smarty records
31 published records for vendor smarty.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 12
- With a fix record
- 87.1%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-94 Improper Control of Generation of Code ('Code Injection')6
- CWE-20 Improper Input Validation5
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-264 Permissions, Privileges, and Access Controls3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
31 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
64This week | CVE-2021-26120No exploit | Smarty before 3.1.39 allows code injection via an unexpected function name after a {function name= substring.smarty · smarty · CWE-94 | Critical9.8 | — | 82.3% | Feb 21, 2021 |
44Plan | CVE-2009-1669Proof of concept | The smarty_function_math function in libs/plugins/function.math.php in Smarty 2.6.22 allows context-dependent attackers to execute arbitrarysmarty · smarty · CWE-20 | Critical10.0 | — | 14.1% | May 18, 2009 |
41Plan | CVE-2010-4724No exploit | Multiple unspecified vulnerabilities in the parser implementation in Smarty before 3.0.0 RC3 have unknown impact and remote attack vectors.smarty · smarty | Critical10.0 | — | 1.9% | Feb 3, 2011 |
41Plan | CVE-2009-5052No exploit | Multiple unspecified vulnerabilities in Smarty before 3.0.0 beta 6 have unknown impact and attack vectors.smarty · smarty | Critical10.0 | — | 1.9% | Feb 3, 2011 |
41Plan | CVE-2010-4727No exploit | Smarty before 3.0.0 beta 7 does not properly handle the <?php and ?> tags, which has unspecified impact and remote attack vectors.smarty · smarty · CWE-20 | Critical10.0 | — | 1.9% | Feb 3, 2011 |
41Plan | CVE-2010-4726No exploit | Unspecified vulnerability in the math plugin in Smarty before 3.0.0 RC1 has unknown impact and remote attack vectors.smarty · smarty | Critical10.0 | — | 1.9% | Feb 3, 2011 |
41Plan | CVE-2010-4722No exploit | Unspecified vulnerability in the fetch plugin in Smarty before 3.0.2 has unknown impact and remote attack vectors.smarty · smarty | Critical10.0 | — | 1.9% | Feb 3, 2011 |
41Plan | CVE-2010-4725No exploit | Smarty before 3.0.0 RC3 does not properly handle an on value of the asp_tags option in the php.ini file, which has unspecified impact and resmarty · smarty | Critical10.0 | — | 1.9% | Feb 3, 2011 |
40Plan | CVE-2017-1000480No exploit | Smarty 3 before 3.1.32 is vulnerable to a PHP code injection when calling fetch() or display() functions on custom resources that does not ssmarty · smarty · CWE-94 | Critical9.8 | — | 3.1% | Jan 3, 2018 |
40Plan | CVE-2006-7105No exploit | PHP remote file inclusion vulnerability in libs/Smarty.class.php in Smarty 2.6.9 allows remote attackers to execute arbitrary PHP code via asmarty · smarty · CWE-94 | Critical9.8 | — | 1.8% | Mar 3, 2007 |
39Monitor | CVE-2011-1028No exploit | The $smarty.template variable in Smarty3 allows attackers to possibly execute arbitrary PHP code via the sysplugins/smarty_internal_compile_smarty · smarty · CWE-20 | Critical9.8 | — | 1.6% | Nov 20, 2019 |
37Monitor | CVE-2010-4723No exploit | Smarty before 3.0.0, when security is enabled, does not prevent access to the (1) dynamic and (2) private object members of an assigned objesmarty · smarty · CWE-264 | Critical9.3 | — | 1.7% | Feb 3, 2011 |
36Monitor | CVE-2022-29221Proof of concept | PHP Code Injection by malicious block or filename in Smartysmarty · smarty · CWE-94 | High8.8 | — | 4.9% | May 24, 2022 |
36Monitor | CVE-2021-21408No exploit | Access to restricted PHP code by dynamic static class access in smartysmarty · smarty · CWE-20 | High8.8 | — | 2.2% | Jan 10, 2022 |
36Monitor | CVE-2021-29454No exploit | Sandbox Escape by math function in smartysmarty · smarty · CWE-74 | High8.8 | — | 1.9% | Jan 10, 2022 |
