Metrics
Affected Vendors & Products
Mon, 23 Feb 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sa2blv
Sa2blv svxportal |
|
| Vendors & Products |
Sa2blv
Sa2blv svxportal |
Mon, 23 Feb 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Radioinorr
Radioinorr svxportal |
|
| CPEs | cpe:2.3:a:radioinorr:svxportal:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Radioinorr
Radioinorr svxportal |
Fri, 20 Feb 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Fri, 20 Feb 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 20 Feb 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SVXportal version 2.5 and prior contain a reflected cross-site scripting vulnerability in log.php via the search query parameter. The application embeds the unsanitized parameter value directly into an HTML input value attribute, allowing an unauthenticated remote attacker to inject and execute arbitrary JavaScript in a victim's browser if the victim visits a crafted URL. This can be used to steal session data, perform actions as the victim, or modify displayed content. | |
| Title | SVXportal <= 2.5 log.php Search Reflected XSS | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-02-20T20:12:00.277Z
Reserved: 2026-02-19T19:51:07.326Z
Link: CVE-2026-27502
Updated: 2026-02-20T19:44:04.132Z
Status : Analyzed
Published: 2026-02-20T17:25:56.750
Modified: 2026-02-23T13:59:18.180
Link: CVE-2026-27502
No data.