Back

CVE-2005-0913

Unknown vulnerability in the regex_replace modifier (modifier.regex_replace.php) in Smarty before 2.6.8 allows attackers to execute arbitrary PHP code.

Published: May 2, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (6)

Vendor Product Version
smarty smarty 2.6.2
smarty smarty 2.6.3
smarty smarty 2.6.4
smarty smarty 2.6.5
smarty smarty 2.6.6
smarty smarty 2.6.7

GitHub Security Advisory GHSA-hh2c-85xj-jphm

Unknown vulnerability in the regex_replace modifier (modifier.regex_replace.php) in Smarty before...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 1.53%

Top 27% most likely to be exploited

Threat Score 30.5 / 100

Data Sources

NVD EPSS GitHub