A server-side template injection in Adobe Commerce and Magento lets an unauthenticated attacker get crafted input evaluated by the template engine, leading to full code execution on the store.