In Joomla! 1.5.0 through 3.6.5 (fixed in 3.7.0), mail sent using the JMail API leaked the used PHPMailer version in the mail headers.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2017-16953
https://developer.joomla.org/security-centre/683-20170401-core-information-disclosure