CVE-2026-27506 | sa2blv SVXportal up to 2.5 user_settings.php firstname/lastname/email/image_url cross site scripting
A vulnerability classified as problematic was found in sa2blv SVXportal up to 2.5. This issue affects some unknown processing of the file user_settings.php. Such manipulation of the argument firstname/lastname/email/image_url leads to cross site scripting.
This vulnerability is documented as CVE-2026-27506. The attack can be executed remotely. There is not any exploit available.