vciy

CVEs we hold for Smart

Records whose assigning authority named Smart as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-78150Post Carousel 4.0.0 - 4.0.7 - Contributor+ Private and Protected Post Content Disclosure via saved-templates-duplicate…Unknown Smart Post
CVE-2026-78149Post Carousel 4.0.0 - 4.0.7 - Unauthenticated Password-Protected Post Content and post_password Disclosure via…Unknown Smart Post
CVE-2026-7807SmarterTools SmarterMail < Build 9560 Server Local File Inclusion via the /api/v1/report/summary/{type} APISmarterTools Inc. SmarterMail
CVE-2026-73387WordPress Resido theme <= 1.5 - Local File Inclusion vulnerabilitySmartDataSoft Resido
CVE-2026-62996Smarty Security stream restriction bypass through stream: resourcesmarty-php smarty
CVE-2026-62993Smarty: SSRF via redirect bypass of trusted_uri using {fetch}smarty-php smarty
CVE-2026-62992Smarty: Symlink path traversal out of trusted directoriessmarty-php smarty
CVE-2026-4683Smartcat Translator for WPML <= 3.1.77 - Missing Authorization to Unauthenticated Plugin Settings Updatesmartcatai Smartcat Translator for WPML
CVE-2026-40514SmarterTools SmarterMail < Build 9610 Cryptographic Weakness via Weak RNGSmarterTools Inc. SmarterMail
CVE-2026-26930no title heldSmarterTools SmarterMail
CVE-2026-25067SmarterTools SmarterMail < Build 9518 Unauthenticated background-of-the-day Path CoercionSmarterTools SmarterMail
CVE-2026-24423SmarterTools SmarterMail < Build 9511 Unauthenticated RCE via ConnectToHub APISmarterTools SmarterMail
CVE-2026-23760SmarterTools SmarterMail < Build 9511 Authentication Bypass via Password Reset APISmarterTools SmarterMail
CVE-2026-22358WordPress Electrician - Electrical Service WordPress theme <= 5.6 - Server Side Request Forgery (SSRF) vulnerabilitySmartDataSoft Electrician - Electrical Service WordPress
CVE-2026-16979SmartCrawl < 3.16.3 - Subscriber+ Private/Draft Post Title Disclosure and Post Meta Key EnumerationUnknown SmartCrawl SEO checker, analyzer & optimizer
CVE-2026-16600SmartAIPress <= 1.2.0 - Subscriber+ Server-Side Request Forgery via smartaipress_openai_upload_and_set_featured_imageUnknown SmartAIPress
CVE-2026-14203Smart Manager < 8.92.0 - Contributor+ Stored XSS via Post TitleUnknown Smart Manager
CVE-2026-10737SP Project & Document Manager <= 4.71 - Missing Authorization to Unauthenticated Arbitrary File Information Disclosure…smartypants SP Project & Document Manager
CVE-2026-10735ShapedPlugin Multiple Pro Plugins - Backdoor via Compromised Vendor Update ServerUnknown Product Slider for WooCommerce Pro
CVE-2025-9451Smartcat Translator for WPML <= 3.1.72 - Authenticated (Author+) SQL Injection via orderby Parametersmartcatai Smartcat Translator for WPML
CVE-2025-6994Reveal Listing <= 3.3 - Unauthenticated Privilege EscalationSmartDataSoft Reveal Listing
CVE-2025-62741WordPress Pool Services theme <= 3.3 - Server Side Request Forgery (SSRF) vulnerabilitySmartDataSoft Pool Services
CVE-2025-58951WordPress Advance Seat Reservation Management for WooCommerce plugin <= 3.1 - SQL Injection vulnerabilitysmartcms Advance Seat Reservation Management for WooCommerce
CVE-2025-58005WordPress DriCub Theme <= 2.9 - Server Side Request Forgery (SSRF) VulnerabilitySmartDataSoft DriCub
CVE-2025-58004WordPress DriCub Theme <= 2.9 - Broken Access Control VulnerabilitySmartDataSoft DriCub
CVE-2025-5340Music Player for Elementor <= 2.4.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via album_buy_url…smartwpress Music Player for Elementor – Audio Player &…
