Known Vulnerabilities for JTL Shop by JTL Software
Listed below are 10 of the newest known vulnerabilities associated with "JTL Shop" by "JTL Software".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-66475 json | Shop manager Cross Site Scripting (XSS) in Checkout Field Editor for WooCommerce – Checkout Manager <= 3.0.5 versions. | Not Provided | 2026-07-27 | 2026-07-27 |
| CVE-2026-65557 json | Shop manager Cross Site Scripting (XSS) in Abandoned Cart Lite for WooCommerce <= 6.8.0 versions. | Not Provided | 2026-07-27 | 2026-07-27 |
| CVE-2026-65550 json | Shop Manager Cross Site Scripting (XSS) in Tabs <= 2.5 versions. | Not Provided | 2026-07-23 | 2026-07-23 |
| CVE-2026-65532 json | Shop manager SQL Injection in Persian Woocommerce SMS <= 7.2.2 versions. | Not Provided | 2026-07-23 | 2026-07-23 |
| CVE-2026-58379 json | A flaw was found in GIMP's Paint Shop Pro (PSP) file format parser. This heap buffer overflow vulnerability allows a remote a... | Not Provided | 2026-07-03 | 2026-07-13 |
| CVE-2026-57405 json | Missing Authorization vulnerability in themehunk Open Shop open-shop allows Exploiting Incorrectly Configured Access Control ... | Not Provided | 2026-07-13 | 2026-07-13 |
| CVE-2026-54390 json | JTL Shop versions 5.2.0 through 5.7.1 contains a server-side template injection vulnerability that allows unauthenticated att... | Not Provided | 2026-06-18 | 2026-06-23 |
| CVE-2026-48518 json | MultiJuicer is used to run separate Juice Shop instances on a central kubernetes cluster without the need for local instances... | Not Provided | 2026-06-15 | 2026-06-16 |
| CVE-2026-40748 json | Subscriber Arbitrary File Upload in Kids Gift Shop <= 0.5.4 versions. | Not Provided | 2026-06-17 | 2026-06-17 |
| CVE-2026-39499 json | Shop manager PHP Object Injection in Advanced Product Fields (Product Addons) for WooCommerce <= 1.6.19 versions. | Not Provided | 2026-06-15 | 2026-06-15 |