PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-39628 kutethemes CVE debrief

CVE-2026-39628 is a MEDIUM severity vulnerability in DukaMarket, a product by kutethemes. The vulnerability is classified as Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS), allowing Code Injection. This issue affects DukaMarket from n/a through <= 1.3.0. The CVE record was published on 2026-04-08T09:16:33.210Z and has not been modified since then. There is no information on exploitation or additional vendor guidance.

Vendor
kutethemes
Product
DukaMarket
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-08
Original CVE updated
2026-07-24
Advisory published
2026-04-08
Advisory updated
2026-07-24

Who should care

Users of DukaMarket version 1.3.0 or earlier should review and apply patches. This includes administrators and security teams responsible for DukaMarket deployments. Vulnerability management and security teams should prioritize patching based on the MEDIUM severity and potential for code injection.

Technical summary

CVE-2026-39628 is an Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in kutethemes DukaMarket dukamarket, allowing Code Injection. This issue affects DukaMarket: from n/a through <= 1.3.0. The vulnerability is considered MEDIUM severity with a CVSS score of 5.3. No additional technical details are provided in the CVE or NVD entries.

Defensive priority

Apply patches for DukaMarket version 1.3.0 or earlier. Verify DukaMarket versions in use and prioritize patching based on MEDIUM severity.

Recommended defensive actions

  • Inventory and verify DukaMarket versions
  • Apply patches or updates for DukaMarket
  • Monitor for suspicious activity
  • Review compensating controls for exposed systems
  • Check relevant monitoring, detection, and logs for exposed assets

Evidence notes

The CVE record was published on 2026-04-08T09:16:33.210Z and has not been modified since then. The NVD entry is currently Deferred. Evidence is limited to CVE and NVD information. Defenders should verify DukaMarket versions and patch status with kutethemes.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-39628 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-39628

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-39628 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-39628

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.