Vendor
Smarty versions before 4.5.8 and 5.8.5 are susceptible to code injection via template inheritance due to improper management of the nocache_hash variable, enabling unauthenticated remote code execution.