CVE detail
CVE-2016-10033
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted Sender property.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 24.0 · diversity 8.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
10 source links · newest first
- U.S. CISA adds MRLG, PHPMailer, Rails Ruby on Rails, and Synacor Zimbra Collaboration Suite flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Multi-Router Looking Glass (MRLG), PHPMailer, Rails Ruby on Rails, and Synacor Zimbra Collaboration Suite (ZCS) flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Multi-Router Looking Glass (MRLG), PHPMailer, Rails Ruby on Rails, and Synacor Zimbra Collaboration Suite (ZCS) flaws to […]
newssecurityaffairs.comJul 8, 2025, 2:13 PM - UPDATED – Vanilla Forums software is still affected by a critical remote code execution zero-day first reported in December 2016.Security Affairs
The popular Vanilla Forums software is still affected by a critical remote code execution zero-day first reported to the development team in December 2016. The exploit code was published by ExploitBox, a remote attacker can chain the flaw with the Host Header injection vulnerability CVE-2016-10073 to execute arbitrary code and take the control of the affected […]
newssecurityaffairs.comMay 12, 2017, 8:23 AM - Week in review: Hacking industrial robots, criminals exploit SS7 flaws to empty bank accountsHelp Net Security
Here’s an overview of some of last week’s most interesting news and articles: Three cybersecurity threat trends that organizations should address today The cybersecurity landscape grows seemingly more complex – and more dangerous – by the day. Attackers exploited SS7 flaws to empty Germans’ bank accounts The exploited vulnerabilities were first publicly reported by German researchers Tobias Engel and Karsten Nohl in 2014. They were apparently exploited for years before that by various intelligence services … More →
newswww.helpnetsecurity.comMay 8, 2017, 1:50 AM Independent security researcher Dawid Golunski has released a proof-of-concept exploit code for an unauthenticated remote code execution vulnerability in WordPress 4.6 (CVE-2016-10033), and information about an unauthorized password reset zero-day vulnerability (CVE-2017-8295) in the latest version of the popular CMS. CVE-2016-10033 The vulnerability exists in the PHPMailer library, and can be exploited by unauthenticated remote attackers to gain access to and compromise an target application server on which a vulnerable WordPress Core version is installed … More →
newswww.helpnetsecurity.comMay 4, 2017, 6:59 PMAccording to the release notes the latest version of WordPress 4.7.1 addresses eight security vulnerabilities and other 62 bugs. Wednesday the latest version of WordPress 4.7.1 was released by the WordPress Team, it is classified as a security release for all previous versions. According to the release notes, the new version addresses eight security flaws […]
newssecurityaffairs.comJan 13, 2017, 9:40 PMThe security expert Dawid Golunski from Legal Hackers has reported critical RCE flaws in the popular PHP libraries SwiftMailer, PhpMailer and ZendMail. Recently the security expert Dawid Golunski from Legal Hackers has reported a critical RCE vulnerability, tracked as CVE-2016-10033, in one of the popular open source PHP library, the PHPMailer. The critical vulnerability in the […]
newssecurityaffairs.comJan 3, 2017, 1:24 PM- Security Affairs newsletter Round 93 – News of the weekSecurity Affairs
A new round of the weekly SecurityAffairs newsletter arrived! The best news of the week with Security Affairs. First of all, let me inform you that at the #infosec16 SecurityAffairs was awarded as The Best European Personal Security Blog http://securityaffairs.co/wordpress/48202/breaking-news/securityaffairs-best-european-personal-security-blog.html Moscow wants Apple to unlock iPhone of the killer of the Russian Ambassador Merry Xmas, @Kapustkiy hacked […]
newssecurityaffairs.comJan 1, 2017, 3:50 PM Experts have determined that the remote code execution vulnerabilities affecting the PHPMailer and SwiftMailer email-sending libraries are caused by PHP design flaws.
newswww.securityweek.comDec 30, 2016, 9:11 AMA security expert discovered a critical vulnerability in the PHPMailer that leaves millions of websites vulnerable to remote exploit. A critical vulnerability, tracked as CVE-2016-10033, affects PHPMailer, one of the most popular open source PHP libraries used to send emails. It has been estimated that more than 9 Million users worldwide leverages on this library. Millions […]
newssecurityaffairs.comDec 27, 2016, 7:32 AM- Critical RCE Flaw Patched in PHPMailerSecurityWeek
The developers of PHPMailer have patched a critical vulnerability that can be exploited by a remote attacker for arbitrary code execution, a researcher said on Sunday.
newswww.securityweek.comDec 27, 2016, 6:23 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2016-10045CVSS 9.8 · Critical
The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code by leveraging imp…
- CVE-2020-36326CVSS 9.8 · Critical
PHPMailer 6.1.8 through 6.4.0 allows object injection through Phar Deserialization via addAttachment with a UNC pathname. NOTE: this is similar to CVE-2018-19296, but arose becaus…
- CVE-2018-19296CVSS 8.8 · High
PHPMailer before 5.2.27 and 6.x before 6.0.6 is vulnerable to an object injection attack.
- CVE-2026-71212CVSS 4.4 · Medium
xidown (a yt-dlp/ffmpeg GUI wrapper) builds its yt-dlp command-line invocation (xidown/core/scanner.py and downloader.py) by appending the user-provided or scanned URL as a bare t…
- CVE-2026-17347CVSS 7.7 · High
The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an administrator configure an external command that returns a per-user encryption key, with %u in the configure…
- CVE-2026-18157CVSS 7.8 · High
A flaw was found in yggdrasil-worker-package-manager. A local attacker with existing access to the system could exploit an argument injection vulnerability in the APT backend. Thi…