Cybersecurity
Unauthenticated Template Injection in JTL Shop Can Yield Webshell and Code Execution, NVD Records
CVE-2026-54390, a critical (CVSS 9.8) server-side template injection flaw in JTL Shop 5.2.0–5.7.1, lets unauthenticated attackers read server secrets and, on 5.4.0–5.7.1, write a webshell to the web root.