VYPR

JTL Shop

by JTL

CVEs (1)

  • CVE-2026-54390Jun 18, 2026
    risk 0.00cvss epss

    JTL Shop versions 5.2.0 through 5.7.1 contains a server-side template injection vulnerability that allows unauthenticated attackers to inject malicious template syntax due to unsanitized user-supplied input passed to the Smarty template engine. Attackers can exploit this flaw to…