Radioinorr's vulnerability footprint centers on a narrow product portfolio, primarily the SVX Portal platform, which appears to serve as a web-based access or management interface. The recurring weakness classes—cross-site scripting and SQL injection—reflect input-handling gaps typical of web applications and point to the need for robust input validation and parameterized query practices in this vendor's development. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Radioinorr over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-27506MEDIUM SVXportal version 2.5 and prior contain a stored cross-site scripting vulnerability in the user profile update workflow (user_settings.php submitting to admin/update_user.php). Aut | Feb 20, 2026 | 6.1 | 23 | NO | NO |
CVE-2026-27505MEDIUM SVXportal version 2.5 and prior contain a stored cross-site scripting vulnerability in the user registration workflow (index.php submitting to admin/user_action.php). User-supplied | Feb 20, 2026 | 6.1 | 23 | NO | NO |
CVE-2026-27504MEDIUM SVXportal version 2.5 and prior contain a reflected cross-site scripting vulnerability in radiomobile_front.php via the stationid query parameter. When an authenticated administrat | Feb 20, 2026 | 6.1 | 23 | NO | NO |
CVE-2026-27503MEDIUM SVXportal version 2.5 and prior contain a reflected cross-site scripting vulnerability in admin/log.php via the search query parameter. When an authenticated administrator views a | Feb 20, 2026 | 6.1 | 23 | NO | NO |
CVE-2026-27502MEDIUM SVXportal version 2.5 and prior contain a reflected cross-site scripting vulnerability in log.php via the search query parameter. The application embeds the unsanitized parameter v | Feb 20, 2026 | 6.1 | 23 | NO | NO |
CVE-2025-63725MEDIUM Reflected Cross-Site Scripting (XSS) vulnerability in SVX Portal 2.7A via the id parameter to Recivers.php. | Nov 14, 2025 | 6.1 | 21 | NO | NO |
CVE-2025-63724MEDIUM SQL injection (SQL-i) vulnerability in SVX Portal 2.7A via crafted POST request to admin/update_setings.php. | Nov 14, 2025 | 6.0 | 21 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Radioinorr.
Media articles that mention a CVE ID that affects a product developed by Radioinorr — matched by CVE ID, not by vendor name.