296,746
Total vulnerabilities in the database
PHPMailer 6.1.8 through 6.4.0 allows object injection through Phar Deserialization via addAttachment with a UNC pathname. NOTE: this is similar to CVE-2018-19296, but arose because 6.1.8 fixed a functionality problem in which UNC pathnames were always considered unreadable by PHPMailer, even in safe contexts. As an unintended side effect, this fix eliminated the code that blocked addAttachment exploitation.
| Software | From | Fixed in |
|---|---|---|
| phpmailer_project / phpmailer | 6.1.8 | 6.4.0.x |
| WordPress / wordpress | 5.7 | 5.7.2 |
| WordPress / wordpress | 5.6 | 5.6.4 |
| WordPress / wordpress | 5.5 | 5.5.5 |
| WordPress / wordpress | 5.4 | 5.4.6 |
| WordPress / wordpress | 4.6 | 4.6.21 |
| WordPress / wordpress | 4.7 | 4.7.21 |
| WordPress / wordpress | 4.8 | 4.8.17 |
| WordPress / wordpress | 4.9 | 4.9.18 |
| WordPress / wordpress | 5.0 | 5.0.13 |
| WordPress / wordpress | 5.1 | 5.1.10 |
| WordPress / wordpress | 5.2 | 5.2.11 |
| WordPress / wordpress | 5.3 | 5.3.8 |
| WordPress / wordpress | 3.7 | 3.7.36 |
| WordPress / wordpress | 3.8 | 3.8.36 |
| WordPress / wordpress | 3.9 | 3.9.34 |
| WordPress / wordpress | 4.0 | 4.0.33 |
| WordPress / wordpress | 4.1 | 4.1.33 |
| WordPress / wordpress | 4.2 | 4.2.30 |
| WordPress / wordpress | 4.3 | 4.3.26 |
| WordPress / wordpress | 4.4 | 4.4.25 |
| WordPress / wordpress | 4.5 | 4.5.24 |
phpmailer / phpmailer
|
6.1.8 | 6.4.1 |