CVE-2021-26120
CVE-2021-26120 is a critical-severity vulnerability in Smarty with a CVSS 3.x base score of 9.8. Its EPSS exploit-prediction score of 82% places it in the 100th percentile, indicating an elevated likelihood of exploitation. The underlying weakness is classified as CWE-94.
Key facts
- Severity: Critical (CVSS 3.x base score 9.8)
- CVSS v2: 7.5
- EPSS exploit prediction: 82% (100th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-94
- Affected product: Smarty
- Published:
- Last modified:
Description
Smarty before 3.1.39 allows code injection via an unexpected function name after a {function name= substring.
Frequently asked questions
- What is CVE-2021-26120?
- Smarty before 3.1.39 allows code injection via an unexpected function name after a {function name= substring.
- How severe is CVE-2021-26120?
- CVE-2021-26120 has a CVSS 3.x base score of 9.8, rated critical severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2021-26120 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 82% (100th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2021-26120?
- CVE-2021-26120 primarily affects Smarty. In total, 4 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2021-26120?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its critical severity, prioritise patching exposed systems.
- When was CVE-2021-26120 published?
- CVE-2021-26120 was published on 2021-02-22 and last updated on 2026-06-17.
References
- https://github.com/smarty-php/smarty/blob/master/CHANGELOG.md
- https://lists.debian.org/debian-lts-announce/2021/04/msg00004.html
- https://lists.debian.org/debian-lts-announce/2021/04/msg00014.html
- https://security.gentoo.org/glsa/202105-06
- https://www.debian.org/security/2022/dsa-5151
Affected products (4)
- cpe:2.3:a:smarty:smarty:*:*:*:*:*:*:*:*
- cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
- cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
- cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
More vulnerabilities in Smarty
- CVE-2010-4727 — Critical (CVSS 10.0): Smarty before 3.0.0 beta 7 does not properly handle the <?php and ?> tags, which has unspecified impact and remote…
- CVE-2010-4726 — Critical (CVSS 10.0): Unspecified vulnerability in the math plugin in Smarty before 3.0.0 RC1 has unknown impact and remote attack vectors.…
- CVE-2010-4725 — Critical (CVSS 10.0): Smarty before 3.0.0 RC3 does not properly handle an on value of the asp_tags option in the php.ini file, which has…
- CVE-2010-4724 — Critical (CVSS 10.0): Multiple unspecified vulnerabilities in the parser implementation in Smarty before 3.0.0 RC3 have unknown impact and…
- CVE-2010-4722 — Critical (CVSS 10.0): Unspecified vulnerability in the fetch plugin in Smarty before 3.0.2 has unknown impact and remote attack vectors.
- CVE-2009-5052 — Critical (CVSS 10.0): Multiple unspecified vulnerabilities in Smarty before 3.0.0 beta 6 have unknown impact and attack vectors.
Other CWE-94 (Code Injection) vulnerabilities
- CVE-2026-105857 — Critical (CVSS 10.0): Payload is a free and open source headless content management system. In @payloadcms/plugin-form-builder versions…
- CVE-2026-55107 — Critical (CVSS 10.0): Kobako is a Ruby gem that embeds a Wasm-isolated mruby interpreter inside applications, allowing execution of untrusted…
- CVE-2026-96349 — Critical (CVSS 10.0): Unauthenticated Remote Code Execution (RCE) in SiteSkite <= 2.1.8 versions.
- CVE-2026-102425 — Critical (CVSS 10.0): Joomla Extension - balbooa.com - Unauthenticated RCE via field shortcode injection in Balbooa Forms < 2.4.3.4 - Balbooa…
- CVE-2026-89275 — Critical (CVSS 10.0): Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability…
- CVE-2026-84412 — Critical (CVSS 10.0): Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability…