PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-39628 kutethemes CVE debrief

CVE-2026-39628 is a MEDIUM severity vulnerability in DukaMarket, a product by kutethemes. The vulnerability is classified as Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS), allowing Code Injection. This issue affects DukaMarket from n/a through <= 1.3.0. The CVE record was published on 2026-04-08T09:16:33.210Z and has not been modified since then. There is no information on exploitation or additional vendor guidance.

Vendor
kutethemes
Product
DukaMarket
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-08
Original CVE updated
2026-07-24
Advisory published
2026-04-08
Advisory updated
2026-07-24

Who should care

Users of DukaMarket version 1.3.0 or earlier should review and apply patches. This includes administrators and security teams responsible for DukaMarket deployments. Vulnerability management and security teams should prioritize patching based on the MEDIUM severity and potential for code injection.

Technical summary

CVE-2026-39628 is an Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in kutethemes DukaMarket dukamarket, allowing Code Injection. This issue affects DukaMarket: from n/a through <= 1.3.0. The vulnerability is considered MEDIUM severity with a CVSS score of 5.3. No additional technical details are provided in the CVE or NVD entries.

Defensive priority

Apply patches for DukaMarket version 1.3.0 or earlier. Verify DukaMarket versions in use and prioritize patching based on MEDIUM severity.

Recommended defensive actions

  • Inventory and verify DukaMarket versions
  • Apply patches or updates for DukaMarket
  • Monitor for suspicious activity
  • Review compensating controls for exposed systems
  • Check relevant monitoring, detection, and logs for exposed assets

Evidence notes

The CVE record was published on 2026-04-08T09:16:33.210Z and has not been modified since then. The NVD entry is currently Deferred. Evidence is limited to CVE and NVD information. Defenders should verify DukaMarket versions and patch status with kutethemes.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-08T09:16:33.210Z and has not been modified since then.