PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-39692 tagDiv CVE debrief

CVE-2026-39692 is a Stored Cross-site Scripting (XSS) vulnerability in the tagDiv Composer plugin, affecting versions up to and including 5.4.3. This issue allows authenticated attackers with low privileges to inject malicious scripts into web pages, potentially leading to unauthorized actions and data breaches. The vulnerability's CVSS score is 6.5, indicating a medium severity level. Administrators should review the official advisory and plan updates or mitigations.

Vendor
tagDiv
Product
tagDiv Composer
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-08
Original CVE updated
2026-07-24
Advisory published
2026-04-08
Advisory updated
2026-07-24

Who should care

Administrators and users of the tagDiv Composer plugin, especially those using versions up to 5.4.3, should be aware of this vulnerability and take necessary actions to mitigate the risk. This includes reviewing compensating controls and monitoring for suspicious activity.

Technical summary

The vulnerability is caused by improper neutralization of input during web page generation. An attacker with low privileges can inject malicious scripts, which are then stored and executed by the application. This can lead to unauthorized actions, data breaches, and other malicious activities. The affected product is tagDiv Composer, and defenders should focus on updating to a secure version.

Defensive priority

Medium priority should be given to updating the tagDiv Composer plugin to a version beyond 5.4.3 or applying appropriate mitigations to prevent exploitation. Defenders should also review asset inventory and implement additional security measures as needed.

Recommended defensive actions

  • Update the tagDiv Composer plugin to a version beyond 5.4.3.
  • Implement input validation and output encoding to prevent XSS attacks.
  • Monitor for suspicious activity and implement additional security measures as needed.

Evidence notes

The CVE record was published on 2026-04-08T09:16:41.520Z and was last modified on 2026-07-24T20:10:00.147Z. The NVD entry is currently Deferred. Patchstack reported this vulnerability. Evidence is limited, and defenders should verify affected scope and vendor guidance.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-39692 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-39692

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-39692 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-39692

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.