33Monitor | CVE-2021-26119No exploit | Smarty before 3.1.39 allows a Sandbox Escape because $smarty.template_object can be accessed in sandbox mode.smarty · smarty | High7.5 | — | 9.4% | Feb 21, 2021 |
31Monitor | CVE-2018-13982No exploit | Smarty_Security::isTrustedResourceDir() in Smarty before 3.1.33 is prone to a path traversal vulnerability due to insufficient template codesmarty · smarty · CWE-22 | High7.5 | — | 3.5% | Sep 18, 2018 |
31Monitor | CVE-2014-8350No exploit | Smarty before 3.1.21 allows remote attackers to bypass the secure mode restrictions and execute arbitrary PHP code as demonstrated by "{litesmarty · smarty · CWE-94 | High7.5 | — | 3.1% | Nov 3, 2014 |
31Monitor | CVE-2008-4810No exploit | The _expand_quoted_text function in libs/Smarty_Compiler.class.php in Smarty 2.6.20 before r2797 allows remote attackers to execute arbitrarsmarty · smarty · CWE-94 | High7.5 | — | 2.2% | Oct 31, 2008 |
31Monitor | CVE-2009-5053No exploit | Unspecified vulnerability in Smarty before 3.0.0 beta 6 allows remote attackers to execute arbitrary PHP code by injecting this code into a smarty · smarty | High7.5 | — | 2.1% | Feb 3, 2011 |
31Monitor | CVE-2008-1066No exploit | The modifier.regex_replace.php plugin in Smarty before 2.6.19, as used by Serendipity (S9Y) and other products, allows attackers to call arbsmarty · smarty · CWE-20 | High7.5 | — | 2.0% | Feb 28, 2008 |
30Monitor | CVE-2008-4811No exploit | The _expand_quoted_text function in libs/Smarty_Compiler.class.php in Smarty 2.6.20 r2797 and earlier allows remote attackers to execute arbsmarty · smarty · CWE-264 | High7.5 | — | 1.6% | Oct 31, 2008 |
30Monitor | CVE-2009-5054No exploit | Smarty before 3.0.0 beta 4 does not consider the umask value when setting the permissions of files, which might allow attackers to bypass insmarty · smarty · CWE-264 | High7.5 | — | 1.6% | Feb 3, 2011 |
30Monitor | CVE-2005-0913No exploit | Unknown vulnerability in the regex_replace modifier (modifier.regex_replace.php) in Smarty before 2.6.8 allows attackers to execute arbitrarsmarty · smarty | High7.5 | — | 1.5% | May 2, 2005 |
30Monitor | CVE-2006-7193No exploit | PHP remote file inclusion vulnerability in unit_test/test_cases.php in Smarty 2.6.1 allows remote attackers to execute arbitrary PHP code vismarty · smarty | High7.5 | — | 1.5% | Apr 12, 2007 |
- CVE-2021-2612064This week
Smarty before 3.1.39 allows code injection via an unexpected function name after a {function name= substring.
CriticalCVSS 9.8No exploitEPSS 82%smarty · smartyFeb 21, 2021
- CVE-2009-166944Plan
The smarty_function_math function in libs/plugins/function.math.php in Smarty 2.6.22 allows context-dependent attackers to execute arbitrary
CriticalCVSS 10.0Proof of conceptEPSS 14%smarty · smartyMay 18, 2009
- CVE-2010-472441Plan
Multiple unspecified vulnerabilities in the parser implementation in Smarty before 3.0.0 RC3 have unknown impact and remote attack vectors.
CriticalCVSS 10.0No exploitEPSS 2%smarty · smartyFeb 3, 2011
- CVE-2009-505241Plan
Multiple unspecified vulnerabilities in Smarty before 3.0.0 beta 6 have unknown impact and attack vectors.
CriticalCVSS 10.0No exploitEPSS 2%smarty · smartyFeb 3, 2011
- CVE-2010-472741Plan
Smarty before 3.0.0 beta 7 does not properly handle the <?php and ?> tags, which has unspecified impact and remote attack vectors.
CriticalCVSS 10.0No exploitEPSS 2%smarty · smartyFeb 3, 2011
- CVE-2010-472641Plan
Unspecified vulnerability in the math plugin in Smarty before 3.0.0 RC1 has unknown impact and remote attack vectors.
CriticalCVSS 10.0No exploitEPSS 2%smarty · smartyFeb 3, 2011
- CVE-2010-472241Plan
Unspecified vulnerability in the fetch plugin in Smarty before 3.0.2 has unknown impact and remote attack vectors.
