SVXportal Stored Cross-Site Scripting Vulnerability in User Registration Workflow

Vulnerability

A stored cross-site scripting vulnerability has been identified in SVXportal versions through 2.5. This issue arises in the user registration process, specifically within 'index.php' when it submits data to 'admin/user_action.php'. User-provided information such as first name, last name, and email is saved in the backend database without proper output encoding. This data is later displayed in the administrator interface ('admin/users.php'), enabling an unauthenticated remote attacker to inject arbitrary JavaScript. The injected script executes in the administrator's browser when the affected page is viewed.

Impact

Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the administrator's browser.

Added: Feb 20, 2026, 5:38 PM
Updated: Feb 20, 2026, 9:28 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.4
exploitability
7.0
remediation
0.0
relevance
3.2
threat
3.2
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.