These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
A MEDIUM severity vulnerability, CVE-2026-39629, was found in Uminex theme, affecting Code Injection via Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS). The vulnerability has a CVSS score of 5.3 and affects Uminex theme version 1.0.9 or earlier. Users of Uminex theme should apply updates to prevent Code Injection attacks. The NVD entry is currently Deferred, and the CVE reco [truncated]
CVE-2026-39628 is a MEDIUM severity vulnerability in DukaMarket, a product by kutethemes. The vulnerability is classified as Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS), allowing Code Injection. This issue affects DukaMarket from n/a through <= 1.3.0. The CVE record was published on 2026-04-08T09:16:33.210Z and has not been modified since then. There is no information on [truncated]
A MEDIUM severity vulnerability, CVE-2026-39626, was found in kutethemes Armania armania. This issue, described as Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS), allows Code Injection. It affects Armania from n/a through version 1.4.8. The vulnerability has a CVSS score of 5.3 and is considered a MEDIUM priority for patching or mitigation. Users of kutethemes Armania armani [truncated]
CVE-2026-39625 is a MEDIUM severity vulnerability in the TechOne theme, affecting versions up to and including 3.0.3. The issue is an Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability, which allows Code Injection. This vulnerability has a CVSS score of 5.3 and a severity rating of MEDIUM. Users of the TechOne theme should be aware of this vulnerability and take ne [truncated]
A Missing Authorization vulnerability in kutethemes Biolife allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Biolife from n/a through <= 3.2.3. The vulnerability has a CVSS score of 5.3 and is classified as MEDIUM severity. Users of kutethemes Biolife, especially those with versions from n/a through 3.2.3, should be aware of this MEDIUM severity vulnerability.
A high-severity vulnerability, CVE-2026-39623, was found in the Biolife theme, allowing for PHP Local File Inclusion. This issue, with a CVSS score of 7.5, affects the Biolife theme from version n/a through 3.2.3. The vulnerability is an Improper Control of Filename for Include/Require Statement in PHP Program, also known as PHP Remote File Inclusion. It allows attackers to include local files, potentiall [truncated]
A high-severity vulnerability, CVE-2026-39613, was found in the kute-boutique theme. This issue, classified as a PHP Local File Inclusion vulnerability, allows attackers to include local files via PHP's include/require statements. The vulnerability has a CVSS score of 7.5 and affects the kute-boutique theme from its inception through version 2.3.3.
A Missing Authorization vulnerability was found in kutethemes KuteShop, affecting versions from n/a through <= 4.2.9. This issue allows for Exploiting Incorrectly Configured Access Control Security Levels. The vulnerability has a CVSS score of 5.3 and is classified as MEDIUM severity. Users of kutethemes KuteShop, especially those using versions up to 4.2.9, should be aware of this vulnerability and take [truncated]
CVE-2026-39611 is a HIGH severity vulnerability with a CVSS score of 7.5, affecting kutethemes KuteShop kuteshop from n/a through <= 4.2.9. This issue relates to Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion'). The vulnerability allows attackers to include local files via crafted requests, potentially leading to code execution. Users of KuteShop vers [truncated]