CVE-2025-53294WordPress Smart Agenda plugin <= 4.9 - Cross Site Scripting (XSS) VulnerabilitySmart Agenda
CVE-2025-52691Upload Arbitrary FilesSmarterTools SmarterMail
CVE-2025-4008Arbitrary Command Injection in Smartbedded MeteoBridgeSmartbedded MeteoBridge
CVE-2025-39479WordPress Smart Notification Plugin <= 10.3 - SQL Injection vulnerabilitysmartiolabs Smart Notification
CVE-2025-39478WordPress Smart Notification Plugin <= 10.3 - Reflected Cross Site Scripting (XSS) vulnerabilitysmartiolabs Smart Notification
CVE-2025-3433Advanced Advertising System <= 1.3.1 - Open Redirectsmartdevth Advanced Advertising System
CVE-2025-32190WordPress Musician's Pack For Elementor plugin <= 1.8.7 - Cross Site Scripting (XSS) vulnerabilitysmartwpress Musician's Pack For Elementor
CVE-2025-31397WordPress Bus Ticket Booking with Seat Reservation for WooCommerce plugin <= 1.7 - SQL Injection vulnerabilitysmartcms Bus Ticket Booking with Seat Reservation for…
CVE-2025-30997WordPress Car Repair Services theme <= 5.0 - Server Side Request Forgery (SSRF) VulnerabilitySmartDataSoft Car Repair Services
CVE-2025-30551WordPress Pretty file links plugin <= 0.9 - Cross Site Scripting (XSS) vulnerabilitysmartredfox Pretty file links
CVE-2025-2513Smart Icons For WordPress <= 1.0.4 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Uploadsmartpixels Smart Icons For WordPress
CVE-2025-23857WordPress Essential WP Real Estate Plugin <= 1.1.3 - Reflected Cross Site Scripting (XSS) vulnerabilitySmartDataSoft Essential WP Real Estate
CVE-2025-22506WordPress Smart Agenda Plugin <= 4.7 - CSRF to Stored XSS vulnerabilitySmart Agenda
CVE-2025-14702Smartbit CommV Smartschool App be.smartschool.mobile.SplashActivity path traversalSmartbit CommV Smartschool App
CVE-2025-12882Clasifico Listing <= 2.0 - Unauthenticated Privilege EscalationSmartDataSoft Clasifico Listing
CVE-2025-1285Resido - Real Estate WordPress Theme <= 3.6 - Missing Authorization to Unauthenticated Server-Side Request Forgery and…SmartDataSoft Resido - Real Estate WordPress Theme
CVE-2025-12448Smartsupp – live chat, AI shopping assistant and chatbots <= 3.9.1 - Authenticated (Subscriber+) Stored Cross-Site…Smartsupp – live chat, AI shopping assistant and chatbots
CVE-2025-10778Smartstore Gift Voucher confirm race conditionn/a Smartstore
CVE-2024-8752WebIQ 2.15.9 Runtime on Windows - Directory Traversal VulnerabilitySmart HMI WebIQ
CVE-2024-8187Smart Post Show <= 3.0.0 - Editor+ Stored XSSUnknown Smart Post Show
CVE-2024-7565SMARTBEAR SoapUI unpackageAll Directory Traversal Remote Code Execution VulnerabilitySMARTBEAR SoapUI
CVE-2024-7016Stored XSS in Smarttek Informatics' Smart DoctorSmarttek Informatics Smart Doctor
CVE-2024-49624WordPress Advanced Advertising System plugin <= 1.3.1 - PHP Object Injection vulnerabilitysmartdevth Advanced Advertising System
CVE-2024-3996Post Grid, Post Carousel, & List Category Posts < 2.4.28 - Editor+ Stored XSSUnknown Smart Post Show
CVE-2024-38790WordPress Smartsupp plugin <= 3.6 - Cross Site Request Forgery (CSRF) vulnerabilitySmartsupp – live chat, chatbots, AI and lead generation
CVE-2024-3735Smart Office Main.aspx weak passwordn/a Smart Office
CVE-2024-37224WordPress SP Project & Document Manager plugin <= 4.71 - Directory Traversal vulnerabilitysmartypants SP Project & Document Manager
CVE-2024-3632Smart Image Gallery < 1.0.19 - Update/Delete Google API Key via CSRFUnknown Smart Image Gallery
CVE-2024-35226PHP Code Injection by malicious attribute in extends-tag in Smartysmarty-php smarty
CVE-2024-33923WordPress SP Project & Document Manager plugin <= 4.69 - Broken Access Control vulnerabilitySmartypants SP Project & Document Manager
