CVEs we hold for Smart
Records whose assigning authority named Smart as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-78150Post Carousel 4.0.0 - 4.0.7 - Contributor+ Private and Protected Post Content Disclosure via saved-templates-duplicate…Unknown Smart Post
CVE-2026-78149Post Carousel 4.0.0 - 4.0.7 - Unauthenticated Password-Protected Post Content and post_password Disclosure via…Unknown Smart Post
CVE-2026-7807SmarterTools SmarterMail < Build 9560 Server Local File Inclusion via the /api/v1/report/summary/{type} APISmarterTools Inc. SmarterMail
CVE-2026-73387WordPress Resido theme <= 1.5 - Local File Inclusion vulnerabilitySmartDataSoft Resido
CVE-2026-4683Smartcat Translator for WPML <= 3.1.77 - Missing Authorization to Unauthenticated Plugin Settings Updatesmartcatai Smartcat Translator for WPML
CVE-2026-40514SmarterTools SmarterMail < Build 9610 Cryptographic Weakness via Weak RNGSmarterTools Inc. SmarterMail
CVE-2026-25067SmarterTools SmarterMail < Build 9518 Unauthenticated background-of-the-day Path CoercionSmarterTools SmarterMail
CVE-2026-24423SmarterTools SmarterMail < Build 9511 Unauthenticated RCE via ConnectToHub APISmarterTools SmarterMail
CVE-2026-23760SmarterTools SmarterMail < Build 9511 Authentication Bypass via Password Reset APISmarterTools SmarterMail
CVE-2026-22358WordPress Electrician - Electrical Service WordPress theme <= 5.6 - Server Side Request Forgery (SSRF) vulnerabilitySmartDataSoft Electrician - Electrical Service WordPress
CVE-2026-16979SmartCrawl < 3.16.3 - Subscriber+ Private/Draft Post Title Disclosure and Post Meta Key EnumerationUnknown SmartCrawl SEO checker, analyzer & optimizer
CVE-2026-16600SmartAIPress <= 1.2.0 - Subscriber+ Server-Side Request Forgery via smartaipress_openai_upload_and_set_featured_imageUnknown SmartAIPress
CVE-2026-10737SP Project & Document Manager <= 4.71 - Missing Authorization to Unauthenticated Arbitrary File Information Disclosure…smartypants SP Project & Document Manager
CVE-2026-10735ShapedPlugin Multiple Pro Plugins - Backdoor via Compromised Vendor Update ServerUnknown Product Slider for WooCommerce Pro
CVE-2025-9451Smartcat Translator for WPML <= 3.1.72 - Authenticated (Author+) SQL Injection via orderby Parametersmartcatai Smartcat Translator for WPML
CVE-2025-6994Reveal Listing <= 3.3 - Unauthenticated Privilege EscalationSmartDataSoft Reveal Listing
CVE-2025-62741WordPress Pool Services theme <= 3.3 - Server Side Request Forgery (SSRF) vulnerabilitySmartDataSoft Pool Services
CVE-2025-58951WordPress Advance Seat Reservation Management for WooCommerce plugin <= 3.1 - SQL Injection vulnerabilitysmartcms Advance Seat Reservation Management for WooCommerce
CVE-2025-58005WordPress DriCub Theme <= 2.9 - Server Side Request Forgery (SSRF) VulnerabilitySmartDataSoft DriCub
CVE-2025-58004WordPress DriCub Theme <= 2.9 - Broken Access Control VulnerabilitySmartDataSoft DriCub
CVE-2025-5340Music Player for Elementor <= 2.4.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via album_buy_url…smartwpress Music Player for Elementor – Audio Player &…
CVE-2025-53294WordPress Smart Agenda plugin <= 4.9 - Cross Site Scripting (XSS) VulnerabilitySmart Agenda
CVE-2025-39479WordPress Smart Notification Plugin <= 10.3 - SQL Injection vulnerabilitysmartiolabs Smart Notification
CVE-2025-39478WordPress Smart Notification Plugin <= 10.3 - Reflected Cross Site Scripting (XSS) vulnerabilitysmartiolabs Smart Notification
CVE-2025-3433Advanced Advertising System <= 1.3.1 - Open Redirectsmartdevth Advanced Advertising System
