VUMETRIC
CYBER PORTAL
Dashboard
Security News
Latest Vulnerabilities
Browse Vulnerabilities
by Vendors
by Products
by Categories
Weekly Reports
Vulnerabilities
> Smarty
Exclude new CVEs:
DATE
CVE
VULNERABILITY TITLE
RISK
2023-09-29
CVE-2023-41661
Unspecified vulnerability in Smarty
Auth.
network
low complexity
smarty
4.8
4.8
2023-03-28
CVE-2023-28447
Cross-site Scripting vulnerability in multiple products
Smarty is a template engine for PHP.
network
low complexity
smarty
fedoraproject
CWE-79
6.1
6.1
2022-09-15
CVE-2018-25047
Cross-site Scripting vulnerability in multiple products
In Smarty before 3.1.47 and 4.x before 4.2.1, libs/plugins/function.mailto.php allows XSS.
network
low complexity
smarty
debian
CWE-79
5.4
5.4
2022-05-24
CVE-2022-29221
Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic.
network
low complexity
smarty
debian
fedoraproject
8.8
8.8
2022-01-10
CVE-2021-21408
Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic.
network
low complexity
smarty
debian
fedoraproject
8.8
8.8
2022-01-10
CVE-2021-29454
Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic.
network
low complexity
smarty
debian
fedoraproject
8.8
8.8
2021-02-22
CVE-2021-26120
Code Injection vulnerability in multiple products
Smarty before 3.1.39 allows code injection via an unexpected function name after a {function name= substring.
network
low complexity
smarty
debian
CWE-94
critical
9.8
9.8
2021-02-22
CVE-2021-26119
Smarty before 3.1.39 allows a Sandbox Escape because $smarty.template_object can be accessed in sandbox mode.
network
low complexity
smarty
debian
7.5
7.5
2019-11-20
CVE-2011-1028
Improper Input Validation vulnerability in multiple products
The $smarty.template variable in Smarty3 allows attackers to possibly execute arbitrary PHP code via the sysplugins/smarty_internal_compile_private_special_variable.php file.
network
low complexity
smarty
debian
CWE-20
critical
9.8
9.8
2018-09-18
CVE-2018-13982
Path Traversal vulnerability in multiple products
Smarty_Security::isTrustedResourceDir() in Smarty before 3.1.33 is prone to a path traversal vulnerability due to insufficient template code sanitization.
network
low complexity
smarty
debian
CWE-22
7.5
7.5
«
1
(current)
2
»
Next