CVE-2018-19296: Debian Linux
High severity, CVSS 8.8. EPSS: 2.2% chance of exploitation in the next 30 days.
PHPMailer before 5.2.27 and 6.x before 6.0.6 is vulnerable to an object injection attack.
Affected products
- Debian Debian Linux: version 8.0 only; version 9.0 only
- Fedoraproject Fedora: version 33 only; version 34 only
- PHPMailer Project PHPMailer: before 5.2.27 (fixed in 5.2.27); from 6.0.0, before 6.0.6 (fixed in 6.0.6)
- WordPress WordPress: from 3.7, up to and including 5.7
Published 2018-11-16. Last modified 2026-06-17.