Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-54390— JTL Shop < 5.7.2 Server-Side Template Injection via Smarty Renderer

CVSS 9.8 · Critical EPSS 0.60% · P46

Affected Version Matrix 6

VendorProductVersion RangeStatus
JTL SoftwareJTL Shop5.0.0≤ 5.1.8unaffected
5.2.0< 5.4.0affected
5.4.0≤ 5.7.1affected
5.5.4unaffected
5.6.2unaffected
5.7.2unaffected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-54390

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
JTL Shop < 5.7.2 Server-Side Template Injection via Smarty Renderer
Source: CVE Program / CVE List V5
Vulnerability Description
JTL Shop versions 5.2.0 through 5.7.1 contains a server-side template injection vulnerability that allows unauthenticated attackers to inject malicious template syntax due to unsanitized user-supplied input passed to the Smarty template engine. Attackers can exploit this flaw to read sensitive server-side values such as database credentials and encryption keys, and on versions 5.4.0 through 5.7.1, leverage registered Smarty modifiers including unserialize and file_get_contents to write a webshell to the web root and execute arbitrary commands as the web server user.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
CWE-1336
Source: CVE Program / CVE List V5
Vulnerability Title
JTL Software JTL Shop 代码注入漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
JTL Software JTL Shop是JTL Software公司的一款电商系统软件 JTL Software JTL Shop 5.2.0及之前版本和5.4.0至5.7.1版本存在代码注入漏洞,该漏洞源于未清理用户输入导致服务器端模板注入,攻击者可能读取数据库凭据、加密密钥等敏感信息,在5.4.0至5.7.1版本中还可以写入webshell并执行任意命令。以下版本受到影响:5.2.0及之前版本和5.4.0至5.7.1版本。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
JTL SoftwareJTL Shop 5.0.0 ~ 5.1.8 -

II. Public POCs for CVE-2026-54390

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-54390

登录查看更多情报信息。

Vendor Advisories for CVE-2026-54390 (1)

Security Blog Posts for CVE-2026-54390 (1)

Vendor Pages for CVE-2026-54390 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-54390

No comments yet


Leave a comment