CriticalCVSS 10.0No exploitEPSS 2%smarty · smartyFeb 3, 2011
- CVE-2010-472541Plan
Smarty before 3.0.0 RC3 does not properly handle an on value of the asp_tags option in the php.ini file, which has unspecified impact and re
CriticalCVSS 10.0No exploitEPSS 2%smarty · smartyFeb 3, 2011
- CVE-2017-100048040Plan
Smarty 3 before 3.1.32 is vulnerable to a PHP code injection when calling fetch() or display() functions on custom resources that does not s
CriticalCVSS 9.8No exploitEPSS 3%smarty · smartyJan 3, 2018
- CVE-2006-710540Plan
PHP remote file inclusion vulnerability in libs/Smarty.class.php in Smarty 2.6.9 allows remote attackers to execute arbitrary PHP code via a
CriticalCVSS 9.8No exploitEPSS 2%smarty · smartyMar 3, 2007
- CVE-2011-102839Monitor
The $smarty.template variable in Smarty3 allows attackers to possibly execute arbitrary PHP code via the sysplugins/smarty_internal_compile_
CriticalCVSS 9.8No exploitEPSS 2%smarty · smartyNov 20, 2019
- CVE-2010-472337Monitor
Smarty before 3.0.0, when security is enabled, does not prevent access to the (1) dynamic and (2) private object members of an assigned obje
CriticalCVSS 9.3No exploitEPSS 2%smarty · smartyFeb 3, 2011
- CVE-2022-2922136Monitor
PHP Code Injection by malicious block or filename in Smarty
HighCVSS 8.8Proof of conceptEPSS 5%smarty · smartyMay 24, 2022
- CVE-2021-2140836Monitor
Access to restricted PHP code by dynamic static class access in smarty
HighCVSS 8.8No exploitEPSS 2%smarty · smartyJan 10, 2022
- CVE-2021-2945436Monitor
Sandbox Escape by math function in smarty
HighCVSS 8.8No exploitEPSS 2%smarty · smartyJan 10, 2022
- CVE-2021-2611933Monitor
Smarty before 3.1.39 allows a Sandbox Escape because $smarty.template_object can be accessed in sandbox mode.
HighCVSS 7.5No exploitEPSS 9%smarty · smartyFeb 21, 2021
- CVE-2018-1398231Monitor
Smarty_Security::isTrustedResourceDir() in Smarty before 3.1.33 is prone to a path traversal vulnerability due to insufficient template code
HighCVSS 7.5No exploitEPSS 3%smarty · smartySep 18, 2018
- CVE-2014-835031Monitor
Smarty before 3.1.21 allows remote attackers to bypass the secure mode restrictions and execute arbitrary PHP code as demonstrated by "{lite
HighCVSS 7.5No exploitEPSS 3%smarty · smartyNov 3, 2014
- CVE-2008-481031Monitor
The _expand_quoted_text function in libs/Smarty_Compiler.class.php in Smarty 2.6.20 before r2797 allows remote attackers to execute arbitrar
HighCVSS 7.5No exploitEPSS 2%smarty · smartyOct 31, 2008
- CVE-2009-505331Monitor
Unspecified vulnerability in Smarty before 3.0.0 beta 6 allows remote attackers to execute arbitrary PHP code by injecting this code into a
HighCVSS 7.5No exploitEPSS 2%smarty · smartyFeb 3, 2011
- CVE-2008-106631Monitor
The modifier.regex_replace.php plugin in Smarty before 2.6.19, as used by Serendipity (S9Y) and other products, allows attackers to call arb
HighCVSS 7.5No exploitEPSS 2%smarty · smartyFeb 28, 2008
- CVE-2008-481130Monitor
The _expand_quoted_text function in libs/Smarty_Compiler.class.php in Smarty 2.6.20 r2797 and earlier allows remote attackers to execute arb
HighCVSS 7.5No exploitEPSS 2%smarty · smartyOct 31, 2008
- CVE-2009-505430Monitor
Smarty before 3.0.0 beta 4 does not consider the umask value when setting the permissions of files, which might allow attackers to bypass in
HighCVSS 7.5No exploitEPSS 2%smarty · smartyFeb 3, 2011
- CVE-2005-091330Monitor
Unknown vulnerability in the regex_replace modifier (modifier.regex_replace.php) in Smarty before 2.6.8 allows attackers to execute arbitrar
HighCVSS 7.5No exploitEPSS 2%smarty · smartyMay 2, 2005
- CVE-2006-719330Monitor
PHP remote file inclusion vulnerability in unit_test/test_cases.php in Smarty 2.6.1 allows remote attackers to execute arbitrary PHP code vi
HighCVSS 7.5No exploitEPSS 1%smarty · smartyApr 12, 2007