
CVE-2026-27502 SVXportal version 2.5 and prior contain a reflected cross-site scripting vulnerability in log.php via the search query parameter. The application embeds the unsanitiz… https://www.cve.org/CVERecord?id=CVE-2026-27502
Post summary
The text discloses a reflected XSS flaw in SVXportal’s log.php, detailing how the vulnerability is triggered but does not provide a PoC, exploit, mitigation, or evidence of active exploitation.
