Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. In affected versions template authors could inject php code by choosing a malicious file name for an extends-tag. Sites that cannot fully trust template authors should update asap. All users are advised to update. There is no patch for users on the v3 branch. There are no known workarounds for this vulnerability.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3956-1 | smarty3 security update |
Debian DSA |
DSA-5826-1 | smarty3 security update |
Debian DSA |
DSA-5830-1 | smarty4 security update |
EUVD |
EUVD-2024-1424 | Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. In affected versions template authors could inject php code by choosing a malicious file name for an extends-tag. Sites that cannot fully trust template authors should update asap. All users are advised to update. There is no patch for users on the v3 branch. There are no known workarounds for this vulnerability. |
Github GHSA |
GHSA-4rmg-292m-wg3w | Smarty vulnerable to PHP Code Injection by malicious attribute in extends-tag |
Ubuntu USN |
USN-7158-1 | Smarty vulnerabilities |
Ubuntu USN |
USN-7377-1 | Smarty vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 03 Nov 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 03 Nov 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Smarty-php
Smarty-php smarty |
|
| CPEs | cpe:2.3:a:smarty-php:smarty:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Smarty-php
Smarty-php smarty |
|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-11-03T21:54:58.981Z
Reserved: 2024-05-14T15:39:41.784Z
Link: CVE-2024-35226
Updated: 2025-11-03T21:54:58.981Z
Status : Awaiting Analysis
Published: 2024-05-28T21:16:30.947
Modified: 2025-11-03T22:16:56.153
Link: CVE-2024-35226
No data.
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Github GHSA
Ubuntu USN