Multiple unspecified vulnerabilities in Smarty before 3.0.0 beta 6 have unknown impact and attack vectors.
Smarty before 3.0.0 RC3 does not properly handle an on value of the asptags option in the php.ini file, which has unspecified impact and remote attack vectors.
Unknown vulnerability in the regexreplace modifier (modifier.regexreplace.php) in Smarty before 2.6.8 allows attackers to execute arbitrary PHP code.
Cross-site scripting (XSS) vulnerability in the SmartyException class in Smarty (aka smarty-php) before 3.1.12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors that trigger a Smarty exception.