Smarty before 3.1.39 allows a Sandbox Escape because $smarty.template_object can be accessed in sandbox mode (CVE-2021-26119).
Smarty before 3.1.39 allows code injection via an unexpected function name after a {function name= substring (CVE-2021-26120).