CVE-2026-39628 is a cross-site scripting (XSS) vulnerability affecting the kutethemes DukaMarket e-commerce platform through version 1.3.0, which allows attackers to inject malicious code through improper neutralization of script-related HTML tags. The vulnerability enables code injection attacks that could compromise website integrity and user security. The vulnerability carries a CVSS severity rating of 5.3 (Medium) with a network-based attack vector requiring no authentication or user interaction. The attack has low complexity and does not require special privileges, though the impact is limited to integrity concerns with no confidentiality or availability impact. The EPSS score of 0.0005 indicates minimal real-world exploitation likelihood at this time. There is currently no evidence of active exploitation, and the vulnerability is not listed on the Known Exploited Vulnerabilities catalog. Community attention remains low, with an inactive status on vulnerability tracking lists. Organizations running DukaMarket should nonetheless prioritize patching to version 1.3.1 or later to mitigate the code injection risk and prevent potential future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Kutethemes | DukaMarket | >= 0, <= 1.3.0CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.