CVE-2017-1000480: Smarty

Critical severity, CVSS 9.8. EPSS: 3.1% chance of exploitation in the next 30 days.

Smarty 3 before 3.1.32 is vulnerable to a PHP code injection when calling fetch() or display() functions on custom resources that does not sanitize template name.

Affected products

  • Smarty Smarty: from 3.0.0, before 3.1.32 (fixed in 3.1.32)

Published 2018-01-03. Last modified 2026-06-17.