Known Vulnerabilities for Smarty by Smarty-php
Listed below are 8 of the newest known vulnerabilities associated with "Smarty" by "Smarty-php".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-62996 json | Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. From 5.0.... | Not Provided | 2026-08-07 | 2026-08-07 |
| CVE-2026-62993 json | Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to ... | Not Provided | 2026-08-31 | 2026-09-02 |
| CVE-2026-62992 json | Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to ... | Not Provided | 2026-08-07 | 2026-08-07 |
| CVE-2026-56785 json | FlatPress contains a stored cross-site scripting vulnerability in comment and contact forms where name, URL, and email fields... | Not Provided | 2026-06-23 | 2026-06-24 |
| CVE-2026-54390 json | JTL Shop versions 5.2.0 through 5.7.1 contains a server-side template injection vulnerability that allows unauthenticated att... | Not Provided | 2026-06-18 | 2026-06-23 |
| CVE-2026-50745 json | A missing sanitisation vulnerability exists with user input in the stats-video.php script. The way URLs to this script were c... | Not Provided | 2026-06-26 | 2026-06-26 |
| CVE-2026-38725 json | xipblog module v2.0.1 and before for PrestaShop allows unauthenticated remote attackers to inject arbitrary JavaScript via th... | Not Provided | 2026-08-28 | 2026-08-28 |
| CVE-2026-14453 json | This vulnerability is a critical Server-Side Template Injection (SSTI) in Centreon's centreon-open-tickets module that leads ... | Not Provided | 2026-07-13 | 2026-07-13 |