What are common pitfalls when using PHP to process form data and send it via email?

One common pitfall when using PHP to process form data and send it via email is not properly sanitizing user input, which can leave your application vulnerable to malicious attacks like SQL injection or cross-site scripting. To solve this issue, always use functions like htmlspecialchars() or mysqli_real_escape_string() to sanitize user input before using it in your email.

// Sanitize user input before using it in the email
$name = htmlspecialchars($_POST['name']);
$email = htmlspecialchars($_POST['email']);
$message = htmlspecialchars($_POST['message']);

// Send email using sanitized data
$to = "your@email.com";
$subject = "New message from website";
$body = "Name: $name\nEmail: $email\nMessage: $message";

// Additional headers
$headers = "From: $email";

// Send email
mail($to, $subject, $body, $headers);