CVE-2026-27504 MEDIUM

CVE-2026-27504: SVXportal <= 2.5 radiomobile_front.php stationid Reflected XSS

Vendor Sa2Blv
Product SVXportal
Weakness CWE-79 · XSS
Published February 20, 2026
Last update May 11, 2026

CVSS base score

5.1/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N

What the vulnerability does

01Description

SVXportal version 2.5 and prior contain a reflected cross-site scripting vulnerability in radiomobile_front.php via the stationid query parameter. When an authenticated administrator views a crafted URL, the application embeds the unsanitized parameter value into a hidden input value field, allowing attacker-supplied script injection and execution in the administrator's browser. This can be used to compromise admin sessions or perform unauthorized actions via the administrator's authenticated context.

Key dates

02Disclosure timeline

February 20, 2026 CVE published
May 11, 2026 Record updated

Related vulnerabilities

04Related CVE