CVE-2016-10033
KEVCRITICAL 9.8EPSS 99.7%
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted Sender property.
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H - CVSS v2.0
- 7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P - EPSS
- 99.71% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2025-07-07
- Nuclei
- critical · CWE-88
- Published
- 2016-12-30
- Updated
- 2025-10-21
Proof-of-concept exploits (147)
- http://packetstormsecurity.com/files/140291/PHPMailer-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/140350/PHPMailer-Sendmail-Argument-Injection.html
- https://legalhackers.com/advisories/PHPMailer-Exploit-Remote-Code-Exec-CVE-2016-10033-Vul…
- https://www.exploit-db.com/exploits/40969/
- http://www.rapid7.com/db/modules/exploit/multi/http/phpmailer_arg_injection
- 0x00-0x00/CVE-2016-100336★ · 2018-02-09
- 777sot/PHPMailer0★ · 2022-11-26
- Anurag168/php-mailer0★ · 2025-04-22
- Astrowmist/POC-CVE-2016-100330★ · 2024-06-06
- Awsafaneh/smm0★ · 2025-05-16
- BagmetDenis/exploits_scripts0★ · 2022-08-13
- Bajunan/CVE-2016-100330★ · 2017-05-19
- Brens498/AulaMvc0★ · 2021-06-22
- ElnurBDa/CVE-2016-100330★ · 2024-05-16
- GeneralTesler/CVE-2016-100339★ · 2017-05-10
- Guangyang-Sunlight/php-phpmailer0★ · 2025-06-06
- Hehhchen/eCommerce0★ · 2019-11-07
- Jack-LaL/idk0★ · 2020-10-25
- JesusAyalaEspinoza/p0★ · 2019-03-28
- KNIGHTTH0R/PHPMail0★ · 2017-12-23
- Keshav9863/MFA_SIGN_IN_PAGE0★ · 2019-10-03
- Lu183/phpmail0★ · 2018-01-25
- MIrfanShahid/PHPMailer0★ · 2018-12-04
- MarcioPeters/PHP1★ · 2020-10-23
- Mona-Mishra/User-Registration-System0★ · 2024-06-09
- Mugdho55/Air_Ticket_Management_System0★ · 2022-08-22
- Niveditakm/homeRental0★ · 2025-01-11
- PatelMisha/Online-Flight-Booking-Management-System1★ · 2023-03-29
- Preeti1502kashyap/loginpage0★ · 2023-01-23
- Rachna-2018/email0★ · 2018-08-21
- RakhithJK/Synchro-PHPMailer0★ · 2023-01-18
- Ramkiskhan/sample0★ · 2020-11-04
- Razzle23/mail-30★ · 2019-01-05
- RichardStwart/PHP0★ · 2023-03-10
- Sakanksha07/Journey-With-Food0★ · 2018-11-23
- SecRet-501/PHPMailer0★ · 2018-05-24
- SeffuCodeIT/phpmailer0★ · 2020-09-28
- Teeeiei/phpmailer0★ · 2017-10-13
- ThatsSacha/forum1★ · 2020-02-10
- VenusPR/PHP0★ · 2023-03-10
- aegunasekara/PHPMailer0★ · 2018-06-02
- aegunasekaran/PHPMailer0★ · 2018-06-02
- afkpaul/smtp0★ · 2017-01-03
- agente945/worm1★ · 2025-06-25
- alexander47777/CVE-2016-100330★ · 2025-08-11
- alexandrazlatea/emails0★ · 2018-04-22
- alokdas1982/phpmailer0★ · 2018-11-21
- anishbhut/simpletest0★ · 2017-09-11
- ank0809/Responsive-login-register-page0★ · 2022-08-01
- antelove19/phpmailer0★ · 2018-01-25
- anushasinha24/send-mail-using-PHPMailer0★ · 2019-05-14
- aquahubtest4/ops0★ · 2024-12-30
- aquahubtest5/ops0★ · 2025-01-03
- arbaazkhanrs/Online_food_ordering_system1★ · 2022-06-17
- ashiqdey/PHPmailer0★ · 2018-04-24
- athirakottekadnew/testingRepophp0★ · 2020-07-28
- awidardi/opsxcq-cve-2016-100331★ · 2018-02-06
- bigtunacan/phpmailer50★ · 2020-09-16
- bkrishnasowmya/OTMS-project0★ · 2020-05-08
- chipironcin/CVE-2016-100331★ · 2017-06-12
- clemerribeiro/cbdu0★ · 2023-04-05
- codersstock/PhpMailer0★ · 2018-11-14
- crackerica/PHPMailer20★ · 2018-05-06
- cved-sources/cve-2016-100330★ · 2021-04-15
- cyberharsh/phpmailer0★ · 2020-09-02
- denniskinyuandege/mailer0★ · 2019-11-13
- devhribeiro/cadweb_aritana0★ · 2020-09-19
- dipak1997/Alumni-M0★ · 2021-05-16
- dp7sv/ECOMM0★ · 2021-06-22
- duhengchen1112/demo0★ · 2018-06-28
- dylangerardf/dhl0★ · 2023-04-06
