CVE-2016-10045
CVE-2016-10045 is a critical-severity vulnerability in Phpmailer Project Phpmailer with a CVSS 3.x base score of 9.8. Its EPSS exploit-prediction score of 98% places it in the 100th percentile, indicating an elevated likelihood of exploitation. The underlying weakness is classified as CWE-77.
Key facts
- Severity: Critical (CVSS 3.x base score 9.8)
- CVSS v2: 7.5
- EPSS exploit prediction: 98% (100th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-77
- Affected product: Phpmailer Project Phpmailer
- Published:
- Last modified:
Description
The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code by leveraging improper interaction between the escapeshellarg function and internal escaping performed in the mail function in PHP. NOTE: this vulnerability exists because of an incorrect fix for CVE-2016-10033.
Frequently asked questions
- What is CVE-2016-10045?
- The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code by leveraging improper interaction between the escapeshellarg function and internal escaping performed in the mail function in PHP. NOTE: this vulnerability exists because of an incorrect fix for CVE-2016-10033.
- How severe is CVE-2016-10045?
- CVE-2016-10045 has a CVSS 3.x base score of 9.8, rated critical severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2016-10045 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 98% (100th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2016-10045?
- CVE-2016-10045 primarily affects Phpmailer Project Phpmailer. In total, 3 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2016-10045?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its critical severity, prioritise patching exposed systems.
- When was CVE-2016-10045 published?
- CVE-2016-10045 was published on 2016-12-30 and last updated on 2026-06-17.
References
- http://openwall.com/lists/oss-security/2016/12/28/1
- http://packetstormsecurity.com/files/140286/PHPMailer-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/140350/PHPMailer-Sendmail-Argument-Injection.html
- http://seclists.org/fulldisclosure/2016/Dec/81
- http://www.rapid7.com/db/modules/exploit/multi/http/phpmailer_arg_injection
- http://www.securityfocus.com/archive/1/539967/100/0/threaded
- http://www.securityfocus.com/bid/95130
- http://www.securitytracker.com/id/1037533
- https://developer.joomla.org/security-centre/668-20161205-phpmailer-security-advisory.html
- https://github.com/PHPMailer/PHPMailer/releases/tag/v5.2.20
- https://github.com/PHPMailer/PHPMailer/wiki/About-the-CVE-2016-10033-and-CVE-2016-10045-vulnerabilities
- https://legalhackers.com/advisories/PHPMailer-Exploit-Remote-Code-Exec-CVE-2016-10045-Vuln-Patch-Bypass.html
- https://www.exploit-db.com/exploits/40969/
- https://www.exploit-db.com/exploits/40986/
- https://www.exploit-db.com/exploits/42221/
Affected products (3)
- cpe:2.3:a:phpmailer_project:phpmailer:*:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*
- cpe:2.3:a:joomla:joomla\!:*:*:*:*:*:*:*:*
More vulnerabilities in Phpmailer Project Phpmailer
- CVE-2020-36326 — Critical (CVSS 9.8): PHPMailer 6.1.8 through 6.4.0 allows object injection through Phar Deserialization via addAttachment with a UNC…
- CVE-2016-10033 — Critical (CVSS 9.8): The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra…
- CVE-2018-19296 — High (CVSS 8.8): PHPMailer before 5.2.27 and 6.x before 6.0.6 is vulnerable to an object injection attack.
- CVE-2021-3603 — High (CVSS 8.1): PHPMailer 6.4.1 and earlier contain a vulnerability that can result in untrusted code being called (if such code is…
- CVE-2021-34551 — High (CVSS 8.1): PHPMailer before 6.5.0 on Windows allows remote code execution if lang_path is untrusted data and has a UNC pathname.
- CVE-2020-13625 — High (CVSS 7.5): PHPMailer before 6.1.6 contains an output escaping bug when the name of a file attachment contains a double quote…
All CVEs affecting Phpmailer Project Phpmailer →
Other CWE-77 (Command Injection) vulnerabilities
- CVE-2026-105484 — Critical (CVSS 10.0): A security vulnerability has been detected in TOTOLINK X6000R 9.4.0cu.652_B20230116. The impacted element is the…
- CVE-2026-105134 — Critical (CVSS 10.0): A flaw has been found in Ahsay AhsayCBS up to 10.3.2. This vulnerability affects unknown code of the file…
- CVE-2026-102240 — Critical (CVSS 10.0): A vulnerability was found in Netcore NAP930 0.1.241010.141410. This affects the function eval of the file…
- CVE-2026-101076 — Critical (CVSS 10.0): A vulnerability was detected in Netcore NR289-GE 1.4.5102. This affects the function system of the file…
- CVE-2026-101075 — Critical (CVSS 10.0): A security vulnerability has been detected in Netcore NR289-GE 1.4.5102. The impacted element is the function system of…
- CVE-2026-101072 — Critical (CVSS 10.0): A vulnerability was identified in Netcore NR289-GE 1.4.5102. This issue affects the function system of the file…