← Vulnerability feed

Vulnerability record · CVE-2016-10045 · published 30 December 2016

CVE-2016-10045: PHPMailer isMail transport argument injection enables remote code execution

Phpmailer Project · Phpmailer

PHPMailer before 5.2.20 fails to properly neutralize shell metacharacters in the isMail transport, because escapeshellarg interacts incorrectly with PHP's internal escaping of the mail() function. An attacker who controls an address field passed to the mailer can inject extra arguments to the underlying sendmail command. This is a bypass of the incomplete fix for CVE-2016-10033, so systems patched only for that earlier flaw remain exposed.

9.8 CVSS 3.1 Critical EPSS 98% · top 0.1% CWE-77 · Command injection
9.8CVSS 3.1 base score, v2 7.5
98%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
30References, 12 tagged exploit
17 Jun 2026Last modified by NVD

Description

The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code by leveraging improper interaction between the escapeshellarg function and internal escaping performed in the mail function in PHP. NOTE: this vulnerability exists because of an incorrect fix for CVE-2016-10033.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no authentication or interaction required, public exploit code and a very high EPSS score make this an urgent patch target despite its age.

What it is

PHPMailer before 5.2.20 fails to properly neutralize shell metacharacters in the isMail transport, because escapeshellarg interacts incorrectly with PHP's internal escaping of the mail() function. An attacker who controls an address field passed to the mailer can inject extra arguments to the underlying sendmail command. This is a bypass of the incomplete fix for CVE-2016-10033, so systems patched only for that earlier flaw remain exposed.

Impact

An unauthenticated remote attacker can pass extra parameters to the mail command and execute arbitrary code in the context of the web server. That typically yields full compromise of the application and its data.

Attack surface

Reached over the network through any application code path that feeds attacker-influenced input (such as a sender or recipient address) into PHPMailer's isMail transport. The CVSS vector shows no privileges and no user interaction required, so exposure depends on whether such a path is reachable.

Exploitation

Not listed in CISA KEV, but EPSS is 0.9758 (99.9th percentile) and multiple references carry Exploit tags, including Packet Storm, Exploit-DB and a Rapid7 Metasploit module, indicating public exploit code exists.

What to do

  • Upgrade PHPMailer to 5.2.20 or later, which contains the corrected fix for the CVE-2016-10033 escaping issue.
  • Update bundled copies in WordPress, Joomla and other applications, since they ship their own PHPMailer versions.
  • Where the isMail transport is not required, switch to SMTP transport to remove the shell invocation path.
  • Validate and reject shell metacharacters in any address or header value passed to the mailer.
  • Inventory applications and libraries embedding PHPMailer to find unpatched copies.

