← Vulnerability feed

Vulnerability record · CVE-2009-1669 · published 18 May 2009

CVE-2009-1669: Smarty improper input validation vulnerability

Smarty · Smarty

The smarty_function_math function in libs/plugins/function.math.php in Smarty 2.6.22 allows context-dependent attackers to execute arbitrary commands via shell metacharacters in the equation attribute of the math function. NOTE: some of these details are obtained from third party information.

10.0 CVSS 2.0 High EPSS 14% · top 3.6% CWE-20 · Improper input validation
10.0CVSS 2.0 base score
14%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
20References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

The smarty_function_math function in libs/plugins/function.math.php in Smarty 2.6.22 allows context-dependent attackers to execute arbitrary commands via shell metacharacters in the equation attribute of the math function. NOTE: some of these details are obtained from third party information.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2009-1669 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2010-4725Smarty vulnerabilitySmarty before 3.0.0 RC3 does not properly handle an on value of the asp_tags option in the php.ini file, which has unspecified impact and remote atta…EPSS 1.9%10.0CVE-2010-4726Smarty vulnerabilityUnspecified vulnerability in the math plugin in Smarty before 3.0.0 RC1 has unknown impact and remote attack vectors. NOTE: this might overlap CVE-20…EPSS 1.9%10.0CVE-2010-4727Smarty improper input validation vulnerabilitySmarty before 3.0.0 beta 7 does not properly handle the <?php and ?> tags, which has unspecified impact and remote attack vectors.EPSS 1.9%10.0CVE-2009-5052Smarty vulnerabilityMultiple unspecified vulnerabilities in Smarty before 3.0.0 beta 6 have unknown impact and attack vectors.EPSS 1.9%10.0CVE-2010-4722Smarty vulnerabilityUnspecified vulnerability in the fetch plugin in Smarty before 3.0.2 has unknown impact and remote attack vectors.EPSS 1.9%10.0CVE-2010-4724Smarty vulnerabilityMultiple unspecified vulnerabilities in the parser implementation in Smarty before 3.0.0 RC3 have unknown impact and remote attack vectors.EPSS 1.9%9.8CVE-2021-26120Smarty template engine code injection via function nameSmarty before 3.1.39 allows code injection through an unexpected function name following a {function name= substring in a template. Because Smarty is…EPSS 82%analysed9.8CVE-2011-1028Smarty improper input validation vulnerabilityThe $smarty.template variable in Smarty3 allows attackers to possibly execute arbitrary PHP code via the sysplugins/smarty_internal_compile_private_s…EPSS 1.6%

Source: NIST National Vulnerability Database (record CVE-2009-1669), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.