CVE-2018-19296: Debian Linux

High severity, CVSS 8.8. EPSS: 2.2% chance of exploitation in the next 30 days.

PHPMailer before 5.2.27 and 6.x before 6.0.6 is vulnerable to an object injection attack.

Affected products

  • Debian Debian Linux: version 8.0 only; version 9.0 only
  • Fedoraproject Fedora: version 33 only; version 34 only
  • PHPMailer Project PHPMailer: before 5.2.27 (fixed in 5.2.27); from 6.0.0, before 6.0.6 (fixed in 6.0.6)
  • WordPress WordPress: from 3.7, up to and including 5.7

Published 2018-11-16. Last modified 2026-06-17.