CVE-2025-32190WordPress Musician's Pack For Elementor plugin <= 1.8.7 - Cross Site Scripting (XSS) vulnerabilitysmartwpress Musician's Pack For Elementor
CVE-2025-31397WordPress Bus Ticket Booking with Seat Reservation for WooCommerce plugin <= 1.7 - SQL Injection vulnerabilitysmartcms Bus Ticket Booking with Seat Reservation for…
CVE-2025-30997WordPress Car Repair Services theme <= 5.0 - Server Side Request Forgery (SSRF) VulnerabilitySmartDataSoft Car Repair Services
CVE-2025-30551WordPress Pretty file links plugin <= 0.9 - Cross Site Scripting (XSS) vulnerabilitysmartredfox Pretty file links
CVE-2025-2513Smart Icons For WordPress <= 1.0.4 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Uploadsmartpixels Smart Icons For WordPress
CVE-2025-23857WordPress Essential WP Real Estate Plugin <= 1.1.3 - Reflected Cross Site Scripting (XSS) vulnerabilitySmartDataSoft Essential WP Real Estate
CVE-2025-14702Smartbit CommV Smartschool App be.smartschool.mobile.SplashActivity path traversalSmartbit CommV Smartschool App
CVE-2025-12882Clasifico Listing <= 2.0 - Unauthenticated Privilege EscalationSmartDataSoft Clasifico Listing
CVE-2025-1285Resido - Real Estate WordPress Theme <= 3.6 - Missing Authorization to Unauthenticated Server-Side Request Forgery and…SmartDataSoft Resido - Real Estate WordPress Theme
CVE-2025-12448Smartsupp – live chat, AI shopping assistant and chatbots <= 3.9.1 - Authenticated (Subscriber+) Stored Cross-Site…Smartsupp – live chat, AI shopping assistant and chatbots
CVE-2024-7565SMARTBEAR SoapUI unpackageAll Directory Traversal Remote Code Execution VulnerabilitySMARTBEAR SoapUI
CVE-2024-49624WordPress Advanced Advertising System plugin <= 1.3.1 - PHP Object Injection vulnerabilitysmartdevth Advanced Advertising System
CVE-2024-3996Post Grid, Post Carousel, & List Category Posts < 2.4.28 - Editor+ Stored XSSUnknown Smart Post Show
CVE-2024-38790WordPress Smartsupp plugin <= 3.6 - Cross Site Request Forgery (CSRF) vulnerabilitySmartsupp – live chat, chatbots, AI and lead generation
CVE-2024-37224WordPress SP Project & Document Manager plugin <= 4.71 - Directory Traversal vulnerabilitysmartypants SP Project & Document Manager
CVE-2024-3632Smart Image Gallery < 1.0.19 - Update/Delete Google API Key via CSRFUnknown Smart Image Gallery
CVE-2024-33923WordPress SP Project & Document Manager plugin <= 4.69 - Broken Access Control vulnerabilitySmartypants SP Project & Document Manager
CVE-2024-32551WordPress SP Project & Document Manage plugin <= 4.71 - Auth. SQL Injection vulnerabilitySmartypants SP Project & Document Manager
CVE-2024-31118WordPress SP Project & Document Manager plugin <= 4.70 - Broken Access Control to XSS vulnerabilitySmartypants SP Project & Document Manager
CVE-2024-24868WordPress SP Project & Document Manager Plugin <= 4.69 is vulnerable to SQL InjectionSmartypants SP Project & Document Manager
CVE-2024-21728Extension - smartcalc.es - Open redirect vulnerability in osTicky component for Joomla <= 2.2.8smartcalc.es osTicky component for Joomla
CVE-2024-1693SP Project & Document Manager <= 4.70 - Authenticated (Subscriber+) Arbitrary Folder Name Updatesmartypants SP Project & Document Manager
CVE-2024-13344Advance Seat Reservation Management for WooCommerce <= 3.3 - Unauthenticated SQL Injectionsmartcms Advance Seat Reservation Management for WooCommerce
CVE-2024-13318Essential WP Real Estate <= 1.1.3 - Missing Authorization to Arbitrary Post/Page Deletionsmartdatasoft Essential WP Real Estate
