{"id":"CVE-2018-25047","aliases":["GHSA-hwq7-5vv9-c6cf"],"url":"https://o3.security/vulnerability/CVE-2018-25047","summary":"Smarty Cross-site Scripting vulnerability in pages that use smarty_function_mailto","details":"In Smarty before 3.1.47 and 4.x before 4.2.1, libs/plugins/function.mailto.php allows XSS. A web page that uses smarty_function_mailto, and that could be parameterized using GET or POST input parameters, could allow injection of JavaScript code by a user.","published":"2022-09-15T00:15:09.580Z","modified":"2026-07-08T05:54:33.031103827Z","cvss":{"score":5.4,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"},"epss":{"score":0.00874,"percentile":0.55778,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Packagist","name":"smarty/smarty","fixedVersion":"3.1.47"},{"ecosystem":"Packagist","name":"smarty/smarty","fixedVersion":"4.2.1"}],"fix":null,"references":[{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2024/11/msg00013.html"},{"type":"ADVISORY","url":"https://github.com/smarty-php/smarty/releases/tag/v3.1.47"},{"type":"ADVISORY","url":"https://github.com/smarty-php/smarty/releases/tag/v4.2.1"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2023/01/msg00002.html"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/202209-09"},{"type":"REPORT","url":"https://bugs.gentoo.org/870100"},{"type":"FIX","url":"https://github.com/smarty-php/smarty/issues/454"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T05:54:33.031103827Z"}}