- dylangerardf/dhl-supp0★ · 2023-04-06
- elhouti/ensimag-ssi-2019-200★ · 2020-01-13
- eminemdordie/mailer0★ · 2017-07-16
- entraned/PHPMailer0★ · 2018-09-09
- faraz07-AI/fullstack-Jcomp0★ · 2021-10-06
- fatfishdigital/phpmailer0★ · 2019-02-28
- fatihbaba44/PeakGames0★ · 2021-06-02
- fatihulucay/PeakGames0★ · 2021-06-02
- frank850219/PHPMailerAutoSendingWithCSV0★ · 2018-10-05
- gaguser/phpmailer0★ · 2017-05-29
- geet56/geet220★ · 2020-01-17
- generalbao/phpmailer60★ · 2017-05-06
- gnikita01/hackedemistwebsite0★ · 2017-12-20
- grayVTouch/phpmailer0★ · 2020-05-25
- gtasaif/PHPMailer0★ · 2018-02-01
- gzy403999903/PHPMailer0★ · 2019-02-17
- heikipikker/exploit-CVE-2016-100340★ · 2017-07-18
- huongbee/mailer01120★ · 2018-03-09
- huongbee/mailer05050★ · 2018-07-24
- ifindu-dk/phpmailer0★ · 2017-11-04
- im-sacha-cohen/forum1★ · 2020-02-10
- inusah42/ecomm0★ · 2019-10-28
- ivankznru/PHPMailer0★ · 2022-08-17
- izisoft/yii2-mailer0★ · 2018-10-11
- j4k0m/CVE-2016-100331★ · 2021-08-31
- jaimedaw86/repositorio-DAW06_PHP0★ · 2020-04-27
- jairo0823/capstone0★ · 2025-03-23
- jamesxiaofeng/sendmail0★ · 2018-09-12
- jatin-dwebguys/PHPMailer0★ · 2016-12-28
- jbperry1998/bd_calendar0★ · 2021-06-22
- jeddatinsyd/PHPMailer0★ · 2020-04-30
- jesusclaramontegascon/PhpMailer0★ · 2020-06-07
- kubota/exploit_PHPMail0★ · 2019-02-03
- kylingit/vul_wordpress0★ · 2017-07-25
- laddoms/faces0★ · 2023-03-04
- lanlehoang67/sender0★ · 2019-12-21
- lcscastro/RecursoFunctionEmail0★ · 2019-04-17
- leftarmm/speexx0★ · 2020-02-25
- leocifrao/site-restaurante0★ · 2020-03-19
- liusec/WP-CVE-2016-100331★ · 2017-07-22
- luxiaojue/phpmail0★ · 2018-01-25
- madbananaman/L-Mailer0★ · 2018-05-11
- marco-comi-sonarsource/PHPMailer0★ · 2020-10-21
- mayankbansal100/PHPMailer0★ · 2017-05-20
- mkrdeptcreative/PHPMailer0★ · 2018-03-13
- mohamed-aymen-ellafi/web0★ · 2025-08-30
- morkamimi/poop0★ · 2020-06-27
- natsootail/alumni1★ · 2018-11-28
- nyamleeze/commit_testing0★ · 2018-08-09
- opsxcq/exploit-CVE-2016-10033407★ · 2023-02-27
- paralelo14/CVE_2016-100337★ · 2016-12-29
- paulogmota/phpmailer-5.2.20-RCE0★ · 2024-04-07
- pctechsupport123/php0★ · 2018-12-24
- pedro823/cve-2016-10033-452★ · 2017-11-19
- pitecozz/RCE-VUL0★ · 2024-05-09
- prostogorod/PHPMailer0★ · 2019-03-07
- rasisbade/allphp0★ · 2017-03-05
- rohandavid/fitdanish0★ · 2022-12-06
- rrathi0705/email0★ · 2018-12-03
- rudresh98/e_commerce_IFood0★ · 2021-06-22
- sakshibohra05/project0★ · 2020-07-12
- sankar-rgb/PHPMailer0★ · 2018-05-26
- sarvottam1766/Project0★ · 2019-02-28
- sashasimulik/integration-10★ · 2021-09-14
- sealldeveloper/CVE-2016-10033-PoC0★ · 2026-01-08
- sealldeveloper/CVE-2016-2098-PoC0★ · 2025-04-25
- supreethsk/rental0★ · 2022-12-05
- sweta-web/Online-Registration-System0★ · 2024-06-14
- tvirus-01/PHP_mail0★ · 2018-06-06
- vaartjesd/test0★ · 2017-04-22
- vatann07/BloodConnect0★ · 2019-06-14
- vedavith/mailer0★ · 2017-12-20
- windypermadi/PHP-Mailer0★ · 2020-11-16
- zakiaafrin/PHPMailer0★ · 2020-04-19
- zeeshanbhattined/exploit-CVE-2016-100330★ · 2022-08-05
- zhangqiyi55/phpemail0★ · 2018-11-19
Nuclei templates (1)
Metasploit modules (1)
ExploitDB entries (8)
- https://www.exploit-db.com/exploits/42024
- https://www.exploit-db.com/exploits/40968
- https://www.exploit-db.com/exploits/42221
- https://www.exploit-db.com/exploits/41996
- https://www.exploit-db.com/exploits/41962
- https://www.exploit-db.com/exploits/40986
- https://www.exploit-db.com/exploits/40974
- https://www.exploit-db.com/exploits/40970