{"api_version":"v1","generated_at":"2026-10-07T06:40:00+00:00","product":{"cve_count":8,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-smarty-php-smarty-de9b79d20868","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/smarty","name":"smarty","next_cursor":null,"observations":[{"affected":">= 5.0.0, < 5.8.2; < 4.5.7","affected_versions_present":true,"cve_id":"CVE-2026-62993","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-62993","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-02T17:36:30.257Z","patch_url":"","primary_source":"","published":"2026-08-31T20:58:03.616Z"},{"affected":">= 5.0.0, < 5.8.4","affected_versions_present":true,"cve_id":"CVE-2026-62996","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-62996","fixed":"5.8.4.","last_modified":"2026-08-07T17:08:09.710Z","patch_url":"https://github.com/smarty-php/smarty/security/advisories/GHSA-rjhh-76wf-8xmw","primary_source":"","published":"2026-08-07T15:04:52.662Z"},{"affected":">= 5.0.0, < 5.8.2; < 4.5.7","affected_versions_present":true,"cve_id":"CVE-2026-62992","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-62992","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-07T16:00:28.634Z","patch_url":"","primary_source":"","published":"2026-08-07T15:02:28.873Z"},{"affected":">= 5.0.0, < 5.1.1; >= 3.0.0, < 4.5.3","affected_versions_present":true,"cve_id":"CVE-2024-35226","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-35226","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-11-03T21:54:58.981Z","patch_url":"","primary_source":"","published":"2024-05-28T20:55:00.884Z"},{"affected":">= 4.0.0, < 4.3.1; < 3.1.48","affected_versions_present":true,"cve_id":"CVE-2023-28447","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-28447","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-11-03T21:47:36.097Z","patch_url":"https://github.com/smarty-php/smarty/commit/685662466f653597428966d75a661073104d713d","primary_source":"","published":"2023-03-28T20:07:39.103Z"},{"affected":"< 3.1.45; >= 4.0.0, < 4.1.1","affected_versions_present":true,"cve_id":"CVE-2022-29221","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-29221","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-04-23T18:22:54.999Z","patch_url":"https://github.com/smarty-php/smarty/commit/64ad6442ca1da31cefdab5c9874262b702cccddd","primary_source":"","published":"2022-05-24T00:00:00.000Z"},{"affected":"< 3.1.42; >= 4.0.0, < 4.0.2","affected_versions_present":true,"cve_id":"CVE-2021-29454","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-29454","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-04-23T19:14:05.629Z","patch_url":"https://github.com/smarty-php/smarty/commit/215d81a9fa3cd63d82fb3ab56ecaf97cf1e7db71","primary_source":"","published":"2022-01-10T00:00:00.000Z"},{"affected":"< 3.1.43; >= 4.0.0, < 4.0.3","affected_versions_present":true,"cve_id":"CVE-2021-21408","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-21408","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-04-23T19:14:12.719Z","patch_url":"https://github.com/smarty-php/smarty/commit/19ae410bf56007a5ef24441cdc6414619cfaf664","primary_source":"","published":"2022-01-10T00:00:00.000Z"}],"source_generated_at":"2026-10-06T06:22:27.870Z","vendor":"smarty-php"}}
