CVE-2016-10033

high KEV
Published 2020-03-05 · Modified 2025-07-07
CVSS v3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H
CVSS v2
VIR risk
9.5

Description

PHPMailer contains a command injection vulnerability because it fails to sanitize user-supplied input. Specifically, this issue affects the 'mail()' function of 'class.phpmailer.php' script. An attacker can exploit this issue to execute arbitrary code within the context of the application. Failed exploit attempts will result in a denial-of-service condition.

CISA KEV

Vendor
PHP
Product
PHPMailer
Due date
2025-07-28

Predictions

Exploit likelihood
99%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cisa-kev — This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/PHPMailer/PHPMailer/releases/tag/v5.2.18 ; https://github.com/advisories/GHSA-5f37-gxvh-23v6 ; https://nvd.nist.gov/vuln/detail/CVE-2016-10033

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2016-10033

vendor Authored 2026-05-27

Vendor advisory: arch — https://security.archlinux.org/ASA-201701-22

Exploits

OS impact

OSVersionStatusFixed in
arch archfixed4.7.1-1
debian debianbookwormfixed5.2.14+dfsg-2.1
debian debianbullseyefixed5.2.14+dfsg-2.1
debian debianforkyfixed5.2.14+dfsg-2.1
debian debiansidfixed5.2.14+dfsg-2.1
debian debiantrixiefixed5.2.14+dfsg-2.1

Package impact

EcosystemPackageVulnerableFixed
php Packagistphpmailer/phpmailer>=5.0.0,<5.2.185.2.18

References

Verify integrity in audit chain (admin only). AS-IS.