Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Smarty

First CVE: May 2, 2005Active for: 21 yearsTotal CVEs: 31
61.4
VTI Score
TOP TARGET

Smarty is a template engine and code generation framework with a focused product footprint that occupies a prominent place in web-application development, particularly in legacy and mixed-technology stacks where its template processing remains widely embedded. Vulnerabilities affecting the vendor skew toward critical-severity outcomes and recur through a durable pattern of input-handling and code-generation weaknesses: code injection, cross-site scripting, path traversal, and improper input validation that reflect the risks inherent to dynamic template processing and user-controlled code pathways. The vendor's exposure is concentrated in the Smarty product itself, making the recurring weakness classes especially relevant to any application that accepts untrusted input for template rendering or relies on Smarty's template syntax without strict sandboxing. Defenders should treat Smarty template injection and XSS vectors as high-risk in applications where user input influences template logic, and should prioritize isolation of template processing from untrusted sources. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
31
Total CVEs
More Total CVEs than 97% of tracked vendors
2.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
8.1
Avg CVSS Score
Higher Avg CVSS Score than 78% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Smarty over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 2, 2005
21 years ago
Most Recent CVE
Sep 29, 2023
1,030 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (31 CVEs).

31 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-26120CRITICAL
Smarty before 3.1.39 allows code injection via an unexpected function name after a {function name= substring.
Feb 22, 20219.875NONO
CVE-2009-1669HIGH
The smarty_function_math function in libs/plugins/function.math.php in Smarty 2.6.22 allows context-dependent attackers to execute arbitrary commands via shell metacharacters in th
May 18, 200910.050NOYES
CVE-2011-1028CRITICAL
The $smarty.template variable in Smarty3 allows attackers to possibly execute arbitrary PHP code via the sysplugins/smarty_internal_compile_private_special_variable.php file.
Nov 20, 20199.831NONO
CVE-2022-29221HIGH
Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to versions 3.1.45 and 4.1.1, template authors could injec
May 24, 20228.830NONO
CVE-2021-21408HIGH
Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to versions 3.1.43 and 4.0.3, template authors could run r
Jan 10, 20228.830NONO
CVE-2017-1000480CRITICAL
Smarty 3 before 3.1.32 is vulnerable to a PHP code injection when calling fetch() or display() functions on custom resources that does not sanitize template name.
Jan 3, 20189.830NONO
CVE-2021-29454HIGH
Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to versions 3.1.42 and 4.0.2, template authors could run a
Jan 10, 20228.829NONO
CVE-2021-26119HIGH
Smarty before 3.1.39 allows a Sandbox Escape because $smarty.template_object can be accessed in sandbox mode.
Feb 22, 20217.528NONO
CVE-2010-4727HIGH
Smarty before 3.0.0 beta 7 does not properly handle the <?php and ?> tags, which has unspecified impact and remote attack vectors.
Feb 3, 201110.028NONO
CVE-2010-4726HIGH
Unspecified vulnerability in the math plugin in Smarty before 3.0.0 RC1 has unknown impact and remote attack vectors. NOTE: this might overlap CVE-2009-1669.
Feb 3, 201110.028NONO
View all 31 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products31 CVEs
19%
68%
13%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network13 (41.9%)
Unknown18 (58.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (38.7%)
High1 (3.2%)
Unknown18 (58.1%)
User Interaction
None10 (32.3%)
Unknown18 (58.1%)
Required3 (9.7%)
Privileges Required
Low4 (12.9%)
High1 (3.2%)
None8 (25.8%)
Unknown18 (58.1%)

Exploit Exposure

Signals from CVEs in this vendor scope (31 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
3.2% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Smarty.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Smarty — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Smarty's Products

View all 5 CNAs →

Top CWEs