CVE-2014-8350: Smarty

High severity, CVSS 7.5. EPSS: 3.1% chance of exploitation in the next 30 days.

Smarty before 3.1.21 allows remote attackers to bypass the secure mode restrictions and execute arbitrary PHP code as demonstrated by "{literal}<{/literal}script language=php>" in a template.

Affected products

  • Smarty Smarty: up to and including 3.1.20; version 1.0 only; version 1.0a only; version 1.0b only; version 1.1.0 only; version 1.2.0 only; …

Published 2014-11-03. Last modified 2026-06-17.