHPMailer before 6.5.0 on Windows allows remote code execution if lang_path is untrusted data and has a UNC pathname.

    Last Modified: Nov 21, 2024
    Published: Jun 16, 2021

    CVE-2020-36326

    PHPMailer 6.1.8 through 6.4.0 allows object injection through Phar Deserialization via addAttachment with a UNC pathname. NOTE: this is similar to CVE-2018-19296, but arose because 6.1.8 fixed a functionality problem in which UNC pathnames were always considered unreadable by PHPMailer, even in safe contexts. As an unintended side effect, this fix eliminated the code that blocked addAttachment exploitation.

    Last Modified: Nov 21, 2024
    Published: Apr 28, 2021

    CVE-2020-13625

    PHPMailer before 6.1.6 contains an output escaping bug when the name of a file attachment contains a double quote character. This can result in the file type being misinterpreted by the receiver or any mail relay processing the message.

    Last Modified: Nov 21, 2024
    Published: Jun 08, 2020

    CVE-2018-19296

    PHPMailer before 5.2.27 and 6.x before 6.0.6 is vulnerable to an object injection attack.

    Last Modified: Nov 21, 2024
    Published: Nov 16, 2018
    Items Per Page