CVE-2016-10033: PHPMailer Command Injection Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2025-07-07. EPSS: 99.7% chance of exploitation in the next 30 days.

The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted Sender property.

Affected products

Published 2016-12-30. Last modified 2026-06-17.