PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-39615 Shahjada CVE debrief

A Stored XSS vulnerability was found in the Download Manager plugin, affecting versions up to 3.3.53. This issue allows an attacker to inject malicious scripts into web pages, potentially leading to unauthorized actions or data theft. The vulnerability is caused by improper neutralization of input during web page generation, classified as CWE-79. The CVSS score is 5.9, with a severity of MEDIUM. The vulnerability requires high privileges to exploit and can result in low impact on confidentiality, integrity, and availability. Users of the Download Manager plugin, especially those with versions up to 3.3.53, should be aware of this vulnerability and take necessary actions to secure their installations.

Vendor
Shahjada
Product
Download Manager
CVSS
MEDIUM 5.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-08
Original CVE updated
2026-07-24
Advisory published
2026-04-08
Advisory updated
2026-07-24

Who should care

Users of the Download Manager plugin, especially those with versions up to 3.3.53, should be aware of this vulnerability and take necessary actions to secure their installations. This includes updating the plugin to a version beyond 3.3.53, implementing input validation and output encoding to prevent XSS, and monitoring for suspicious activity.

Technical summary

The vulnerability is caused by improper neutralization of input during web page generation, classified as CWE-79. The CVSS score is 5.9, with a severity of MEDIUM. The vulnerability requires high privileges to exploit and can result in low impact on confidentiality, integrity, and availability. The vulnerability affects the Download Manager plugin, and users should take necessary actions to secure their installations.

Defensive priority

Medium priority due to the CVSS score and potential impact. Users should take necessary actions to secure their installations, including updating the plugin and implementing compensating controls. A web application firewall can be used to detect and prevent attacks. Users should also review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. Compensating controls should be reviewed for exposed systems while remediation is scheduled and verified. Relevant monitoring, detection, and logs should be checked for exposed assets that need extra review. Asset inventory and rollback/change windows should be considered for exposed systems. Source tracking should be implemented to monitor for potential attacks. Exposure review should be conducted to determine the potential impact of the vulnerability. Vendor patch guidance should be followed to update the plugin. Monitoring and compensating controls should be implemented to prevent attacks.

Recommended defensive actions

  • Update the Download Manager plugin to a version beyond 3.3.53.
  • Implement input validation and output encoding to prevent XSS.
  • Monitor for suspicious activity and implement compensating controls.
  • Consider using a web application firewall to detect and prevent attacks.

Evidence notes

The CVE record was published on 2026-04-08T09:16:31.323Z and last modified on 2026-07-24T21:10:00.143Z. The NVD entry is currently Deferred. Limited information is available about the vulnerability, and further investigation is recommended. The vulnerability has a CVSS score of 5.9 and a severity of MEDIUM. The Download Manager plugin is affected by this vulnerability, and users should take necessary actions to secure their installations.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-08T09:16:31.323Z and has not been modified since then. The NVD entry is currently Deferred.