Smarty is a template engine and code generation framework with a focused product footprint that occupies a prominent place in web-application development, particularly in legacy and mixed-technology stacks where its template processing remains widely embedded. Vulnerabilities affecting the vendor skew toward critical-severity outcomes and recur through a durable pattern of input-handling and code-generation weaknesses: code injection, cross-site scripting, path traversal, and improper input validation that reflect the risks inherent to dynamic template processing and user-controlled code pathways. The vendor's exposure is concentrated in the Smarty product itself, making the recurring weakness classes especially relevant to any application that accepts untrusted input for template rendering or relies on Smarty's template syntax without strict sandboxing. Defenders should treat Smarty template injection and XSS vectors as high-risk in applications where user input influences template logic, and should prioritize isolation of template processing from untrusted sources. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Smarty over time
Signals from CVEs in this vendor scope (31 CVEs).
31 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-26120CRITICAL Smarty before 3.1.39 allows code injection via an unexpected function name after a {function name= substring. | Feb 22, 2021 | 9.8 | 75 | NO | NO |
CVE-2009-1669HIGH The smarty_function_math function in libs/plugins/function.math.php in Smarty 2.6.22 allows context-dependent attackers to execute arbitrary commands via shell metacharacters in th | May 18, 2009 | 10.0 | 50 | NO | YES |
CVE-2011-1028CRITICAL The $smarty.template variable in Smarty3 allows attackers to possibly execute arbitrary PHP code via the sysplugins/smarty_internal_compile_private_special_variable.php file. | Nov 20, 2019 | 9.8 | 31 | NO | NO |
CVE-2022-29221HIGH Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to versions 3.1.45 and 4.1.1, template authors could injec | May 24, 2022 | 8.8 | 30 | NO | NO |
CVE-2021-21408HIGH Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to versions 3.1.43 and 4.0.3, template authors could run r | Jan 10, 2022 | 8.8 | 30 | NO | NO |
CVE-2017-1000480CRITICAL Smarty 3 before 3.1.32 is vulnerable to a PHP code injection when calling fetch() or display() functions on custom resources that does not sanitize template name. | Jan 3, 2018 | 9.8 | 30 | NO | NO |
CVE-2021-29454HIGH Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to versions 3.1.42 and 4.0.2, template authors could run a | Jan 10, 2022 | 8.8 | 29 | NO | NO |
CVE-2021-26119HIGH Smarty before 3.1.39 allows a Sandbox Escape because $smarty.template_object can be accessed in sandbox mode. | Feb 22, 2021 | 7.5 | 28 | NO | NO |
CVE-2010-4727HIGH Smarty before 3.0.0 beta 7 does not properly handle the <?php and ?> tags, which has unspecified impact and remote attack vectors. | Feb 3, 2011 | 10.0 | 28 | NO | NO |
CVE-2010-4726HIGH Unspecified vulnerability in the math plugin in Smarty before 3.0.0 RC1 has unknown impact and remote attack vectors. NOTE: this might overlap CVE-2009-1669. | Feb 3, 2011 | 10.0 | 28 | NO | NO |
Signals from CVEs in this vendor scope (31 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Smarty.
Media articles that mention a CVE ID that affects a product developed by Smarty — matched by CVE ID, not by vendor name.