PT-2026-42389 · Smarty · Smarty

Published

2026-05-19

·

Updated

2026-05-19

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Smarty versions prior to 3.1.21-1ubuntu1+esm2
Description Smarty fails to properly escape JavaScript code, which could allow an attacker to conduct a cross-site scripting attack. Cross-site scripting is a technique where malicious scripts are injected into otherwise benign and trusted websites.
Recommendations Update to version 3.1.21-1ubuntu1+esm2.

Related Identifiers

USN-8272-1

Affected Products

Smarty