PatchSiren cyber security CVE debrief
CVE-2026-39628 kutethemes CVE debrief
CVE-2026-39628 is a MEDIUM severity vulnerability in DukaMarket, a product by kutethemes. The vulnerability is classified as Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS), allowing Code Injection. This issue affects DukaMarket from n/a through <= 1.3.0. The CVE record was published on 2026-04-08T09:16:33.210Z and has not been modified since then. There is no information on exploitation or additional vendor guidance.
- Vendor
- kutethemes
- Product
- DukaMarket
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-08
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-08
- Advisory updated
- 2026-07-24
Who should care
Users of DukaMarket version 1.3.0 or earlier should review and apply patches. This includes administrators and security teams responsible for DukaMarket deployments. Vulnerability management and security teams should prioritize patching based on the MEDIUM severity and potential for code injection.
Technical summary
CVE-2026-39628 is an Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in kutethemes DukaMarket dukamarket, allowing Code Injection. This issue affects DukaMarket: from n/a through <= 1.3.0. The vulnerability is considered MEDIUM severity with a CVSS score of 5.3. No additional technical details are provided in the CVE or NVD entries.
Defensive priority
Apply patches for DukaMarket version 1.3.0 or earlier. Verify DukaMarket versions in use and prioritize patching based on MEDIUM severity.
Recommended defensive actions
- Inventory and verify DukaMarket versions
- Apply patches or updates for DukaMarket
- Monitor for suspicious activity
- Review compensating controls for exposed systems
- Check relevant monitoring, detection, and logs for exposed assets
Evidence notes
The CVE record was published on 2026-04-08T09:16:33.210Z and has not been modified since then. The NVD entry is currently Deferred. Evidence is limited to CVE and NVD information. Defenders should verify DukaMarket versions and patch status with kutethemes.
Official resources
-
CVE-2026-39628 CVE record
CVE.org
-
CVE-2026-39628 NVD detail
NVD
-
Source item URL
nvd_modified
- Mitigation or vendor reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-08T09:16:33.210Z and has not been modified since then.