CVE-2026-82531
- EPSS 0.82%
- Veröffentlicht 06.10.2026 12:18:31
- Zuletzt bearbeitet 06.10.2026 16:00:36
Smarty before 4.5.8 and 5.x before 5.8.5 contains a code injection vulnerability where the top-level nocache_hash is never restored during extends:/multi-component template inheritance, leaving it null. Attackers can supply assigned data containing a...
CVE-2026-62993
- EPSS 0.42%
- Veröffentlicht 31.08.2026 20:58:03
- Zuletzt bearbeitet 08.09.2026 21:11:31
Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to 4.5.7 and 5.8.2, depending on the release line, Smarty's {fetch} handling in libs/plugins/function.fetch.php and src/Function...
CVE-2026-62996
- EPSS 0.35%
- Veröffentlicht 07.08.2026 15:04:52
- Zuletzt bearbeitet 09.09.2026 21:02:22
Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. From 5.0.0 until 5.8.4, Smarty's stream: resource-name handling does not adequately restrict which PHP stream wrappers and filter chai...
CVE-2026-62992
- EPSS 0.36%
- Veröffentlicht 07.08.2026 15:02:28
- Zuletzt bearbeitet 09.09.2026 21:02:22
Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to 5.8.2 (and 4.5.7 on the 4.x line), Security::_checkDir() does not fully resolve symbolic links before validating that a reque...
CVE-2023-41661
- EPSS 0.36%
- Veröffentlicht 29.09.2023 14:15:10
- Zuletzt bearbeitet 21.11.2024 08:21:26
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PressPage Entertainment Inc. Smarty for WordPress plugin <= 3.1.35 versions.
CVE-2023-28447
- EPSS 1.03%
- Veröffentlicht 28.03.2023 21:15:11
- Zuletzt bearbeitet 03.11.2025 22:16:06
Smarty is a template engine for PHP. In affected versions smarty did not properly escape javascript code. An attacker could exploit this vulnerability to execute arbitrary JavaScript code in the context of the user's browser session. This may lead to...
CVE-2018-25047
- EPSS 0.87%
- Veröffentlicht 15.09.2022 00:15:09
- Zuletzt bearbeitet 03.11.2025 22:15:45
In Smarty before 3.1.47 and 4.x before 4.2.1, libs/plugins/function.mailto.php allows XSS. A web page that uses smarty_function_mailto, and that could be parameterized using GET or POST input parameters, could allow injection of JavaScript code by a ...
CVE-2022-29221
- EPSS 4.91%
- Veröffentlicht 24.05.2022 15:15:07
- Zuletzt bearbeitet 21.11.2024 06:58:44
Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to versions 3.1.45 and 4.1.1, template authors could inject php code by choosing a malicious {block} name or {include} file name...
CVE-2021-29454
- EPSS 1.93%
- Veröffentlicht 10.01.2022 20:15:08
- Zuletzt bearbeitet 21.11.2024 06:01:08
Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to versions 3.1.42 and 4.0.2, template authors could run arbitrary PHP code by crafting a malicious math string. If a math strin...
CVE-2021-21408
- EPSS 2.22%
- Veröffentlicht 10.01.2022 20:15:07
- Zuletzt bearbeitet 21.11.2024 05:48:17
Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to versions 3.1.43 and 4.0.3, template authors could run restricted static php methods. Users should upgrade to version 3.1.43 o...