CVE-2024-32551WordPress SP Project & Document Manage plugin <= 4.71 - Auth. SQL Injection vulnerabilitySmartypants SP Project & Document Manager
CVE-2024-31118WordPress SP Project & Document Manager plugin <= 4.70 - Broken Access Control to XSS vulnerabilitySmartypants SP Project & Document Manager
CVE-2024-24868WordPress SP Project & Document Manager Plugin <= 4.69 is vulnerable to SQL InjectionSmartypants SP Project & Document Manager
CVE-2024-21728Extension - smartcalc.es - Open redirect vulnerability in osTicky component for Joomla <= 2.2.8smartcalc.es osTicky component for Joomla
CVE-2024-1905Smart Forms < 2.6.96 - Admin+ Stored XSSUnknown Smart Forms
CVE-2024-1693SP Project & Document Manager <= 4.70 - Authenticated (Subscriber+) Arbitrary Folder Name Updatesmartypants SP Project & Document Manager
CVE-2024-13894Path traversal in Smartwares camerasSmartwares C724IP
CVE-2024-13893Shared credentials in Smartwares camerasSmartwares C724IP
CVE-2024-13892Command Injection in Smartwares camerasSmartwares C724IP
CVE-2024-13344Advance Seat Reservation Management for WooCommerce <= 3.3 - Unauthenticated SQL Injectionsmartcms Advance Seat Reservation Management for WooCommerce
CVE-2024-13318Essential WP Real Estate <= 1.1.3 - Missing Authorization to Arbitrary Post/Page Deletionsmartdatasoft Essential WP Real Estate
CVE-2024-1307Smart Forms < 2.6.94 - Subscriber+ Edit Entries via Broken Access ControlUnknown Smart Forms
CVE-2024-1306Smart Forms < 2.6.94 - Edit Entries via CSRFUnknown Smart Forms
CVE-2024-12683Smart Maintenance Mode < 1.5.2 - Admin+ Stored XSSUnknown Smart Maintenance Mode
CVE-2024-12682Smart Maintenance Mode < 1.5.2 - Admin+ Stored XSSUnknown Smart Maintenance Mode
CVE-2024-11781Smart Agenda – Prise de rendez-vous en ligne <= 4.6 - Authenticated (Contributor+) Stored Cross-Site ScriptingSmartAgenda – Prise de rendez-vous en ligne
CVE-2024-10582Music Player for Elementor – Audio Player & Podcast Player <= 2.4.1 - Missing Authorization to Authenticated…smartwpress Music Player for Elementor – Audio Player &…
CVE-2024-0566Smart Manager < 8.28.0 - Admin+ SQL InjectionUnknown Smart Manager
CVE-2023-7203Smart Forms < 2.6.87 - Subscriber+ Arbitrary Entry DeletionUnknown Smart Forms
CVE-2023-5949SmartCrawl WordPress SEO checker < 3.8.3 - Unauthenticated Password Protected Post DisclosureUnknown SmartCrawl WordPress SEO checker, SEO analyzer, SEO…
CVE-2023-48376SmartStar Software CWS Web-Base - Arbitrary File UploadSmartStar Software CWS Web-Base
CVE-2023-48375SmartStar Software CWS Web-Base - Broken Access ControlSmartStar Software CWS Web-Base
CVE-2023-48374SmartStar Software CWS Web-Base - Use of Hard-coded CredentialsSmartStar Software CWS Web-Base
CVE-2023-37288SmartBPM.NET - Path TraversalSmartSoft SmartBPM.NET
CVE-2023-36677WordPress SP Project & Document Manager Plugin <= 4.67 is vulnerable to SQL InjectionSmartypants SP Project & Document Manager
CVE-2023-36530WordPress SP Project & Document Manager Plugin <= 4.67 is vulnerable to Cross Site Scripting (XSS)Smartypants SP Project & Document Manager
CVE-2023-3504SmartWeb Infotech Job Board My Profile Page account unrestricted uploadSmartWeb Infotech Job Board
CVE-2023-3063SP Project & Document Manager <= 4.67 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary User…smartypants SP Project & Document Manager
CVE-2023-28447Cross site scripting vulnerability in Javascript escaping in smarty/smartysmarty-php smarty
CVE-2023-0660Smart Slider 3 < 3.5.1.14 - Contributor+ Stored XSSUnknown Smart Slider 3
