CVE-2016-10033: PHP PHPMailer
EPSS99.7%No. 169 of 1739 in KEV
CVE year2016~9 yrs before listing
Same vendor in KEV3
Same product1
| Field | Value |
|---|---|
| Vendor | PHP |
| Product | PHPMailer |
| Name | PHPMailer Command Injection Vulnerability |
| Added to KEV | 2025-07-07 |
| US federal due date | 2025-07-28 |
| Ransomware use | Unknown |
| CWE | CWE-77, CWE-88 |
CISA description
PHPMailer contains a command injection vulnerability because it fails to sanitize user-supplied input. Specifically, this issue affects the 'mail()' function of 'class.phpmailer.php' script. An attacker can exploit this issue to execute arbitrary code within the context of the application. Failed exploit attempts will result in a denial-of-service condition.
Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page
A PHP PHPMailer vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2025-07-07.