Detection

  • Search web server and application logs for mail command arguments containing shell metacharacters or unexpected flags.
  • Monitor for outbound connections or child processes spawned by the web server user that are unusual for the application.
  • Check file integrity and process creation events on hosts running PHP applications that use PHPMailer.
  • Scan deployed code bases for PHPMailer versions below 5.2.20.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://openwall.com/lists/oss-security/2016/12/28/1 Mailing ListPatch
http://packetstormsecurity.com/files/140286/PHPMailer-Remote-Code-Execution.html ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/140350/PHPMailer-Sendmail-Argument-Injection.html ExploitThird Party AdvisoryVDB Entry
http://seclists.org/fulldisclosure/2016/Dec/81 Mailing ListPatchThird Party Advisory
http://www.rapid7.com/db/modules/exploit/multi/http/phpmailer_arg_injection ExploitThird Party Advisory
http://www.securityfocus.com/archive/1/539967/100/0/threaded Third Party AdvisoryVDB Entry
http://www.securityfocus.com/bid/95130 ExploitThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1037533 Third Party AdvisoryVDB Entry
https://developer.joomla.org/security-centre/668-20161205-phpmailer-security-advisory.html Third Party Advisory
https://github.com/PHPMailer/PHPMailer/releases/tag/v5.2.20 PatchVendor Advisory
https://github.com/PHPMailer/PHPMailer/wiki/About-the-CVE-2016-10033-and-CVE-2016-10045-vulnerabilities PatchVendor Advisory
https://legalhackers.com/advisories/PHPMailer-Exploit-Remote-Code-Exec-CVE-2016-10045-Vuln-Patch-Bypass.html ExploitPatchThird Party Advisory
https://www.exploit-db.com/exploits/40969/ ExploitThird Party AdvisoryVDB Entry
https://www.exploit-db.com/exploits/40986/ Third Party AdvisoryVDB Entry
https://www.exploit-db.com/exploits/42221/ Third Party AdvisoryVDB Entry
http://openwall.com/lists/oss-security/2016/12/28/1 Mailing ListPatch
http://packetstormsecurity.com/files/140286/PHPMailer-Remote-Code-Execution.html ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/140350/PHPMailer-Sendmail-Argument-Injection.html ExploitThird Party AdvisoryVDB Entry
http://seclists.org/fulldisclosure/2016/Dec/81 Mailing ListPatchThird Party Advisory
http://www.rapid7.com/db/modules/exploit/multi/http/phpmailer_arg_injection ExploitThird Party Advisory
http://www.securityfocus.com/archive/1/539967/100/0/threaded Third Party AdvisoryVDB Entry
http://www.securityfocus.com/bid/95130 ExploitThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1037533 Third Party AdvisoryVDB Entry
https://developer.joomla.org/security-centre/668-20161205-phpmailer-security-advisory.html Third Party Advisory
https://github.com/PHPMailer/PHPMailer/releases/tag/v5.2.20 PatchVendor Advisory
https://github.com/PHPMailer/PHPMailer/wiki/About-the-CVE-2016-10033-and-CVE-2016-10045-vulnerabilities PatchVendor Advisory
https://legalhackers.com/advisories/PHPMailer-Exploit-Remote-Code-Exec-CVE-2016-10045-Vuln-Patch-Bypass.html ExploitPatchThird Party Advisory
https://www.exploit-db.com/exploits/40969/ ExploitThird Party AdvisoryVDB Entry
https://www.exploit-db.com/exploits/40986/ Third Party AdvisoryVDB Entry
https://www.exploit-db.com/exploits/42221/ Third Party AdvisoryVDB Entry

Track CVE-2016-10045 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-63030WordPress REST API route confusion leads to SQL injection and RCEWordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 contain a REST API batch endpoint route confusion flaw (CWE-436). Chained with the author__not_in…KEVEPSS 10%analysed9.8CVE-2016-10033PHPMailer isMail mailSend argument injection enables remote code executionPHPMailer before 5.2.18 fails to properly sanitize the Sender property in the mailSend function of the isMail transport, allowing a crafted backslash…KEVEPSS 100%analysed5.9CVE-2026-60137WordPress WP_Query author__not_in SQL injectionWordPress core fails to properly sanitise the author__not_in parameter of WP_Query in versions before 6.8.6, 6.9.5 and 7.0.2, allowing SQL injection …KEVEPSS 5.9%analysed5.3CVE-2023-23752Joomla! webservice endpoints improper access checkJoomla! 4.0.0 through 4.2.7 contains an improper access check that allows unauthenticated access to webservice endpoints. Because the endpoints can e…KEVEPSS 100%analysed10.0CVE-2012-2399Wordpress vulnerabilityCross-site scripting (XSS) vulnerability in swfupload.swf in SWFupload 2.2.0.1 and earlier, as used in WordPress before 3.5.2, TinyMCE Image Manager …EPSS 8.6%10.0CVE-2012-2400Wordpress vulnerabilityUnspecified vulnerability in wp-includes/js/swfobject.js in WordPress before 3.3.2 has unknown impact and attack vectors.EPSS 3.0%10.0CVE-2011-3125Wordpress vulnerabilityUnspecified vulnerability in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 has unknown impact and attack vectors related to "Various security hard…EPSS 2.4%10.0CVE-2011-3122Wordpress vulnerabilityUnspecified vulnerability in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 has unknown impact and attack vectors related to "Media security."EPSS 2.6%

Source: NIST National Vulnerability Database (record CVE-2016-10045), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.