CVE-2022-50951WiFi File Transfer 1.0.8 Persistent XSS via Web Server Input ValidationsmarterDroid WiFi File Transfer
CVE-2022-39035Smart eVision - Stored XSSSmart eVision
CVE-2022-39034Smart eVision - Path Traversal -2Smart eVision
CVE-2022-39033Smart eVision - Path Traversal -1Smart eVision
CVE-2022-39032Smart eVision - Improper Privilege ManagementSmart eVision
CVE-2022-39031Smart eVision - Exposure of Sensitive Information to an Unauthorized Actor -3Smart eVision
CVE-2022-39030Smart eVision - Exposure of Sensitive Information to an Unauthorized Actor -2Smart eVision
CVE-2022-39029Smart eVision - Exposure of Sensitive Information to an Unauthorized Actor -1Smart eVision
CVE-2022-34857WordPress SP Project & Document Manager plugin <= 4.59 - Reflected Cross-Site Scripting (XSS) vulnerabilitysmartypants SP Project & Document Manager (WordPress plugin)
CVE-2022-3357Smart Slider 3 < 3.5.1.11 - PHP Object InjectionUnknown Smart Slider 3
CVE-2022-29221PHP Code Injection by malicious block or filename in Smartysmarty-php smarty
CVE-2022-24387File upload and overwrite to app_data/Config in SmarterTrack v100.0.8019.14010SmarterTools SmarterTrack
CVE-2022-24386Stored XSS in SmarterTrack v100.0.8019.14010SmarterTools SmarterTrack
CVE-2022-24385Information disclosure via direct object access on SmarterTrack v100.0.8019.14010SmarterTools SmarterTrack
CVE-2022-24384Reflective XSS on SmarterTrack v100.0.8019.14010SmarterTools SmarterTrack
CVE-2022-21810no title heldn/a smartctl
CVE-2022-1912Button Widget Smartsoft <= 1.0.1 - Cross-Site Request Forgery to Cross-Site Scriptingsmartsoftbuttonwidget Button Widget Smartsoft
CVE-2022-0163Smart Forms < 2.6.71 - Subscriber+ Form Data DownloadUnknown Smart Forms – when you need more than just a…
CVE-2021-47791SmartFTP Client 10.0.2909.0 - 'Multiple' Denial of ServiceSmartFTP Client
CVE-2021-38315SP Project & Document Manager <= 4.25 Reflected Cross-Site ScriptingSmartyPants SP Project & Document Manager
CVE-2021-3457no title heldn/a smart_proxy_shellhooks
CVE-2021-3456no title heldn/a smart_proxy_salt
CVE-2021-29454Sandbox Escape by math function in smartysmarty-php smarty
CVE-2021-24992Buttonizer - Smart Floating Action Button < 2.5.5 - Admin+ Stored Cross-Site ScriptingUnknown Smart Floating / Sticky Buttons – Call, Sharing…
CVE-2021-24976Smart SEO Tool < 3.0.6 - Reflected Cross-Site ScriptingUnknown Smart SEO Tool – SEO优化插件
CVE-2021-21408Access to restricted PHP code by dynamic static class access in smartysmarty-php smarty
CVE-2021-20290no title heldn/a smart_proxy_openscap
CVE-2020-9067no title heldn/a SmartAX EA5800
CVE-2020-7548no title heldn/a Smartlink, PowerTag, and Wiser Series Gateways (see…
CVE-2020-36972SmartBlog 2.0.1 - 'id_post' Blind SQL injectionsmartdatasoft SmartBlog
CVE-2020-36926SmarterTools SmarterTrack 7922 -Information DisclosureSmarterTools SmarterTrack
CVE-2020-15243WebApi Authentication attribute missing in Smartstoresmartstore SmartStoreNET
CVE-2019-6005no title heldSmart TV Box firmware version prior to 1300
CVE-2019-25235Smartwares HOME easy 1.0.9 Client-Side Authentication Bypass via Web PagesSmartwares HOME easy
CVE-2018-25239Smart VPN 1.1.3.0 Denial of Service via SearchSmartVPN Smart VPN
CVE-2018-25234SmartFTP Client 9.0.2615.0 Denial of Service via Host FieldSmartFTP Client
CVE-2014-0757Smart Software Solutions (3S) CoDeSys Runtime Toolkit NULL Pointer DereferenceSmart Software Solutions (3S) CoDeSys Runtime Toolkit
CVE-2011-1028no title heldsmarty3

124 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.