CVE-2017-11503: PHPMailer Project PHPMailer

Medium severity, CVSS 6.1. EPSS: 2.4% chance of exploitation in the next 30 days.

PHPMailer 5.2.23 has XSS in the "From Email Address" and "To Email Address" fields of code_generator.php.

Affected products

Published 2017-07-20. Last modified 2026-06-17.