{"id":"CVE-2018-19296","aliases":["GHSA-7w4p-72j7-v7c2"],"url":"https://o3.security/vulnerability/CVE-2018-19296","summary":"Phar object injection in PHPMailer","details":"PHPMailer before 5.2.27 and 6.x before 6.0.6 is vulnerable to an object injection attack.","published":"2018-11-16T09:29:00.230Z","modified":"2026-07-08T05:54:29.024058435Z","cvss":{"score":8.8,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Packagist","name":"phpmailer/phpmailer","fixedVersion":"5.2.27"},{"ecosystem":"Packagist","name":"phpmailer/phpmailer","fixedVersion":"6.0.6"}],"fix":null,"references":[{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3B5WDPGUFNPG4NAZ6G4BZX43BKLAVA5B/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KPU66INRFY5BQ3ESVPRUXJR4DXQAFJVT/"},{"type":"ADVISORY","url":"https://github.com/PHPMailer/PHPMailer/releases/tag/v5.2.27"},{"type":"ADVISORY","url":"https://github.com/PHPMailer/PHPMailer/releases/tag/v6.0.6"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2018/12/msg00020.html"},{"type":"ADVISORY","url":"https://www.debian.org/security/2018/dsa-4351"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T05:54:29.024058435Z"}}