CVE-2024-1307Smart Forms < 2.6.94 - Subscriber+ Edit Entries via Broken Access ControlUnknown Smart Forms
CVE-2024-11781Smart Agenda – Prise de rendez-vous en ligne <= 4.6 - Authenticated (Contributor+) Stored Cross-Site ScriptingSmartAgenda – Prise de rendez-vous en ligne
CVE-2024-10582Music Player for Elementor – Audio Player & Podcast Player <= 2.4.1 - Missing Authorization to Authenticated…smartwpress Music Player for Elementor – Audio Player &…
CVE-2023-5949SmartCrawl WordPress SEO checker < 3.8.3 - Unauthenticated Password Protected Post DisclosureUnknown SmartCrawl WordPress SEO checker, SEO analyzer, SEO…
CVE-2023-48376SmartStar Software CWS Web-Base - Arbitrary File UploadSmartStar Software CWS Web-Base
CVE-2023-48375SmartStar Software CWS Web-Base - Broken Access ControlSmartStar Software CWS Web-Base
CVE-2023-48374SmartStar Software CWS Web-Base - Use of Hard-coded CredentialsSmartStar Software CWS Web-Base
CVE-2023-36677WordPress SP Project & Document Manager Plugin <= 4.67 is vulnerable to SQL InjectionSmartypants SP Project & Document Manager
CVE-2023-36530WordPress SP Project & Document Manager Plugin <= 4.67 is vulnerable to Cross Site Scripting (XSS)Smartypants SP Project & Document Manager
CVE-2023-3504SmartWeb Infotech Job Board My Profile Page account unrestricted uploadSmartWeb Infotech Job Board
CVE-2023-3063SP Project & Document Manager <= 4.67 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary User…smartypants SP Project & Document Manager
CVE-2023-28447Cross site scripting vulnerability in Javascript escaping in smarty/smartysmarty-php smarty
CVE-2022-50951WiFi File Transfer 1.0.8 Persistent XSS via Web Server Input ValidationsmarterDroid WiFi File Transfer
CVE-2022-39031Smart eVision - Exposure of Sensitive Information to an Unauthorized Actor -3Smart eVision
CVE-2022-39030Smart eVision - Exposure of Sensitive Information to an Unauthorized Actor -2Smart eVision
CVE-2022-39029Smart eVision - Exposure of Sensitive Information to an Unauthorized Actor -1Smart eVision
CVE-2022-34857WordPress SP Project & Document Manager plugin <= 4.59 - Reflected Cross-Site Scripting (XSS) vulnerabilitysmartypants SP Project & Document Manager (WordPress plugin)
CVE-2022-24387File upload and overwrite to app_data/Config in SmarterTrack v100.0.8019.14010SmarterTools SmarterTrack
CVE-2022-24385Information disclosure via direct object access on SmarterTrack v100.0.8019.14010SmarterTools SmarterTrack
CVE-2022-1912Button Widget Smartsoft <= 1.0.1 - Cross-Site Request Forgery to Cross-Site Scriptingsmartsoftbuttonwidget Button Widget Smartsoft
CVE-2022-0163Smart Forms < 2.6.71 - Subscriber+ Form Data DownloadUnknown Smart Forms – when you need more than just a…
CVE-2021-38315SP Project & Document Manager <= 4.25 Reflected Cross-Site ScriptingSmartyPants SP Project & Document Manager
CVE-2021-24992Buttonizer - Smart Floating Action Button < 2.5.5 - Admin+ Stored Cross-Site ScriptingUnknown Smart Floating / Sticky Buttons – Call, Sharing…
CVE-2021-24976Smart SEO Tool < 3.0.6 - Reflected Cross-Site ScriptingUnknown Smart SEO Tool – SEO优化插件
CVE-2021-21408Access to restricted PHP code by dynamic static class access in smartysmarty-php smarty
CVE-2019-25235Smartwares HOME easy 1.0.9 Client-Side Authentication Bypass via Web PagesSmartwares HOME easy
CVE-2014-0757Smart Software Solutions (3S) CoDeSys Runtime Toolkit NULL Pointer DereferenceSmart Software Solutions (3S) CoDeSys Runtime Toolkit
124 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.