{"id":"CVE-2014-8350","aliases":["GHSA-2pmx-6mm6-6v72"],"url":"https://o3.security/vulnerability/CVE-2014-8350","summary":"Smarty arbitrary PHP code execution","details":"Smarty before 3.1.21 allows remote attackers to bypass the secure mode restrictions and execute arbitrary PHP code as demonstrated by \"{literal}<{/literal}script language=php>\" in a template.","published":"2014-11-03T16:55:08Z","modified":"2026-04-16T06:25:34.201316259Z","cvss":null,"epss":{"score":0.03127,"percentile":0.87228,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":3,"affectedPackages":[{"ecosystem":"Packagist","name":"smarty/smarty","fixedVersion":"3.1.21"}],"fix":null,"references":[{"type":"ADVISORY","url":"http://advisories.mageia.org/MGASA-2014-0468.html"},{"type":"ADVISORY","url":"http://www.mandriva.com/security/advisories?name=MDVSA-2014:221"},{"type":"EVIDENCE","url":"http://seclists.org/oss-sec/2014/q4/420"},{"type":"EVIDENCE","url":"http://seclists.org/oss-sec/2014/q4/421"},{"type":"EVIDENCE","url":"https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=765920"},{"type":"WEB","url":"http://www.securityfocus.com/bid/70708"},{"type":"WEB","url":"https://code.google.com/p/smarty-php/source/browse/trunk/distribution/change_log.txt?r=4902"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/97725"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-04-16T06:25:34.201316259Z"}}