Exploited Vulnerabilities Daily
🌐 English

Home › PHP

CVE-2016-10033: PHP PHPMailer

EPSS99.7%No. 169 of 1739 in KEV
CVE year2016~9 yrs before listing
Same vendor in KEV3
Same product1
FieldValue
VendorPHP
ProductPHPMailer
NamePHPMailer Command Injection Vulnerability
Added to KEV2025-07-07
US federal due date2025-07-28
Ransomware useUnknown
CWECWE-77, CWE-88

CISA description

PHPMailer contains a command injection vulnerability because it fails to sanitize user-supplied input. Specifically, this issue affects the 'mail()' function of 'class.phpmailer.php' script. An attacker can exploit this issue to execute arbitrary code within the context of the application. Failed exploit attempts will result in a denial-of-service condition.

NVD — CVE-2016-10033

Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page

A PHP PHPMailer vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2025-07-07.