Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 23 Feb 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sa2blv
Sa2blv svxportal |
|
| Vendors & Products |
Sa2blv
Sa2blv svxportal |
Mon, 23 Feb 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Radioinorr
Radioinorr svxportal |
|
| CPEs | cpe:2.3:a:radioinorr:svxportal:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Radioinorr
Radioinorr svxportal |
Fri, 20 Feb 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 20 Feb 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Fri, 20 Feb 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SVXportal version 2.5 and prior contain a reflected cross-site scripting vulnerability in admin/log.php via the search query parameter. When an authenticated administrator views a crafted URL, the application embeds the unsanitized parameter value directly into an HTML input value attribute, allowing attacker-supplied JavaScript to execute in the administrator's browser. This can enable session theft, administrative action forgery, or other browser-based compromise in the context of an admin user. | |
| Title | SVXportal <= 2.5 admin/log.php Search Reflected XSS | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-11T23:11:21.339Z
Reserved: 2026-02-19T19:51:07.327Z
Link: CVE-2026-27503
Updated: 2026-02-20T19:40:04.257Z
Status : Analyzed
Published: 2026-02-20T17:25:56.920
Modified: 2026-02-23T13:58:42.027
Link: CVE-2026-27503
No data.
OpenCVE Enrichment
Updated: 2026-04-17T17:30:23Z